The Fall of "Rey": How an Amman Teenager, a Brand of Extortion, and a Cascading Global Hack Upended Cybersecurity

Share
The Fall of "Rey": How an Amman Teenager, a Brand of Extortion, and a Cascading Global Hack Upended Cybersecurity

Executive Overview

The sprawling, decentralized ecosystem of global cybercrime has suffered another high-profile fracture. Saif Al-din Khader—a teenager operating from Amman, Jordan, under the hacker handle “Rey”—has been detained by local authorities and is reportedly cooperating extensively with the Federal Bureau of Investigation (FBI). Khader is suspected of acting as a principal mastermind behind the modern iteration of ShinyHunters, a prolific data theft and extortion syndicate responsible for pilfering billions of records across multiple industry sectors over the last half-decade.

Rey’s apprehension occurred precisely as the syndicate was deep in the process of extorting a digital aviation and navigation business unit recently divested by global aerospace titan Boeing. This specific targeting added profound geopolitical and operational urgency to international law enforcement efforts. The arrest follows a chaotic summer of mass-exploitation campaigns targeting zero-day vulnerabilities in Oracle PeopleSoft software, high-stakes public taunts directed at the FBI and the Cl0p ransomware collective, and the dramatic police raids of alleged co-conspirators across Europe.

As investigators peel back the layers of Rey’s digital footprint, the case exposes a shifting underworld model: the franchising of notorious cybercriminal brands. Much like the cinematic "Dread Pirate Roberts," contemporary syndicates like ShinyHunters operate less as rigid hierarchies and more as decentralized holding companies. In this franchise model, aspiring young hackers can purchase digital credentials, inherit historical pgp keys, and lease the terrifying reputation of an established moniker to amplify their own extortion payouts.


Detailed Chronology: From Zero-Day Exploits to the Amman Arrest

The modern saga of ShinyHunters’ latest incarnation accelerated rapidly in mid-2025 and 2026, pivoting on a devastating software flaw, daring counter-attacks against federal law enforcement, and a rapid succession of international arrests.

The PeopleSoft Zero-Day Campaign

In June 2026, threat actors associated with the ShinyHunters brand began mass-exploiting a critical zero-day vulnerability—designated as CVE-2026-35273—in Oracle PeopleSoft, a widely deployed Software-as-a-Service (SaaS) platform utilized by global enterprises for human resources management, payroll, and recruitment tracking.

While Oracle scrambled to release security patches, and security firms like Mandiant rushed to publish web application firewall (WAF) mitigation rules, the hackers adapted. Utilizing a well-known URL-encoding technique to bypass WAF defenses, the attackers successfully breached dozens of high-profile networks across higher education, healthcare, technology, agriculture, transportation, and government sectors.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

A joint threat intelligence report released on September 25, 2026, by Mandiant and the Google Threat Intelligence Group (GTIG) confirmed the massive scope of the data theft campaign. Concurrently, investigative reports revealed that the FBI’s own recruitment portal had been compromised via an unpatched contractor system at Accenture, exposing sensitive personal, medical, and psychiatric records of over 5,000 FBI personnel.

The Hijacking of a Brand

The high-water mark of the syndicate’s defiance occurred in mid-September 2026. On September 15, Dutch police executed a dramatic flash-bang raid in Amsterdam, arresting 24-year-old Pepijn van der Stap—a previously convicted cybercriminal who had managed to integrate himself into legitimate cybersecurity circles under the alias "Umbreon."

Immediately following Van der Stap’s arrest, Rey seized absolute control of the ShinyHunters online assets. Operating from Amman, Rey launched a brazen public relations blitz. He claimed responsibility for hacking the FBI and extorting the notorious Cl0p ransomware group. Utilizing his long-standing Twitter/X handle, Rey posted mocking memes incorporating Umbreon’s avatar, attempting to frame the imprisoned Dutchman for the attacks while simultaneously negotiating ransoms and cycling through data-leaking forums.

The Net Closes: Amman and Amsterdam

International pressure mounted rapidly. On October 3, Reuters cited three intelligence sources confirming that Saif Al-din Khader had been detained by Jordanian authorities and was actively cooperating with the FBI.

Concurrently, explosive allegations emerged from the Netherlands regarding Van der Stap. Dutch daily newspaper RTL reported on September 29 that investigators suspected Van der Stap of orchestrating at least two contract murders abroad, shattering the narrative of his successful post-prison rehabilitation as an "offensive security lead" at Neo Security.


Supporting Context & Metrics: The Anatomy of a Cyber Franchise

The evolution of ShinyHunters illustrates a fundamental structural shift in modern cybercrime. Understanding how a teenager in Jordan managed to steer one of the world’s most feared cyber extortion syndicates requires examining the mechanics of brand franchising, family data exposure, and collateral fallout.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

The "Dread Pirate Roberts" Cyber Model

The original core members of ShinyHunters—predominantly French nationals—were largely rounded up and imprisoned by European law enforcement agencies for breaches dating back to 2019. However, rather than dying out, the brand lived on.

Security researchers note that modern cyber syndicates frequently operate via "franchising." Freelance threat actors and affiliate groups purchase legacy PostgreSQL databases, PGP keys, and forum administrative rights to inherit historical intimidation capital. Rey, operating under various aliases, reportedly coordinated with 5 to 6 affiliate friend groups, leveraging the ShinyHunters name to negotiate corporate ransom payouts while taking a 25% to 30% cut.

The Boeing-Jeppesen Nexus

The investigation gained existential urgency for Western intelligence agencies when Rey’s syndicate targeted a navigation and digital aviation business unit recently divested by Boeing: Jeppesen ForeFlight.

Boeing had sold Jeppesen ForeFlight to private equity firm Thoma Bravo in November 2025 for $10.55 billion. The theft of sensitive navigation and flight operations data from such an entity posed severe operational safety and security risks.

Intriguingly, digital forensics revealed an intimate personal irony: Rey is the son of an employee at Royal Jordanian Airlines, a government-controlled carrier whose long-haul fleet relies entirely on Boeing passenger aircraft. Previous malware compromises of the Khader family’s shared home computer revealed that Rey’s father had repeatedly used identical credential sets across employee portals for the airline. When contacted by investigative journalists prior to the Amman raids, Rey abruptly purged his social media presence, though his technical blog on GitHub—which notably dozed the core Russian developers behind the Cl0p ransomware group—survived the purge.

Summary of Key Incidents and Entities

Entity / Actor Role / Affiliation Impact / Status
Saif Al-din Khader ("Rey") Amman-based teenager; ShinyHunters admin Detained in Amman, Jordan; cooperating with the FBI.
Pepijn van der Stap ("Umbreon") Dutch cybercriminal / Neo Security employee Arrested in Amsterdam; facing data theft and suspected murder-for-hire charges.
Jeppesen ForeFlight Aviation navigation subsidiary divested by Boeing Targeted by ShinyHunters for high-risk data extortion; operations unaffected.
Oracle PeopleSoft Enterprise SaaS platform Exploited via zero-day (CVE-2026-35273) to target hundreds of global networks.
Cl0p Ransomware Group Established Russian-speaking extortion syndicate Extorted and publicly doxed by Rey via GitHub investigative blog posts.

Official Statements and Industry Reactions

The cascading disclosures surrounding the Oracle PeopleSoft breaches, the FBI recruitment portal compromise, and the subsequent arrests have prompted guarded responses from corporate and governmental stakeholders.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security
  • Boeing Corporate Communications:

    "We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."

  • Jeppesen ForeFlight Management:

    "Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products."

  • The FBI Flash Notice (May 2026):
    Prior to the network breaches, the FBI issued an advisory warning victims against paying ransoms to the ShinyHunters syndicate. The bureau highlighted the group’s aggressive harassment tactics—ranging from harassing phone calls and text messages to corporate executives, to physical swatting incidents and the circulation of fabricated compromising media.

  • The Register Interview with ShinyHunters:
    In communications with technology journalists, representatives of the hacking collective defended their breach of the FBI recruitment database as a necessary counter-offensive. They claimed the attack served as a vital "public relations and marketing initiative" designed to undermine the credibility of federal cybersecurity warnings that had adversely impacted their ransom conversion rates.

    ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Future Outlook: The Waning Power of Extortion Brands

The detainment of Saif Al-din Khader in Jordan and the incarceration of Pepijn van der Stap in the Netherlands mark a turning point for modern cybercrime enforcement. However, cybersecurity analysts caution that dismantling individual nodes does little to eliminate the underlying economic engine of digital extortion.

  1. Erosion of Cyber Brands: The public ridicule faced by Rey on underground Telegram channels—such as the channel "The Battle"—highlights a growing fatigue within cybercrime forums regarding amateurs who buy legacy brands simply to inflate their perceived technical prowess. When brand names become radioactive due to intense law enforcement focus, threat actors will inevitably pivot to fresh, unnamed configurations.
  2. Hardening SaaS Supply Chains: The Oracle PeopleSoft zero-day crisis demonstrated that enterprise reliance on centralized human resources and recruitment platforms remains an acute single point of failure. Organizations must accelerate zero-trust architectures, enforce rigorous patch management schedules, and audit third-party contractor access continuously.
  3. Cross-Border Intelligence Sharing: The successful cooperation between Jordanian authorities, Dutch national police, and the FBI underscores the increasing efficacy of international coalitions in tracking down teenage cyber elites who previously believed geographic boundaries offered absolute immunity.

As the legal proceedings against Khader and Van der Stap advance, the digital underworld is forced to reckon with an uncomfortable reality: operating under the shadow of a famous hacker handle is no longer a shield against the reach of global law enforcement.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *