The Fall of "Rey": Inside the Unraveling of the ShinyHunters Cybercrime Syndicate and the Global Pursuit of Its Key Operatives

Share
The Fall of "Rey": Inside the Unraveling of the ShinyHunters Cybercrime Syndicate and the Global Pursuit of Its Key Operatives

Executive Overview

The sprawling, decentralized enterprise of international cyber extortion has suffered a severe blow following the detention of a teenager in Amman, Jordan, suspected of operating under the infamous moniker “Rey.” Identified by cybersecurity investigations as Saif Al-din Khader, the young hacker allegedly assumed control of the ShinyHunters data theft brand following a series of high-profile international law enforcement interventions.

According to intelligence sources cited by KrebsOnSecurity and Reuters, Khader is currently cooperating with the Federal Bureau of Investigation (FBI) to unmask remaining members of the hacking syndicate. His arrest coincided with a desperate, high-stakes extortion campaign targeting Jeppesen ForeFlight—a crucial digital aviation and navigation unit recently divested by aerospace giant Boeing.

The ripple effects of this arrest extend far beyond Jordan. Simultaneously, Dutch authorities have moved against 24-year-old Pepijn van der Stap (formerly known online as “Umbreon”), a convicted cybercriminal whose purported rehabilitation as an offensive security lead at a Dutch tech firm was upended by police raids involving flashbang grenades and chilling new allegations of orchestrating murder-for-hire plots abroad.

Together, these developments illuminate the chaotic, franchised evolution of modern cybercrime syndicates. No longer monolithic gangs of the past, contemporary extortion groups operate more like decentralized franchise networks—akin to a digital "Dread Pirate Roberts"—where succession is dictated not by retirement, but by sudden arrest, betrayal, and the ruthless recycling of notorious brand names for illicit profit.


Detailed Chronology: From Zero-Day Exploits to International Raids

The unraveling of the current ShinyHunters iteration is the culmination of a months-long digital cat-and-mouse game involving global intelligence agencies, threat intelligence firms like Mandiant and Google Threat Intelligence Group (GTIG), and independent cybersecurity journalists.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

June 2026: The Oracle PeopleSoft Zero-Day Campaign

The technical foundation of the recent ShinyHunters wave trace back to June, when the group began weaponizing a critical zero-day vulnerability (CVE-2026-35273) affecting PeopleSoft, an Oracle software-as-a-service (SaaS) platform widely utilized by corporations for human resources, payroll, and benefits management.

While Oracle quickly issued a patch and security firms like Mandiant released web application firewall (WAF) rules, the hackers adapted. Utilizing a well-known URL-encoding trick to bypass Mandiant’s defensive rules, ShinyHunters mass-exploited systems across diverse industries, including higher education, healthcare, technology, agriculture, government, and transportation.

The group’s original, audacious goal was reportedly to breach the FBI’s own internal PeopleSoft database. While that specific vector met with limited success initially, subsequent attacks successfully compromised the FBI’s recruitment portal. This breach exposed sensitive personal and professional data—including medical and psychiatric records, unit specializations, and background profiles—belonging to over 5,000 FBI personnel. The lapse prompted the FBI to sever ties with an Accenture contractor responsible for managing and patching the vulnerable web asset.

Mid-September 2026: The Dutch Raids and the Rise of "Rey"

On September 15, Dutch police executed a dramatic raid involving flashbang grenades in Amsterdam, arresting Pepijn van der Stap. Van der Stap, who had publicly positioned himself as a reformed hacker and "offensive security lead" at a cybersecurity firm named Neo Security, was suddenly unmasked as a suspected core collaborator in ShinyHunters’ data theft operations.

Immediately following Van der Stap’s arrest, "Rey" (Saif Al-din Khader) seized the opportunity to aggressively hijack the ShinyHunters brand identity. Operating from Amman, Rey took to social media platform X (formerly Twitter) and Telegram to publicly boast about stealing sensitive data and extorting the rival Cl0p ransomware group. In a calculated effort to misdirect investigators, Rey’s taunting memes prominently featured the avatar of Van der Stap’s former alias, "Umbreon," attempting to frame the jailed Dutchman for the fresh wave of high-profile intrusions.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Late September to Early October 2026: Cracking Down on the Franchise

The bravado was short-lived. By September 25, Mandiant and GTIG published comprehensive threat intelligence reports detailing the mass exploitation campaign. Concurrently, investigative journalists began closing in on Rey’s true identity, linking his digital footprints to his family’s residence in Amman.

Following inquiries directed at Rey’s father—an employee of Royal Jordanian Airlines whose personal computer credentials had been compromised by password-stealing malware—Rey panicked, systematically purging his social media footprints. However, his GitHub blog remained intact, revealing a deep fixation on the Cl0p ransomware syndicate, including a March post doxing two Russian men alleged to be Cl0p’s core operators.

On September 30, following an ultimatum and an expired FBI deadline, the ShinyHunters darknet extortion portal went offline. Days later, on October 3, Reuters and independent investigators confirmed that Jordanian authorities had detained Khader, who immediately commenced cooperation with the FBI.


Supporting Context & Metrics: The Anatomy of a Cybercrime Franchise

To understand how a teenager from Jordan managed to paralyze high-profile networks and antagonize federal law enforcement, analysts point to the fundamental shift in how ransomware and extortion rings operate today.

  • The Franchise Model: The original core members of ShinyHunters—predominantly French nationals—were largely rounded up or imprisoned years ago. However, the brand name carries immense psychological weight among corporate victims, making it a lucrative umbrella for freelance cybercriminals.
  • The "Dread Pirate Roberts" Effect: Successive generations of threat actors acquire old PGP keys, forum access credentials, and brand aesthetics to "larp" as the original group. According to underground chat intelligence analyzed by researchers, Rey allegedly operated by negotiating ransoms for various small-time hacker crews, taking a 25% to 30% cut of extorted funds and causing upwards of $200 million in cumulative damages.
  • The PR War with the FBI: In an extraordinary interview with The Register, members of the group admitted that hacking the FBI was primarily a public relations and marketing maneuver. They sought to discredit a May 2026 FBI Flash Notice warning victims against paying ransoms—a notice that highlighted the group’s aggressive harassment tactics, which included cold-calling executives, sending threatening text messages, and occasionally swatting uncooperative targets.

Official Statements and Corporate Responses

The fallout from the dual takedowns of Khader and Van der Stap has prompted defensive postures and official statements from major corporate stakeholders caught in the crosshairs.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Boeing and Jeppesen ForeFlight

The FBI’s pursuit of Rey gained critical momentum when the group targeted Jeppesen ForeFlight, a digital aviation and navigation subsidiary that Boeing sold in November 2025 to private equity firm Thoma Bravo for $10.55 billion. Given the proprietary nature of global flight planning and aviation data, an extortion breach here posed acute operational safety risks.

"We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight," a Boeing spokesperson stated. "Estamos actively reviewing the matter with the Jeppesen ForeFlight team."

Jeppesen ForeFlight issued a reassuring counter-statement:

"Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."

Neo Security and the Murder-For-Hire Allegations

The situation surrounding Pepijn van der Stap took an even darker turn when Dutch daily RTL reported on September 29 that investigators suspect Van der Stap of attempting to orchestrate at least two murders abroad.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Benjamin Korper, owner of Neo Security—the firm that unwisely hired Van der Stap as an offensive security lead—expressed shock. Korper confirmed that Dutch forensic investigators descended upon his offices on the night of Van der Stap’s arrest, though independent external audits commissioned by Neo Security have thus far found no evidence that Van der Stap compromised internal company networks or client data.


Future Outlook: The Fragile Ecosystem of Cyber Extortion

The simultaneous neutralization of Saif Al-din Khader in Jordan and the dramatic incarceration of Pepijn van der Stap in the Netherlands mark a watershed moment for the cybersecurity landscape.

  1. Erosion of Underground Trust: The speed at which these actors turned on each other—ranging from Rey doxing Cl0p operators to Khader reportedly cooperating with the FBI—demonstrates that the digital honor code among cybercriminals is non-existent. Trust within these syndicates is exceptionally fragile, rendering them vulnerable to coordinated international law enforcement pressure.
  2. Devaluation of Extortion Brands: Brand names like ShinyHunters have historically functioned as badges of terror for corporate boards. However, as law enforcement systematically dismantles successive waves of "franchise" operators who inherit these names, the psychological leverage wielded by cyber extortionists is steadily eroding.
  3. Heightened Scrutiny on SaaS Supply Chains: The weaponization of Oracle PeopleSoft vulnerabilities underscores a broader structural vulnerability in enterprise IT. As long as Human Resources and payroll platforms remain soft targets for zero-day exploitation, third-party contractors and major enterprises alike will remain squarely in the crosshairs of cyber extortion syndicates.

As the FBI continues to debrief Khader in Amman and Dutch prosecutors prepare their case regarding both data extortion and grave criminal conspiracy charges against Van der Stap, the message to the global cybercrime underground is clear: the digital shadows are shrinking, and the brand names shielding modern extortionists offer no permanent immunity from accountability.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *