Inside the Fall of ‘Rey’: How a Teenage Amman Hacker, a Franchise Cybercrime Syndicate, and a Boeing Extortion Plot Collided

Share
Inside the Fall of ‘Rey’: How a Teenage Amman Hacker, a Franchise Cybercrime Syndicate, and a Boeing Extortion Plot Collided

Executive Overview

The sprawling, volatile ecosystem of global cyber extortion has suffered another major seismic jolt. According to international investigative reports and cybersecurity intelligence, a teenager operating out of Amman, Jordan, under the hacker handle “Rey” has been detained by local authorities and is reportedly cooperating with the Federal Bureau of Investigation (FBI).

The suspect, identified by security researchers as Saif Al-din Khader, allegedly served as a central driving force behind recent mass-extortion and data theft campaigns attributed to the notorious brand ShinyHunters.

Khader’s apprehension occurred precisely as the syndicate was deep into an aggressive extortion campaign targeting a newly divested business unit of global aerospace titan Boeing. This move ultimately triggered a high-priority, unrelenting international manhunt.

Compounding the gravity of the situation, Khader’s arrest intersects with a chaotic web of high-stakes arrests, corporate compromises, and bizarre international developments. These include Dutch police executing flash-bang raids against a supposedly reformed cybersecurity professional suspected of ordering offshore contract hits, brazen mass-exploits of Oracle PeopleSoft infrastructure, and the direct, retaliatory hacking of FBI recruitment databases.

This deep dive examines the anatomy of the ShinyHunters franchise model, the technical vectors that led to mass corporate compromises, and the intricate web of personal connections that brought a teenager from Amman into the crosshairs of global law enforcement.


Detailed Chronology: From Zero-Day Exploits to International Arrests

June 2026: The PeopleSoft Zero-Day Campaign

The current saga traces its roots back to June, when threat actors operating under the ShinyHunters banner began mass-exploiting a critical zero-day vulnerability (CVE-2026-35273) within PeopleSoft, an enterprise resource planning and human resources software-as-a-service (SaaS) platform built by tech giant Oracle.

Oracle swiftly issued an emergency patch for the vulnerability, while Mandiant released auxiliary web application firewall (WAF) mitigation rules to protect organizations unable to immediately patch their systems.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Despite swift industry warnings, ShinyHunters utilized a clever URL-encoding trick to bypass Mandiant’s WAF defenses. According to threat intelligence reports published by Mandiant and the Google Threat Intelligence Group (GTIG) in late September, the group successfully breached dozens of high-profile networks across critical industries, including higher education, healthcare, agriculture, transportation, and government agencies.

May–September 2026: The FBI Recruitment Portal Breach

In May 2026, the FBI issued a formal flash notice advising victim companies never to yield to ransom demands from ShinyHunters. The advisory highlighted the group’s psychological pressure tactics, which included harassment phone calls, swatting attacks, and empty threats regarding non-existent sensitive media.

Stung by the public relations blow and seeking to discredit the agency’s warning, ShinyHunters pivoted their technical capabilities toward a direct target: the FBI itself. Leveraging their PeopleSoft access, the hackers successfully breached an FBI recruitment website.

The breach exposed sensitive records belonging to more than 5,000 Bureau personnel, detailing specific units, specializations, and confidential medical and psychiatric evaluations. Consequently, the FBI was forced to terminate an Accenture contractor responsible for maintaining the compromised infrastructure.

September 15–28, 2026: The Dutch Raid and the Succession Scramble

The friction point leading to the syndicate’s current unraveling began in Europe. On the evening of September 15, Dutch police executed a dramatic tactical raid involving flash-bang grenades on the Amsterdam residence of 24-year-old Pepijn van der Stap.

Van der Stap, a convicted cybercriminal previously linked to data thefts totaling millions of euros, had publicly rebranded himself as a reformed security professional, recently taking on a role as an "offensive security lead" at a Dutch firm named Neo Security. Investigators, however, suspected him of quietly continuing his association with ShinyHunters.

Immediately following Van der Stap’s arrest, Saif Al-din Khader (“Rey”) seized control of the defunct ShinyHunters brand assets. Seeking to frame the detained Dutchman, Rey launched a public taunting campaign on Twitter/X. He posted memes boasting of FBI data thefts and clashing with the notorious Cl0p ransomware syndicate, embedding the avatar of Van der Stap’s former hacker alias, “Umbreon,” into the graphics to misdirect investigators.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

October 2026: Amman Detention and Boeing Extortion Focus

As Reuters and independent security journalists began piecing together the intelligence, it emerged that Jordanian authorities had detained Khader in Amman. Sources familiar with the ongoing FBI-led investigation indicated that Khader is actively cooperating with federal agents, providing actionable intelligence on remaining core members and co-conspirators.

Crucially, Khader’s detention coincided with the group’s frantic extortion campaign targeting a newly divested Boeing enterprise unit—a miscalculation that accelerated the FBI’s timeline and stripped away whatever operational security Khader thought he possessed.


Supporting Context & Metrics: The Mechanics of the "ShinyHunters" Franchise

The "Dread Pirate Roberts" Cyber Model

Security experts emphasize that the entities currently operating under the banner of ShinyHunters bear little resemblance to the original French cybercriminals who founded the moniker years prior. Most of those original core actors have long since been arrested, prosecuted, or imprisoned.

Instead, ShinyHunters has evolved into a decentralized franchise model. Much like the fictional Dread Pirate Roberts archetype from The Princess Bride, where the title and reputation are passed down following the removal of an incumbent, modern cybercrime syndicates operate as open-source brand names.

Freelance hackers, affiliate groups, and opportunistic teenagers acquire old PGP keys, forum administrative access, and defunct Telegram channels. They use the feared ShinyHunters name to negotiate payouts, extracting ransoms before reselling stolen enterprise data on underground forums.

The Jeppesen ForeFlight Extortion Vector

The specific campaign that sealed Khader’s fate involved Jeppesen ForeFlight, a digital aviation and navigation subsidiary previously owned by Boeing. Boeing finalized the sale of Jeppesen ForeFlight to private equity firm Thoma Bravo for $10.55 billion in November 2025.

According to sources close to the investigation, the data stolen from the former Boeing unit carried severe operational and navigational safety risks, elevating the incident from a standard corporate data leak to an urgent national security priority.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

This specific target choice introduced a deeply ironic familial twist:

  • The Royal Jordanian Connection: Evidence recovered from malware infections on family computers linked Khader directly to his father, an employee of Royal Jordanian Airlines.
  • The Fleet Overlap: Royal Jordanian Airlines operates a long-haul passenger fleet built entirely by Boeing.
  • The Operational Blunder: The attempt to extort an entity tethered to Boeing—the manufacturer of the aircraft piloted by his father’s employer—drew immediate cross-continental scrutiny, focusing the full glare of the FBI’s counter-cyber operations onto Amman.

Official Statements and Corporate Responses

The fallout from these combined breaches has elicited measured responses from the major multinational corporations caught in the crossfire:

  • Boeing Statement:

    "Chúng tôi đang nhận thức được các khiếu nại từ một tác nhân đe dọa liên quan đến dữ liệu bị cáo buộc gắn liền với Boeing và cựu công ty con Jeppesen ForeFlight của chúng tôi. Chúng tôi đang tích cực xem xét vấn đề với nhóm Jeppesen ForeFlight."
    (Translation: "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team.")

  • Jeppesen ForeFlight Statement:

    "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."

  • Neo Security Context:
    Following the dramatic arrest of Pepijn van der Stap, Neo Security owner Benjamin Korper confirmed that external forensic investigators were brought in to audit the firm’s systems. Initial findings revealed no evidence that Van der Stap compromised his employer or clients during his tenure, despite his concurrent covert activities.

    ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The Dark Underbelly: Accusations Beyond Data Theft

As the technical investigations into the ShinyHunters infrastructure unfold, parallel criminal proceedings in the Netherlands have introduced far darker allegations against individuals linked to the ecosystem.

Dutch daily newspaper RTL reported that investigators suspect Pepijn van der Stap attempted to orchestrate at least two contract murders abroad, allegedly issuing direct orders for the killings prior to his arrest. These developments frame a terrifying evolution within modern cybercrime syndicates, where digital extortion and data theft increasingly blur into physical-world violence and transnational organized crime.

Meanwhile, within underground Telegram channels like the tracker server "The Battle," online commentators have relentlessly mocked Khader for his amateurish operational security lapses. Cybersecurity analysts note that Khader’s decision to resurrect the burned ShinyHunters brand—coupled with his ultimate collapse under law enforcement pressure—demonstrates the inherent fragility of juvenile actors attempting to play in the upper echelons of global cybercrime.


Future Outlook

The neutralization and cooperation of Saif Al-din Khader marks a significant tactical victory for international law enforcement coalitions, underscoring the vulnerabilities inherent in decentralized cybercrime franchises.

Several key takeaways and forward-looking projections define the current cybersecurity landscape:

  1. The Death of Brand Perpetuation: Law enforcement agencies have proven exceptionally effective at tracking individuals who inherit legacy cybercriminal monikers. The collapse of the ShinyHunters brand under the weight of Khader’s arrest signals that "franchise hacking" carries an extraordinarily high probability of identification.
  2. Enterprise Supply-Chain Vigilance: The Oracle PeopleSoft zero-day campaign exposed catastrophic gaps in corporate patch management. Enterprises will face increased regulatory penalties for failing to apply critical software updates within standard remediation windows.
  3. Escalation of Kinetic Consequences: The intersection of corporate data extortion—such as the Jeppesen ForeFlight incident—with aviation safety metrics proves that cyber attacks against modern industrial titans will continue to command immediate, unyielding counter-intelligence responses from global superpowers.

As the FBI continues to dismantle the remaining fringes of the ShinyHunters affiliate network, the digital underground is forced to reckon with an uncomfortable reality: the digital boundaries separating suburban bedrooms in Amman from maximum-security federal indictments have never been thinner.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *