The Fall of "Rey": Inside the Unraveling of the ShinyHunters Extortion Empire and the Global Manhunt

Share
The Fall of "Rey": Inside the Unraveling of the ShinyHunters Extortion Empire and the Global Manhunt

Executive Overview

The volatile landscape of international cybercrime has shifted dramatically following a high-stakes series of law enforcement actions across the Middle East and Europe. Saif Al-din Khader, a teenager from Amman, Jordan, widely known in underground forums by the hacker handle “Rey,” has been detained by local authorities and is reportedly cooperating with the Federal Bureau of Investigation (FBI). Khader is suspected of operating as a key leader and administrator of ShinyHunters, a prolific and ruthless data theft and extortion syndicate responsible for billions of compromised records over the past half-decade.

The dragnet that ensnared Khader closed in as the teenage mastermind was actively attempting to extort a newly divested business unit of global aerospace giant Boeing. In a striking twist of geopolitical and corporate irony, Khader’s father is employed by Royal Jordanian Airlines—an enterprise whose long-haul fleet relies heavily on Boeing aircraft, and whose corporate credentials were inadvertently compromised through household malware infections linked to the young hacker.

Simultaneously, the investigation has cast a wide net into European cybercrime circles. Dutch law enforcement recently executed a dramatic, flash-bang raid in Amsterdam to arrest 24-year-old Pepijn van der Stap, a supposedly reformed hacker and former cybersecurity professional who investigators now suspect of involvement not only in massive data extortions with ShinyHunters, but also in orchestrating international murder-for-hire plots.

As the iconic, feared "ShinyHunters" brand dissolves into a decentralized franchise plagued by infighting, doxxing campaigns, and direct confrontations with federal agencies, the dismantling of Khader’s network offers a rare window into the modern cyber-underworld—where youthful bravado, franchise-style cybercrime, and geopolitical fallout collide.


Detailed Chronology: From Zero-Day Exploits to International Detentions

The unraveling of the modern ShinyHunters apparatus began in earnest with a software vulnerability that exposed critical human resources infrastructure across the globe, eventually triggering a high-stakes chess match between elite hackers and federal investigators.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Oracle PeopleSoft Zero-Day Campaign

In June, ShinyHunters began aggressively exploiting a zero-day vulnerability—subsequently tracked as CVE-2026-35273—in PeopleSoft, a widely deployed enterprise software-as-a-service (SaaS) platform from tech giant Oracle. Designed to manage payroll, employee benefits, hiring, and internal human resources, PeopleSoft servers across diverse industries—ranging from higher education and healthcare to agriculture, technology, and government—were rapidly compromised.

According to communications between the hackers and security researchers at BleepingComputer, the primary objective of the initial zero-day push was to breach the internal PeopleSoft databases of the FBI itself. While those initial direct incursions into federal systems hit roadblocks, the threat actors quickly adapted. When security firm Mandiant and Google’s Threat Intelligence Group (GTIG) issued web application firewall (WAF) rules to mitigate the vulnerability, ShinyHunters bypassed these defenses using a well-known URL-encoding trick.

By late September, Mandiant and GTIG confirmed a mass-exploitation campaign had successfully exfiltrated sensitive data from dozens of enterprise networks. The fallout struck particularly close to home for federal law enforcement when investigative reports revealed that an Accenture contractor had failed to patch the specific FBI recruitment portal targeted by the hackers. This oversight exposed sensitive personal records belonging to more than 5,000 FBI personnel, including specialized unit assignments, medical records, and psychiatric evaluations.

The Rise and Fall of "Rey"

As the exploit campaign gained momentum, "Rey" (Saif Al-din Khader) stepped into the vacuum left by the arrests of original French ShinyHunters core members. Following the mid-September arrest of Dutch national Pepijn van der Stap, Khader brazenly seized control of the ShinyHunters brand. Operating from Amman, he launched a public relations and taunting campaign on Twitter/X, mocking both the FBI and the rival ransomware cartel Cl0p with elaborate memes. In an apparent effort to frame van der Stap, Khader embedded visual references to "Umbreon"—van der Stap’s historical hacker alias—within his taunting posts.

However, Khader’s digital footprint proved fatal. Security researchers had previously profiled Khader in late 2025, mapping his involvement across multiple ransomware and extortion groups, including Scattered Lapsus. Investigations into family computers revealed that password-stealing malware had harvested credentials belonging to Khader’s father, which were subsequently reused across internal Royal Jordanian Airlines employee portals.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

On October 3, Reuters cited three intelligence sources confirming that Khader had been detained by Jordanian authorities and was actively cooperating with the FBI. Hours before international media broke the story, automated notification requests sent to Khader’s father triggered a frantic purge. Khader hastily deleted his primary social media channels, though his public GitHub blog—featuring deep investigative "doxes" on the Russian leadership of the Cl0p ransomware group—inadvertently survived the purge.


Supporting Context & Metrics: The Anatomy of a Cybercrime Franchise

To understand how a teenager managed to cause hundreds of millions of dollars in damages, security analysts must examine how modern cybercrime has transitioned from centralized gangs into decentralized franchises.

+-----------------------------------------------------------------+
                 THE SHINYHUNTERS FRANCHISE MODEL                  
+-----------------------------------------------------------------+
                         [ Core Operators ]                       
             (Original French members arrested/imprisoned)        
                                  |                             
                                  v                             
                       [ Brand & PGP Key Sale ]                   
                                  |                             
         +------------------------+------------------------+    
         |                                                 |    
         v                                                 v    
  [ Freelance Affiliates ]                         [ Extortion Brokers ]
  (Supplied stolen SaaS credentials)               (Rey & associates negotiate 
                                                    ransom deals for 25-30% cuts)
         |                                                 |    
         +------------------------+------------------------+    
                                  |                             
                                  v                             
                   [ Enterprise Victim Extortion ]                
                (Boeing / Jeppesen, FBI, Oracle PeopleSoft)       
+-----------------------------------------------------------------+

The "Dread Pirate Roberts" Phenomenon

Security experts frequently compare the modern iteration of ShinyHunters to the fictional character Dread Pirate Roberts from The Princess Bride. In this criminal ecosystem, succession is dictated not by death, but by law enforcement arrests. The original core members of ShinyHunters—predominantly French nationals tied to historic breaches dating back to 2019—were systematically rounded up and imprisoned by European authorities.

Rather than dying out, the brand name, infrastructure, and PGP keys were acquired, rented, or usurped by freelance affiliates. Khader reportedly purchased or inherited key digital assets, operating a loose federation where freelance hackers fed stolen credentials from corporate SaaS platforms into the pipeline in exchange for a 25% to 30% cut of subsequent ransom payments.

The Extortion of Boeing’s Jeppesen ForeFlight

The investigation reached a critical inflection point when Khader and his associates targeted Jeppesen ForeFlight, a digital aviation and navigation subsidiary previously held by aerospace giant Boeing. Boeing had divested the unit in November 2025, selling it to private equity firm Thoma Bravo for $10.55 billion.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

According to sources close to the investigation, the theft of proprietary aviation data from Jeppesen ForeFlight introduced unprecedented risks to operational safety and flight navigation systems. This specific extortion attempt forced the FBI to escalate its timeline, transforming the operation from a standard data-theft investigation into a high-priority national security mandate.

Doxing, Infighting, and the "Battle" Channel

Khader’s downfall within the cybercrime underground was hastened by rival threat actors. A Telegram channel dubbed "The Battle" dedicated weeks to doxing and ridiculing Khader, portraying him as an inexperienced greenhorn ("skiddie") attempting to ride the coattails of a notorious brand.

According to logs published by underground analysts, Khader was accused of generating over $200 million in cumulative downstream damages while alienating veteran hackers through clumsy negotiations and sudden, erratic public retractions. When the FBI issued an ultimatum backed by a stern May advisory warning victims not to pay ShinyHunters—noting the group’s aggressive tactics, including swatting and harassment of executive families—ShinyHunters attempted to strike back. In interviews with The Register, the group claimed their hack of the FBI was a "public relations and marketing initiative" designed to counter federal warnings that were harming their extortion conversion rates.


Official Statements and Corporate Responses

As the fallout from the global investigations reverberates through corporate boardrooms and federal agencies, major stakeholders have issued formal statements addressing the breaches and ongoing security audits.

  • Boeing Corporation: In a statement provided to security journalists, Boeing acknowledged awareness of the threat actor claims regarding data tied to its former subsidiary. "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight," a Boeing spokesperson stated. "We are actively reviewing the matter with the Jeppesen ForeFlight team."
  • Jeppesen ForeFlight: Seeking to calm enterprise clients, a spokesperson for the aviation software unit emphasized that operational integrity remained uncompromised. "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
  • Accenture & Federal Contractors: Following reports that an Accenture contractor was ousted due to the failure to patch the PeopleSoft recruitment portal, federal agencies have tightened oversight regarding third-party vendor compliance, particularly for contractors handling sensitive personnel records.

The European Connection: Murder-for-Hire Allegations Against Pepijn van der Stap

While the arrest of Saif Al-din Khader dismantled the operational leadership of the ShinyHunters franchise in the Middle East, simultaneous developments in Europe introduced a far darker dimension to the investigation.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Dutch daily newspaper RTL reported that Dutch investigators suspect Pepijn van der Stap—the 24-year-old cybercriminal arrested in Amsterdam on September 15 following a dramatic raid involving flash-bang grenades—tried to orchestrate at least two murders abroad. Investigators are actively probing whether van der Stap issued direct orders for these contract killings while maintaining a public persona as a "reformed hacker."

Prior to his arrest, van der Stap had successfully rehabilitated his public image, securing a role as an "offensive security lead" at Dutch cybersecurity firm Neo Security, while previously working as a software engineer at startup Hadrian and volunteering for the Dutch Institute for Vulnerability Disclosure (DIVD). Neo Security owner Benjamin Korper confirmed that forensic investigators had thoroughly audited the firm’s networks and found no evidence that van der Stap had compromised client systems or abused his employment.

When interviewed by security researchers prior to his arrest, van der Stap deflected skepticism regarding his reformation, stating: "You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced. I’m doing what I can to repay victims, and that’s all I can do." These protestations carry an entirely new weight now that Dutch prosecutors have elevated the charges against him far beyond digital extortion and data theft.


Future Outlook: The Fragmented Horizon of Ransomware Syndicates

The simultaneous neutralization of key actors across Amman and Amsterdam marks a watershed moment in the modern fight against cyber extortion syndicates. However, industry experts warn that arresting individual administrators rarely eradicates the underlying economic ecosystem.

  1. Decentralized Resilience: Because modern syndicates operate less like rigid corporate hierarchies and more like open-source franchise networks, the arrest of figureheads like "Rey" merely fractures the brand into smaller, harder-to-track splinter cells. Freelance access brokers will continue to harvest corporate SaaS credentials, pivoting to new aliases and darknet portals.
  2. Heightened Corporate Scrutiny on SaaS: The mass exploitation of Oracle PeopleSoft underscores an uncomfortable truth for enterprise IT departments: perimeter defenses are failing against automated zero-day campaigns. Organizations can no longer treat human resources and payroll platforms as low-risk internal utilities; they require the same rigorous, automated patch management applied to external-facing customer portals.
  3. Cross-Border Law Enforcement Cooperation: The successful detention and FBI cooperation of Saif Al-din Khader in Jordan demonstrates that international diplomatic channels and cyber-intelligence sharing can pierce safe havens previously thought impenetrable. As foreign governments face mounting economic and infrastructure threats from localized hackers, state cooperation in detaining cybercriminals is reaching unprecedented levels.

Ultimately, while the "Rey" persona has been permanently silenced and his social media channels scrubbed from the internet, the cyber-underworld is already adapting. The lesson left in the wake of ShinyHunters’ collapse is clear: in the digital shadows, notoriety is a liability, and the pursuit of corporate extortion invariably draws the full weight of global intelligence agencies.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *