News · Defence & Security

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

ShinyHunters suffered a major disruption after Jordanian authorities detained “Rey,” a teenager from Amman suspected of leading the group. The detention matters because Rey had taken control of the ShinyHunters brand after another suspected member was arrested in the Netherlands. He reportedly cooperated with the FBI after his arrest. According to sources, Rey was detained while ShinyHunters was extorting Boeing’s former Jeppesen ForeFlight unit. The group allegedly stole sensitive aviation-related information and threatened the company during the dispute. Rey had also publicly claimed hacks involving the FBI and ransomware group Cl0p. The investigation remains active. Reuters reported that Jordanian authorities detained Saif Al-din Khader, and KrebsOnSecurity identified him as Rey. His reported cooperation could help investigators identify additional hackers, understand the group’s operations, and connect attacks across many industries.

Based on reporting by Krebs Security

What happened to ShinyHunters, and why was its suspected leader, “Rey,” detained?

ShinyHunters suffered a major disruption after Jordanian authorities detained “Rey,” a teenager from Amman suspected of leading the group. The detention matters because Rey had taken control of the ShinyHunters brand after another suspected member was arrested in the Netherlands. He reportedly cooperated with the FBI after his arrest.

According to sources, Rey was detained while ShinyHunters was extorting Boeing’s former Jeppesen ForeFlight unit. The group allegedly stole sensitive aviation-related information and threatened the company during the dispute. Rey had also publicly claimed hacks involving the FBI and ransomware group Cl0p.

The investigation remains active. Reuters reported that Jordanian authorities detained Saif Al-din Khader, and KrebsOnSecurity identified him as Rey. His reported cooperation could help investigators identify additional hackers, understand the group’s operations, and connect attacks across many industries.

What is ShinyHunters, and how does a data-theft and extortion group operate?

ShinyHunters is a data-theft and extortion group. It breaks into organizations, copies sensitive information, and then threatens to publish or misuse that information unless the victim responds to its demands. This model creates pressure even when hackers do not encrypt systems or stop operations.

The group exploited a vulnerability in Oracle’s PeopleSoft platform, which organizations use for hiring, human resources, benefits, and payroll. After stealing data, ShinyHunters allegedly targeted victims across higher education, technology, healthcare, agriculture, transportation, and government. It also used public posts and memes to claim attacks and intimidate targets.

The group’s reported campaign shows why data theft can be powerful on its own. A stolen database may contain personal, medical, financial, or operational information. Investigators are now examining ShinyHunters’ members, victims, and methods, while organizations must patch exposed systems and strengthen monitoring.

How large was the campaign—how many organizations and people were potentially affected?

The campaign was broad, but the article does not give one exact total for all affected people or organizations. Mandiant and the Google Threat Intelligence Group said ShinyHunters stole data from dozens of systems across many industries. That makes the campaign significant because it reached beyond one sector or isolated victim.

The affected areas included higher education, technology, healthcare, agriculture, transportation, and government. Separately, the hacked FBI recruitment website exposed sensitive information on more than 5,000 FBI personnel. The exposed details reportedly included each person’s unit and specialization, plus medical and psychiatric records.

The confirmed figures show both organizational and personal risk. “Dozens” indicates many compromised systems, while the FBI case provides a concrete human impact. The article does not state the total number of people affected across the entire campaign, so the overall scale may be larger than the specifically reported FBI exposure.

What were Boeing’s former Jeppesen ForeFlight unit and its aviation-related data doing in the extortion dispute?

Jeppesen ForeFlight became an alleged extortion target after ShinyHunters claimed to possess data associated with the aviation company. Boeing had sold the unit to private equity firm Thoma Bravo in November 2025 for $10.55 billion. The dispute therefore involved a former Boeing business, not necessarily Boeing’s current operations.

Sources told KrebsOnSecurity that ShinyHunters stole sensitive information from the unit and threatened extortion. They said the data could create operational safety and security risks because the business provides navigation and digital aviation services. Boeing acknowledged the threat claims and said it was reviewing the matter with ForeFlight.

ForeFlight gave a more reassuring assessment. It said its investigation found no impact to operations or products and pointed to its proactive security posture. The case still shows why aviation data can attract attackers: even unconfirmed claims can trigger urgent reviews, legal concerns, and security action.

How did ShinyHunters use a PeopleSoft vulnerability, zero-day exploitation, and URL-encoding tricks to enter targeted systems?

A software vulnerability is a weakness attackers can exploit to enter or control a system. ShinyHunters used CVE-2026-35273 in Oracle’s PeopleSoft platform, which manages hiring, employee records, benefits, and payroll. The group reportedly began exploiting the flaw as a zero-day in June, before many organizations could install a fix.

Oracle issued a security update, and Mandiant published web application firewall rules for organizations unable to patch quickly. A web application firewall filters suspicious internet requests. ShinyHunters later used a known URL-encoding trick, which changes how characters are represented in a web address, to bypass those suggested rules and continue attacks.

Mandiant and Google said the group then mass-exploited the vulnerability across dozens of systems. The episode shows that temporary defenses can fail when attackers adapt. Organizations need rapid patching, layered controls, careful testing, and monitoring for unusual requests rather than relying on one protection.

What can happen when hackers steal sensitive employee, government, or aviation data and threaten to publish it?

When hackers steal sensitive data, the damage can continue long after the initial break-in. Personal records may expose employees to privacy violations, embarrassment, fraud, or targeted scams. Government information can reveal personnel roles and specialties, while medical records are especially sensitive. Threats to publish the data add immediate pressure.

The FBI recruitment website illustrates the risk. ShinyHunters reportedly exposed information on more than 5,000 FBI personnel, including unit assignments, specializations, and medical and psychiatric records. In the aviation case, sources warned that stolen information could pose operational safety and security risks, although ForeFlight said its operations and products were unaffected.

Extortion also forces victims to investigate, notify affected people, coordinate with authorities, and assess whether systems remain safe. Public claims can damage confidence even before every detail is confirmed. The article shows why organizations need strong access controls, fast patching, monitoring, response plans, and careful handling of sensitive records.

What are software vulnerabilities, security patches, and web application firewalls, and why are all three important for defending against attacks?

A software vulnerability is a mistake or weakness that attackers can use to access data or perform actions they should not control. A security patch is an update that fixes that weakness. A web application firewall, or WAF, examines web traffic and blocks requests that look malicious. Each defense addresses a different part of the problem.

In this case, ShinyHunters exploited PeopleSoft vulnerability CVE-2026-35273. Oracle released a fix, while Mandiant offered WAF rules for organizations that could not patch immediately. Those rules were useful as a temporary barrier, but ShinyHunters later used URL encoding to bypass them and continue attacks.

The lesson is that no single defense is enough. Patches remove the underlying weakness, while WAFs can reduce exposure during the response window. Organizations also need monitoring, testing, access controls, and response plans. Fast updates matter because zero-day exploitation can begin before defenders have a fix.

Key Facts:

📌 Jordanian authorities detained suspected ShinyHunters leader Rey in Amman.

📌 Rey was reportedly cooperating with the FBI after his detention.

📌 His arrest came during an alleged extortion attempt involving Boeing’s former aviation unit.

📌 ShinyHunters steals data and threatens to publish it.

📌 The group targeted organizations across numerous industries.

📌 Its tactics included exploitation, extortion, and public intimidation.

📌 ShinyHunters mass-exploited systems across dozens of organizations.

More on JupiteX