Anatomy of a Cyber Extortion Franchise: Inside the Fall of "Rey" and the Global Crackdown on ShinyHunters

Share
Anatomy of a Cyber Extortion Franchise: Inside the Fall of "Rey" and the Global Crackdown on ShinyHunters

Executive Overview

The global cybercrime landscape has undergone a seismic shift following the detention of a teenage mastermind in Amman, Jordan. Identified by investigative security journalism as Saif Al-din Khader—better known by his hacker handle “Rey”—the suspect is reportedly cooperating with the Federal Bureau of Investigation (FBI). Khader’s apprehension marks a critical milestone in dismantling the modern iterations of ShinyHunters, a prolific data theft and extortion syndicate responsible for billions of compromised records over the past half-decade.

The dragnet closing in on Khader coincides with a series of dramatic international law enforcement raids, including the September arrest of Dutch cybercriminal Pepijn van der Stap. Together, these events lay bare the mechanics of modern cybercrime syndicates: decentralized, franchise-style extortion networks that operate less like traditional mafia cells and more like opportunistic rogue corporations.

As investigators piece together how a teenager managed to hijack the ShinyHunters moniker to taunt the FBI and extort major multinational entities—including a divested subsidiary of aerospace giant Boeing—new layers of complexity have emerged. These include sophisticated software-as-a-service (SaaS) supply chain attacks, deep-seated family digital compromises, and even chilling, unrelated allegations of murder-for-hire tied to the group’s European affiliates.


Detailed Chronology: The Fall of "Rey" and the Oracle PeopleSoft Exploit

The unraveling of Khader’s operation began in earnest following a summer campaign of mass exploitation targeting enterprise software infrastructure worldwide.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Oracle PeopleSoft Zero-Day Campaign

In June, ShinyHunters began weaponizing a zero-day vulnerability (tracked as CVE-2026-35273) affecting PeopleSoft, a widely deployed enterprise resource planning (ERP) platform from Oracle. The flaw allowed unauthorized actors to infiltrate databases utilized by organizations across diverse sectors, including technology, healthcare, higher education, agriculture, transportation, and government agencies.

Security researchers at Mandiant and the Google Threat Intelligence Group (GTIG) published exhaustive analyses in late September detailing how the gang bypassed initial web application firewall (WAF) mitigations using advanced URL-encoding tricks.

According to communications with security outlets like BleepingComputer, ShinyHunters’ initial ambition was audacious: to breach the FBI’s internal recruitment and personnel databases. While direct infiltration of the bureau’s core infrastructure proved challenging initially, the attackers successfully compromised an unsecured FBI recruitment website portal managed by an Accenture contractor. This breach exposed sensitive personal identifiable information (PII) on more than 5,000 FBI personnel, including specialized unit assignments, medical records, and psychiatric evaluations.

The Arrest in Amman and the Boeing Extortion Angle

By early October, Reuters and security researchers confirmed that Jordanian authorities had detained Saif Al-din Khader in Amman. Sources close to the investigation revealed that Khader’s arrest was catalyzed by an escalation of FBI pressure after ShinyHunters targeted a navigation and digital aviation unit recently divested by Boeing—specifically Jeppesen ForeFlight, which Boeing sold to private equity firm Thoma Bravo for $10.55 billion in November 2025.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The threat to Jeppesen ForeFlight introduced severe operational safety and security risks, injecting maximum urgency into the FBI’s investigation. Interestingly, Khader’s personal background ties directly into the aviation sector. Investigations revealed that Khader’s father was an employee of Royal Jordanian Airlines, a state-controlled carrier operating long-haul fleets composed primarily of Boeing aircraft. Previous password-stealing malware infections on the Khader family’s shared computer revealed that the elder Khader routinely utilized identical credentials across multiple corporate portals for the airline—a digital slip that helped researchers definitively map the young hacker’s physical and virtual footprint.

The Social Media Purge and Cl0p Doxxing

Following inquiries sent to Khader’s family by investigative journalists, the teenager began rapidly scrubbing his digital presence, deleting his prominent Twitter/X profiles and associated Telegram channels. However, a technical trace remained: a cybersecurity blog hosted on GitHub through which Khader had previously sought to cement his reputation. In March, the blog published an extensive investigative post doxing two Russian nationals alleged to be the core operators behind the Cl0p ransomware operation.


Supporting Context & Metrics: The Franchise Model of Cybercrime

To understand the current iteration of ShinyHunters, security experts advise looking past the original core members—mostly French nationals who have faced multiple arrests over the years—and viewing the brand through the lens of modern franchising.

The "Dread Pirate Roberts" Phenomenon

Modern cyber extortion syndicates increasingly function on a franchise model akin to the literary figure Dread Pirate Roberts from The Princess Bride: when one leader is arrested or killed, another assumes the mantle, and multiple individuals may even claim the brand simultaneously.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security
  • The Freelance Pipeline: The FBI’s current investigative focus centers on a network of freelance affiliates. These actors harvest valid corporate credentials from vulnerable SaaS platforms and feed them to the "brand holders" in exchange for a 25% to 30% cut of any subsequent extortion payouts.
  • The Scale of Damage: Cybercriminals associated with the ShinyHunters moniker have claimed responsibility for data breaches impacting dozens of major global corporations, resulting in billions of leaked records since 2019.
  • The PR Wars: In a bizarre twist of digital public relations, ShinyHunters actually admitted to The Register that their primary motivation for hacking the FBI was not purely financial, but tactical. They sought to retaliate against a May advisory issued by the FBI’s Internet Crime Complaint Center (IC3) that warned victims against paying ransoms and painted the gang as erratic. The hackers claimed the attack was designed to demonstrate their technical superiority and refute agency "misinformation."

Official Statements and Corporate Responses

As the fallout from the Oracle PeopleSoft vulnerabilities and subsequent extortions reverberates through the corporate world, affected entities have issued statements clarifying their security postures:

  • Boeing Statement: "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."
  • Jeppesen ForeFlight Response: "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."
  • The FBI’s Position: The Bureau has maintained a hardline stance against extortion, updating its advisories to warn organizations that ShinyHunters affiliates frequently resort to aggressive harassment tactics—including direct phone calls, text messages, and physical swatting attacks against corporate executives and their families—while routinely fabricating claims about possessing compromising multimedia assets.

Future Outlook: The Intersection of Cyber Extortion and Violent Crime

The wider web of arrests surrounding the ShinyHunters ecosystem has also exposed a darker, more alarming convergence between digital extortion and traditional criminal enterprise.

In the Netherlands, Dutch daily newspaper RTL reported explosive allegations regarding Pepijn van der Stap—the 24-year-old Dutch cybercriminal arrested in a dramatic Amsterdam raid involving flash-bang grenades on September 15. While van der Stap had recently cultivated a public persona as a "reformed hacker" and offensive security lead at a firm called Neo Security, Dutch investigators now suspect he attempted to orchestrate at least two murders abroad.

The simultaneous downfall of van der Stap in Europe and Saif Al-din Khader in Jordan marks the twilight of an era for the current generation of ShinyHunters operators. Security analysts predict that while the individual actors face imminent prosecution or intensive cooperation agreements with federal authorities, the underlying economic incentives of SaaS credential theft and corporate extortion will ensure that new decentralized franchises inevitably rise to take their place.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

For enterprise security teams, the mandate moving forward is clear: robust patch management for foundational enterprise platforms like Oracle PeopleSoft, proactive threat hunting for credential-stuffing campaigns, and absolute zero-trust architectures to mitigate the risk of supply chain breaches.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *