In a dramatic convergence of international law enforcement actions, Jordanian authorities have detained Saif Al-din Khader, a teenager from Amman operating under the digital moniker “Rey.” Khader, identified by investigators as a central figure and administrator within the notorious data theft and extortion syndicate known as ShinyHunters, is currently cooperating with the Federal Bureau of Investigation (FBI) to unmask remaining members of the cybercrime operation.
The apprehending of Khader marks a critical juncture in an international crackdown targeting a group responsible for high-profile cyber-extortion campaigns, massive enterprise data breaches, and bold attacks on federal infrastructure. Khader’s detention unfolded while ShinyHunters was actively attempting to extort Jeppesen ForeFlight, a digital aviation and navigation business unit recently divested by aerospace giant Boeing to private equity firm Thoma Bravo. The extortion attempt raised immediate alarms within intelligence and security circles due to potential operational safety and strategic risks associated with the stolen aviation data.
Khader’s capture follows closely on the heels of the dramatic September 15 arrest of 24-year-old Dutch cybercriminal Pepijn van der Stap (known online as “Umbreon”) in Amsterdam. Together, these law enforcement operations have exposed the inner mechanics, technical vulnerabilities, internal betrayals, and systemic brand degradation of ShinyHunters. Once regarded as an elite hacking collective, the group evolved into a decentralized "franchise" model operated by opportunistic freelancers, leaving a trail of compromised enterprise Software-as-a-Service (SaaS) platforms, leaked government personnel records, and claims of financial damages exceeding $200 million.
Detailed Chronology
The sequence of events leading to the unraveling of ShinyHunters’ latest operational core highlights a fast-moving, multi-jurisdictional investigation spanning several months:
+-----------------------------------------------------------------------------------+
| CHRONOLOGY OF EVENTS: SHINYHUNTERS DOWNFALL |
+-----------------------------------------------------------------------------------+
| June 2026 | Mass zero-day exploitation of Oracle PeopleSoft begins. |
| May 15, 2026 | FBI issues Flash Notice warning against paying ShinyHunters. |
| Sept 15, 2026 | Dutch police raid Pepijn van der Stap's home in Amsterdam. |
| Sept 22, 2026 | "Rey" posts taunting memes framing "Umbreon" for FBI hack. |
| Sept 25, 2026 | Mandiant & GTIG issue report detailing PeopleSoft campaigns. |
| Sept 28, 2026 | Dutch arrest revealed; Rey begins deleting social accounts. |
| Sept 29, 2026 | Dutch daily RTL reports Van der Stap murder-for-hire probe. |
| Sept 30, 2026 | ShinyHunters darknet extortion leak site goes offline. |
| Oct 3, 2026 | Reports emerge that Saif Al-din Khader ("Rey") is detained. |
| Oct 5, 2026 | FBI removes Accenture contractor over unpatched PeopleSoft. |
+-----------------------------------------------------------------------------------+
June 2026: Zero-Day Exploitation Begins
ShinyHunters initiates a wide-scale campaign targeting enterprise installations running Oracle PeopleSoft, a widely deployed human resources, hiring, and payroll platform. Exploiting a zero-day vulnerability tracked as CVE-2026-35273, the group targets enterprise environments and government systems, specifically aiming to infiltrate the FBI’s recruitment database.
September 15, 2026: The Amsterdam Raid
Dutch tactical police units execute a high-risk raid using flash-bang grenades on the Amsterdam residence of Pepijn van der Stap (“Umbreon”). Van der Stap, a convicted cybercriminal working as the “offensive security lead” at cybersecurity firm Neo Security, is taken into custody on suspicion of assisting ShinyHunters in executing major data thefts and extortions.
Late September 2026: Escalation, Taunts, and Exposure
September 22: Following Van der Stap’s arrest, Khader (“Rey”) assumes public control of the ShinyHunters brand. Operating via Twitter/X, Rey boasts about compromising FBI systems and extorting the rival Cl0p ransomware cartel. Rey posts memes incorporating Van der Stap’s "Umbreon" avatar in an attempt to frame the arrested Dutchman for the FBI breach.
September 25: Security researchers at Mandiant and the Google Threat Intelligence Group (GTIG) publish an in-depth threat intelligence report confirming ShinyHunters’ mass exploitation of CVE-2026-35273 across healthcare, tech, government, and education sectors.
September 28: Public reporting exposes Van der Stap’s arrest. Prompted by media inquiries sent to his father, Khader begins frantically deleting his social media presences, including his primary Twitter/X account.
September 29: Dutch news outlet RTL reveals explosive law enforcement findings indicating Van der Stap is under investigation for allegedly ordering two foreign murder-for-hire hits.
September 30: The official darknet leak site operated by ShinyHunters suddenly drops offline following the expiration of an extortion deadline given to federal authorities.
October 3–5, 2026: Detentions and Federal Fallout
October 3: Reuters reports that Jordanian security forces in Amman have detained Saif Al-din Khader ("Rey"). Khader begins actively cooperating with the FBI.
October 5: Investigations into the FBI recruitment breach reveal that an Accenture contractor failed to apply critical security patches to the bureau’s Oracle PeopleSoft instance, resulting in the contractor’s immediate removal from the federal engagement.
Supporting Context & Metrics
The Technical Exploitation Vector: CVE-2026-35273
The primary engine driving ShinyHunters’ 2026 cyber-campaign was CVE-2026-35273, a vulnerability in Oracle’s PeopleSoft SaaS platform. Initially exploited as a zero-day in June, the vulnerability allowed attackers to gain unauthorized access to core human resources databases containing sensitive employee data, social security information, and banking details.
CVE-2026-35273 Exploitation Flow
================================
[ Target: Oracle PeopleSoft ]
|
+---> (Bypasses standard input validation)
|
[ Security Patch Issued ]
|
+---> (Mandiant deploys WAF Mitigations)
|
[ ShinyHunters Pivot ]
|
+---> (Applies URL-Encoding Trick to bypass WAF)
|
[ Mass Data Exfiltration ]
+---> Exfiltrates HR, Medical & Government Records
When Oracle issued a patch and Mandiant published Web Application Firewall (WAF) mitigation rules for organizations unable to immediately patch, ShinyHunters adapted. The hackers bypassed Mandiant’s recommended WAF protections using a classic URL-encoding manipulation trick. This technique allowed them to continue harvesting credentials and exfiltrating data from dozens of organizations spanning higher education, technology, healthcare, agriculture, transportation, and government agencies.
Quantitative & Breach Impact Metrics
Targeted Entity / Metric
Extent of Intrusion / Financial Impact
Specific Compromised Assets
FBI Personnel Recruitment Portal
Over 5,000 personnel records exposed
Medical histories, psychiatric evaluations, organizational units, individual specializations
Jeppesen ForeFlight (ex-Boeing)
Active extortion campaign during arrest
Stolen digital aviation and operational navigation data
Thoma Bravo Deal Value
$10.55 billion acquisition cost
Acquired Jeppesen ForeFlight from Boeing in November 2025
Van der Stap Cybercrime History
€1.5 million to €2.7 million
Previous extortion earnings leading to a prior 4-year prison sentence
Estimated Syndicate Damages
Exceeds $200 million
Cumulative damages across affiliated cybercrime operations
Affiliate Ransom Split
25% to 30% cut
Paid to cybercriminal freelancers supplying stolen SaaS credentials
Family Ties and Digital Footprints
Khader’s online activities eventually pointed directly back to his household in Amman. Investigative research revealed that his father was employed by Royal Jordanian Airlines, a carrier largely controlled by the Jordanian government whose long-haul fleet consists predominantly of Boeing aircraft. Early in 2025, Khader claimed on Telegram that his father worked as an airline pilot.
While that claim remained unverified, forensic evidence showed that the Khader family’s shared home computer had previously been infected with password-stealing malware. The exfiltrated log files confirmed that Khader’s father used the infected device to authenticate against multiple internal Royal Jordanian Airlines employee portals.
Khader’s digital footprint extended to a GitHub technical blog. In March 2026, he published a detailed research post dox-listing two Russian nationals whom he asserted were the core developers and administrators behind the Cl0p ransomware syndicate.
KHADER FAMILY & DIGITAL NEXUS
=============================
[ Family Computer (Amman) ] ---- Infested by Infostealer Malware
|
+---> Exfiltrated Credentials: Royal Jordanian Airlines Portals
|
[ Saif Al-din Khader ("Rey") ]
|
+---> GitHub Cybersecurity Blog: Doxxed core Russian operators of Cl0p (March 2026)
|
+---> Twitter/X Account: Taunted FBI & Cl0p; framed "Umbreon" (Deleted Sept 2026)
|
+---> Telegram Channels: Managed BreachForums / ShinyHunters re-brand operations
Syndicate Degradation: The "Franchise" Model
Cybersecurity analysts emphasize that the entity operating as ShinyHunters in 2026 is vastly different from the original group established around 2019. The founding members—predominantly French citizens—were largely arrested or incarcerated in prior law enforcement sweeps.
In their place, ShinyHunters evolved into a franchised criminal brand, operating much like the fictional "Dread Pirate Roberts"—where identity and infrastructure are passed along to new actors following the capture of predecessors. Khader allegedly purchased the group’s original PGP cryptographic key to construct new iterations of BreachForums and associated Telegram channels.
ORIGINAL SHINYHUNTERS 2026 "FRANCHISE" MODEL
+--------------------------+ +--------------------------+
| Core French Operators | | Cybercrime Freelancers |
| (Arrested/Imprisoned) | | & Credential Brokers |
+--------------------------+ +--------------------------+
| |
v v
[ Custom Zero-Day Breaches ] [ SaaS Access + Bought PGP Key ]
| |
+-------------------> <--------------------+
|
v
[ Brand Degradation & Doxing ]
This structural shift sparked internal conflict within the cybercrime underground. Rival channels on Telegram, such as "The Battle," frequently mocked Khader as an inexperienced operator riding the coattails of an established brand. Critics accused Khader of damaging the group’s reputation by making bold, unfulfilled threats against federal agencies, reselling previously leaked data, and abandoning extortion demands under pressure.
The Dutch Parallel: Flash-Bangs and Murder-for-Hire
The arrest of Pepijn van der Stap in Amsterdam introduces a dramatic parallel chapter to the ShinyHunters investigation. Van der Stap, who previously served time for high-level extortion that generated millions of euros, had carefully cultivated a public image as a reformed cybercriminal. Before his September 2026 arrest, he worked as a software engineer at cybersecurity firm Hadrian, volunteered for the Dutch Institute for Vulnerability Disclosure (DIVD), and held the position of offensive security lead at Neo Security.
PEPIJN VAN DER STAP ("UMBREON") DOUBLE LIFE
===========================================
Public Persona Undercover Operations
+-------------------------+ +-------------------------+
| - Lead, Neo Security | | - ShinyHunters Admin |
| - Ex-Engineer, Hadrian | <===============> | - Extortion & Data Theft|
| - DIVD Volunteer | | - Murder-for-Hire Probe |
+-------------------------+ +-------------------------+
However, police investigations revealed that Van der Stap was secretly assisting ShinyHunters in major data theft campaigns while operating under his legacy alias, "Umbreon."
The situation escalated dramatically on September 29, 2026, when Dutch news outlet RTL reported that federal prosecutors suspect Van der Stap of attempting to orchestrate at least two foreign murder-for-hire plots. Law enforcement authorities indicated that initial findings point to Van der Stap directly issuing orders for contract killings abroad, adding severe violence-related charges to his ongoing cybercrime prosecution.
Official Statements
The law enforcement operations, enterprise breaches, and technical fallout prompted formal responses from corporate executives, target organizations, and the threat actors themselves:
Corporate & Target Responses
Boeing Spokesperson: "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."
Jeppesen ForeFlight Official Statement: "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
Benjamin Korper, Owner of Neo Security: Korper confirmed that Dutch forensic investigators executed a high-risk search warrant at Neo Security’s headquarters on September 15. The company retained an independent cybersecurity firm to conduct a comprehensive digital audit, noting: "So far investigators have found no evidence he [Van der Stap] acted against his employer or clients."
Threat Actor Assertions & Pre-Arrest Remarks
Pepijn van der Stap ("Umbreon")(Speaking to KrebsOnSecurity on September 9, prior to his arrest): "You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced. I’m doing what I can to repay victims, and that’s all I can do. If someone doesn’t want to believe me, then that’s on them."
ShinyHunters Representatives(In an interview with The Register regarding their FBI recruitment portal breach): The hackers claimed the attack on federal systems was executed directly to counter an FBI Flash Notice issued on May 15, 2026, which advised corporate entities against paying ransoms: "The attack demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers… This was fundamentally a public relations and marketing initiative for our business."
Administrators of "The Battle" Telegram Channel(Commentary on Khader’s operation): "Rey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters. That group had already been dismantled, with many of its members either arrested or imprisoned, yet Rey still chose to use its name while carrying out his crimes. We’re aware of claims that Rey caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25–30% cut."
Future Outlook
The simultaneous removal of Saif Al-din Khader in Jordan and Pepijn van der Stap in the Netherlands severely dismantles the operational infrastructure supporting the modern iteration of ShinyHunters. With Khader actively cooperating with federal authorities, law enforcement investigators are positioned to map out the network of cybercriminal freelancers, credential brokers, and initial access brokers who fueled the syndicate’s SaaS extortion model.
SaaS Vulnerability Management: The exploitation of CVE-2026-35273 highlights critical exposure points in legacy cloud-hosted enterprise applications. Organizations are moving away from relying solely on WAF mitigation rules, opting instead for rapid zero-day patch deployments to counter URL-encoding bypass techniques.
Contractor & Third-Party Risk Enforcement: The FBI’s termination of its Accenture contractor following the unpatched PeopleSoft breach underscores a growing intolerance for security oversights within government supply chains. Federal agencies are implementing stricter security compliance audits for external IT service providers.
The Dissolution of Franchised Cybercrime Brands: The collapse of ShinyHunters demonstrates the inherent instability of cybercrime syndicates relying on franchised brand identities. As federal agencies target access brokers and affiliate networks, the legal risks associated with operating under legacy threat-group aliases continue to escalate.