The Fall of ‘Rey’: Inside the Collapse and Franchise Chaos of the ShinyHunters Cybercrime Syndicate

Share
The Fall of ‘Rey’: Inside the Collapse and Franchise Chaos of the ShinyHunters Cybercrime Syndicate

Executive Overview

The sprawling, fractured landscape of international cybercrime has witnessed a seismic shift following the detention of a key teenage figure linked to the notorious data theft and extortion syndicate ShinyHunters. Jordanian authorities have detained Saif Al-din Khader—a young man operating under the online handle “Rey” out of Amman, Jordan. According to multiple intelligence and investigative sources, Khader is actively cooperating with the Federal Bureau of Investigation (FBI) to unmask and track down remaining nodes of the hacking collective.

The arrest comes at a volatile time for global cybersecurity. Khader was apprehended precisely as he and his criminal affiliates were deeply embedded in an aggressive extortion campaign targeting a newly divested business unit of aerospace giant Boeing. This high-stakes targeting inadvertently drew unprecedented geopolitical and familial complications, given that Khader’s father is reportedly employed by Royal Jordanian Airlines, a carrier heavily reliant on Boeing’s commercial fleet.

Simultaneously, the broader ShinyHunters enterprise has been unraveling under the weight of aggressive law enforcement coordination across multiple continents. The recent Dutch police arrest of 24-year-old Pepijn van der Stap—a purported "reformed" security professional allegedly moonlighted as an active ShinyHunters facilitator—ignited a chain reaction. Van der Stap’s capture prompted Rey to recklessly seize control of the dwindling ShinyHunters brand, launching brazen, memetic cyber-attacks against the FBI and the Cl0p ransomware syndicate.

This deep-dive investigation examines the anatomy of Rey’s rise and fall, the franchise-like mutation of the ShinyHunters network, the explosive real-world threats tied to its members, and the systemic software vulnerabilities that enabled a loose coalition of digital freelancers to hold global enterprises and government agencies hostage.


Detailed Chronology: From Zero-Day Exploits to International Detention

The Oracle PeopleSoft Campaign and FBI Infiltration

The genesis of the most recent ShinyHunters escalation traces back to June, when a collective of hackers began weaponizing a zero-day vulnerability, tracked as CVE-2026-35273, within Oracle PeopleSoft. Widely deployed across corporate enterprises, higher education, healthcare, and government sectors for human resources, payroll, and recruitment administration, PeopleSoft proved to be a lucrative wedge for the syndicate.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

In communications with security researchers at BleepingComputer, ShinyHunters admitted that their primary objective was breaching the FBI’s proprietary PeopleSoft database. Although initial direct strikes against the bureau faced roadblocks, the threat actors adapted. When Mandiant and the Google Threat Intelligence Group (GTIG) published emergency web application firewall (WAF) mitigation rules, the hackers simply bypassed them utilizing classic URL-encoding obfuscation tricks.

By late September, the mass-exploitation campaign had harvested sensitive data from dozens of organizations globally. Most damagingly, the vulnerability exposed the recruitment portal of the FBI itself. On October 5, international reports revealed that the FBI had summarily terminated an Accenture contractor over failures to patch the compromised server. The breach laid bare sensitive, restricted data concerning more than 5,000 FBI personnel, exposing precise specializations, unit assignments, and even confidential medical and psychiatric records.

The Van der Stap Raid and Rey’s Reckless Takeover

The operational walls began closing in on September 15. In a dramatic pre-dawn raid in Amsterdam utilizing flash-bang grenades, Dutch law enforcement detained Pepijn van der Stap. A convicted cybercriminal who had ostensibly rehabilitated into an "offensive security lead" at a Dutch firm named Neo Security, Van der Stap was accused of aiding ShinyHunters data thefts.

The moment Van der Stap’s handcuffs clicked, digital chaos ensued. Recognizing a vacuum in the underground hierarchy, Rey stepped forward. Seizing control of the historical ShinyHunters brand, PGP keys, and communication channels, Rey initiated a public relations war. He began flooding Twitter/X with taunting memes targeting both the FBI and the ruthless Cl0p ransomware gang. In a calculated maneuver designed to throw investigators off his trail, Rey embedded the digital avatars of "Umbreon"—Van der Stap’s former hacking alias—within his taunting posts, attempting to frame the imprisoned Dutchman for the bureau’s hacking.

The bravado was short-lived. Following a frantic series of warnings, the ShinyHunters darknet infrastructure vanished offline on September 30. Shortly thereafter, leaks from investigative sources confirmed that Saif Al-din Khader had been cornered in Amman, Jordan, and turned informant for the FBI.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Supporting Context & Metrics: The Franchise Model of Modern Cybercrime

The "Dread Pirate Roberts" of Extortion

Security experts emphasize that the modern iteration of ShinyHunters bears little structural resemblance to the original French-led collective that terrorized corporations between 2019 and 2021—most of whom have long since been identified, arrested, or imprisoned.

Instead, ShinyHunters has evolved into a criminal franchise model. Operating much like the mythical "Dread Pirate Roberts" of The Princess Bride, the brand survives through serial succession, where arrests simply pave the way for opportunistic freelancers to buy or inherit the moniker. Rather than an organized mafia, today’s ShinyHunters function as a decentralized affiliate network. Freelance hackers breach corporate Software-as-a-Service (SaaS) environments, hand off stolen session tokens or credentials to intermediary negotiators like Rey, and split the resulting ransoms—typically taking a 25% to 30% cut.

The Boeing-Jeppesen Nexus

The investigation into Rey gained explosive momentum due to his targeting of Jeppesen ForeFlight, a digital aviation and navigation unit divested by Boeing in November 2025 in a $10.55 billion buyout by private equity firm Thoma Bravo. The theft of sensitive aviation data introduced severe operational security risks, compelling federal investigators to fast-track the neutralization of the threat actors involved.

Adding a layer of dramatic irony, digital forensics uncovered deep personal contradictions in Rey’s operations. Evidence retrieved from malware compromises on his family’s shared computer revealed that Rey’s father utilized the exact same login credentials across multiple employee portals for Royal Jordanian Airlines. The airline operates its long-haul passenger fleet almost exclusively on aircraft manufactured by Boeing—the very company Rey was actively extorting.

Though Rey attempted to wipe his digital footprint—deleting his Twitter/X handles hours after inquiries were sent to his family—his public GitHub blog remained intact. Ironically, the blog featured an extensive doxing investigation authored by Rey himself, which unmasked two Russian nationals allegedly serving as the masterminds behind the Cl0p ransomware operation.

ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

Escalating Violence: Murder-for-Hire Allegations

While Rey faces legal reckoning in Jordan and cooperation agreements with the FBI, his erstwhile co-conspirator Pepijn van der Stap faces even graver allegations in the Netherlands. Dutch daily RTL reported that investigators suspect Van der Stap of orchestrating at least two international murder-for-hire plots.

These developments cast a chilling shadow over the tech media’s romanticized narratives of reformed hackers transitioning smoothly into legitimate corporate security roles. While executives at Neo Security maintained that internal audits found no evidence of malicious activity targeting their own clients, the revelation of alleged physical violence highlights the increasingly dangerous, volatile intersection of enterprise data extortion and transnational organized crime.


Official Statements & Industry Impact

The fallout from the ShinyHunters campaign has forced a public reckoning across corporate boardrooms, federal agencies, and cybersecurity vendors.

  • The FBI’s Flash Notice: In a May 2026 advisory (IC3 PSA260515), the bureau warned organizations against capitulating to ShinyHunters extortion demands, explicitly detailing the group’s aggressive harassment tactics. These have historically included direct phone calls, targeted text messaging to executives’ families, and dangerous physical "swatting" incidents.
  • The Hackers’ Defense: In interviews with The Register, surviving ShinyHunters representatives defended their breach of the FBI, framing it as a necessary counter-offensive. They claimed the hack was designed to "demonstrate our technical capabilities and directly refute the misinformation disseminated by the FBI," acknowledging that the bureau’s public warnings severely damaged their extortion conversion rates.
  • Corporate Responses: Boeing issued a measured statement acknowledging the extortion claims tied to its former subsidiary:

    " ক্ষুদ্র We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight. We are actively reviewing the matter with the Jeppesen ForeFlight team."

    ShinyHunters Extorted Boeing Spin-off Prior to Arrests – Krebs on Security

    Concurrently, Jeppesen ForeFlight insisted that internal investigations showed zero negative impact on operational workflows or aviation software products.


Future Outlook

The neutralization of Saif Al-din Khader and the ongoing prosecution of Pepijn van der Stap mark a severe blow to the current generation of ShinyHunters affiliates, but they are unlikely to eradicate the franchise model entirely. The ease with which young, digitally native actors can inherit historical cybercrime brands, leverage enterprise SaaS zero-days (such as the Oracle PeopleSoft flaw), and coordinate via Telegram channels ensures that digital extortion remains a persistent systemic threat.

For global enterprises, the episode serves as an unforgiving reminder that supply chain hygiene, rapid patch management, and strict access controls are no longer optional line items—they are the thin red line holding back a fluid, opportunistic underworld of digital mercenaries. As federal authorities continue to decode the intelligence provided by cooperating informants like Khader, the underground ecosystem of ransomware affiliates and data brokers faces an increasingly hostile and coordinated global manhunt.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *