Executive Overview
The sprawling, volatile world of international cybercrime has witnessed another tectonic shift. Saif Al-din Khader—a teenager operating out of Amman, Jordan, under the hacker handle “Rey”—has reportedly been detained by local authorities and is actively cooperating with the Federal Bureau of Investigation (FBI). Khader, identified in previous threat intelligence profiles as a central figure steering the notorious data theft and extortion syndicate ShinyHunters, was apprehended precisely as the group was executing an aggressive extortion campaign against a high-value aviation asset recently divested by aerospace giant Boeing.
The detention of the young Jordanian mastermind underscores a broader, evolving phenomenon within the cybercriminal underworld: the "franchising" of elite threat groups. Much like the legendary "Dread Pirate Roberts" persona from The Princess Bride, the ShinyHunters moniker has transcended its original creators—mostly French nationals now languishing in European prisons—to become a corporate-style brand adopted by a rotating cast of digital mercenaries.
Rey’s reign over the moniker was brief, marked by brazen digital taunts, fabricated operational false flags, and high-stakes attacks targeting global corporations and law enforcement alike. However, his descent from self-proclaimed digital sovereign to cooperating informant illuminates the fragile nature of modern cyber syndicates, where youthful hubris often collides with the relentless machinery of global counterintelligence.
Detailed Chronology: From Zero-Day Exploits to Detention in Amman
The downfall of "Rey" and the recent turmoil surrounding ShinyHunters did not happen in a vacuum. It represents the culmination of months of coordinated law enforcement pressure, high-profile zero-day exploits, and calculated cyberwarfare between threat actors and Western intelligence.

June 2026: The PeopleSoft Zero-Day Campaign
The current saga took root in June 2026, when ShinyHunters weaponized a critical zero-day vulnerability (CVE-2026-35273) affecting Oracle PeopleSoft, a widely deployed software-as-a-service (SaaS) platform used by enterprises and government agencies for human resources, benefits, and payroll management.
According to admissions made by the hackers to security researchers at BleepingComputer, the primary target of this campaign was the FBI’s own internal PeopleSoft database. While that specific objective was reportedly unsuccessful, the group quickly pivoted to a mass-exploitation strategy. Utilizing URL-encoding tricks to bypass web application firewall (WAF) rules issued by Mandiant, the threat actors breached dozens of enterprise systems spanning higher education, healthcare, technology, agriculture, transportation, and government sectors.
September 15, 2026: The Dutch Raid
Law enforcement pressure intensified dramatically on the evening of September 15, 2026. Dutch police, utilizing flash-bang grenades in a high-risk tactical raid in Amsterdam, arrested 24-year-old convicted cybercriminal Pepijn van der Stap (formerly known by the alias “Umbreon”). Van der Stap, who had recently cultivated a public persona as a "reformed" hacker working as an offensive security lead at a Dutch cybersecurity firm, was apprehended on suspicion of aiding ShinyHunters’ data thefts and extortions.
September 16–22, 2026: Rey’s False-Flag Gambit
Seizing upon the sudden vacuum left by Van der Stap’s arrest, Rey aggressively stepped into the spotlight. Assuming de facto administrative control over the ShinyHunters brand on Telegram and Twitter/X, Rey publicly boasted about compromising the FBI and extorting the rival ransomware syndicate Cl0p.

In an elaborate attempt to misdirect investigators, Rey’s public taunts prominently featured memes incorporating the avatar of Van der Stap’s former alias, "Umbreon," attempting to frame the jailed Dutchman for the fresh wave of attacks. Concurrently, Rey utilized a GitHub blog to meticulously doze two Russian nationals alleged to be the core developers and operators behind Cl0p.
Late September 2026: The FBI Breach Exposed and Retaliatory Flash Notices
On September 25, the Google Threat Intelligence Group (GTIG) and Mandiant released a comprehensive joint report confirming the mass exploitation of the PeopleSoft vulnerability. Shortly thereafter, investigative reports revealed that the FBI had been forced to remove an Accenture contractor over a severe security lapse: failure to patch the very recruitment portal breached by ShinyHunters. This breach exposed sensitive personal data—including psychiatric and medical records, unit specializations, and credentials—pertaining to more than 5,000 FBI personnel.
The breach prompted the FBI to issue a rare public flash notice on May 15, 2026, warning organizations against paying ransoms to ShinyHunters and highlighting the group’s aggressive harassment tactics, which include swatting and direct intimidation of victims’ families. In interviews with The Register, ShinyHunters admitted that their targeting of the FBI was fundamentally a public relations stunt designed to counter the agency’s advisory and protect their brand’s extortion capabilities.
Early October 2026: The Collapse and Arrest
The house of cards collapsed for Rey at the turn of the month. On September 30, following the expiration of an FBI ultimatum, the primary ShinyHunters darknet portal went offline. Reuters reported on October 3 that three independent sources confirmed Saif Al-din Khader had been detained by Jordanian authorities in Amman and was actively cooperating with the FBI.

Faced with the closing net, Rey purged his social media presence, deleting his Twitter/X accounts. However, his digital footprint—including a family computer compromised by infostealer malware that exposed his father’s credentials for Royal Jordanian Airlines—had already provided international investigators with the connective tissue required to map his identity.
Supporting Context & Metrics: Anatomy of a Cyber Franchise
To fully understand the significance of Rey’s arrest, one must examine the metrics and operational structure that allowed a teenager in Amman to orchestrate millions of dollars in damages.
- Scale of Operations: Cybercriminals operating under the ShinyHunters banner are historically linked to dozens of major data breaches involving billions of compromised records dating back to 2019.
- The "Franchise" Model: Modern cybercrime has largely abandoned rigid hierarchical structures in favor of loose affiliate networks. Freelancers feed stolen SaaS credentials to syndicate operators in exchange for a 25% to 30% cut of finalized ransoms. According to darknet monitors, Rey allegedly helped coordinate 5 to 6 distinct cybercriminal cells, generating over $200 million in cumulative enterprise damages.
- The Boeing Extortion Nexus: The FBI’s investigation gained ultimate urgency when ShinyHunters targeted Jeppesen ForeFlight, a digital aviation and navigation unit recently divested by Boeing. Boeing sold the subsidiary in November 2025 to private equity firm Thoma Bravo for $10.55 billion. The theft of sensitive aviation and navigation data posed profound operational safety risks, triggering high-priority international intervention.
- The Jordanian Connection: Investigations into Rey revealed a striking personal irony: while the teenager was attempting to extort Boeing’s former aviation unit, his father was employed as a pilot for Royal Jordanian Airlines—a flag carrier operating a long-haul fleet composed entirely of Boeing aircraft.
Official Statements and Industry Impact
The multi-jurisdictional fallout from the ShinyHunters investigations has prompted guarded responses from the corporate entities caught in the crossfire.
- Boeing’s Response: A corporate spokesperson acknowledged the extortion attempts tied to its former subsidiary, stating:
"We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."

- Jeppesen ForeFlight’s Response: Minimizing the operational disruption, a Jeppesen ForeFlight spokesperson noted:
"Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
- The Neo Security Controversy: Meanwhile, in the Netherlands, the narrative surrounding Pepijn van der Stap took a far darker turn. Dutch daily RTL reported that prosecutors suspect Van der Stap of attempting to orchestrate at least two murders abroad. Benjamin Korper, owner of Neo Security—the cybersecurity firm that employed Van der Stap as an "offensive security lead"—confirmed that forensic police investigators raided his offices on September 15 using flash-bang grenades, though internal audits found no evidence of malicious activity targeting Neo Security’s client base.
Future Outlook: The Death of a Brand?
The detention of Saif Al-din Khader and the ongoing legal battles surrounding Pepijn van der Stap mark a watershed moment for the cybercrime underground.
The strategy of "larping" as legacy cyber syndicates—using established brand names to instill fear and command higher ransom payouts—carries existential risks. While Rey initially succeeded in monetizing the ShinyHunters reputation through SaaS credential harvesting and aggressive social media posturing, his actions ultimately drew the undivided attention of the FBI, foreign intelligence services, and rival cybercriminal factions (such as the operators behind the "The Battle" Telegram channel who eagerly doxxed him).
As international law enforcement continues to dismantle the infrastructure supporting these decentralized extortion rings, the lesson for aspiring digital mercenaries is clear: the digital veil of anonymity is gossamer thin, and playing king ("Rey") in the volatile realm of international cybercrime invariably ends in a fall.
