Alleged ShinyHunters Leader Detained in Jordan, Cooperating with FBI

Teen suspect linked to extortion of Boeing business unit and Oracle PeopleSoft hacks

By LineZotpaper
Published
Read Time2 min
A teenager from Amman, Jordan suspected of leading the ShinyHunters hacking group has been detained and is cooperating with the FBI, according to sources cited by Reuters and reporting by KrebsOnSecurity. The suspect, who uses the alias "Rey" and has been identified as Saif Al-din Khader, was arrested as the group was in the process of extorting a business unit recently divested by aerospace giant Boeing.

A teenager from Amman, Jordan suspected of leading the data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang, according to sources cited by Reuters. The suspect, who uses the hacker handle "Rey" and has been identified by KrebsOnSecurity as Saif Al-din Khader, was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's father — Royal Jordanian Airlines.

KrebsOnSecurity first identified Rey as Khader in a November 2025 profile, in which the young man admitted working with multiple ransomware groups. On September 28, KrebsOnSecurity reported that Dutch police arrested 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding in data thefts and extortions by ShinyHunters. The story noted that immediately following the Dutchman's arrest on September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the FBI and extorting the ransomware group Cl0p.

Rey taunted both the FBI and Cl0p with memes posted to his Twitter/X account, while simultaneously including images of the avatar used by Van Der Stap's former hacker alias "Umbreon" in an apparent attempt to frame the Dutchman for both hacks.

As previously reported, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability in PeopleSoft, a software-as-a-service platform from Oracle that is broadly used to manage hiring, human resources, benefits, and payroll. Oracle quickly issued a fix for the vulnerability, which ShinyHunters first began exploiting as a zero-day in June, and Mandiant released web application firewall rules for organizations that could not apply the security update quickly enough.

§

Analysis

Why This Matters

  • The detention of a key suspect in a prolific hacking group highlights a potential breakthrough in international cyber investigations
  • The extortion of a Boeing business unit underscores the vulnerability of critical infrastructure and supply chain companies
  • This case illustrates the increased cooperation between foreign authorities and the FBI in pursuing cybercriminals

Background

ShinyHunters is a hacking group known for large-scale data theft and extortion operations targeting companies globally. The group has been linked to breaches of major organizations, leveraging vulnerabilities in widely used enterprise software like Oracle's PeopleSoft platform. The group's operations often involve exfiltrating sensitive data and demanding ransom payments, with recent attacks exploiting zero-day vulnerabilities.

Key Perspectives

Law Enforcement (FBI, Jordanian authorities): Focused on dismantling the hacking network and gathering intelligence on remaining members through cooperating suspects ShinyHunters members: The group's sustainability is threatened by the detention and cooperation of a leader; other members may evade detection or face increased pressure Victims (Boeing, FBI, other companies): Face potential data exposure and operational disruption; they likely seek to recover compromised data and prevent future attacks Critics/Skeptics: The effectiveness of cooperation may be limited if the suspect's information is incomplete or if other group members are not extradited

What to Watch

  • Whether the suspect's cooperation leads to further arrests or seizures of assets
  • Boeing's response to the attempted extortion and any data breach notifications
  • Oracle's and Mandiant's efforts to secure PeopleSoft against future vulnerabilities

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.