ShinyHunters Suspect Detained as Boeing Reviews Separate Jeppesen ForeFlight Data Claims

Sources allege ShinyHunters operator Rey sought to extort Jeppesen ForeFlight as Boeing reviews claims; detention and data theft remain unconfirmed.

ShinyHunters Suspect Detained as Boeing Reviews Separate Jeppesen ForeFlight Data Claims
Ransomware

Illustrative image generated with AI

Alleged extortion targeted a business Boeing sold in November 2025

A suspected ShinyHunters operator known as “Rey” was detained while the cybercrime group was allegedly trying to extort Jeppesen ForeFlight, according to two sources familiar with the investigation cited by KrebsOnSecurity.

Jeppesen ForeFlight provides navigation and digital aviation services. Boeing sold the business to private-equity firm Thoma Bravo for $10.55 billion in November 2025.

The two sources alleged that sensitive information had been stolen and said its contents could create operational safety and security risks. Those assertions have not been independently established in the supplied reporting, which does not demonstrate what data, if any, was obtained.

Boeing confirmed that it knew of a threat actor’s claims concerning data allegedly associated with the company and its former subsidiary. It said it was reviewing the matter with Jeppesen ForeFlight, without confirming that an intrusion or data theft had occurred.

Jeppesen ForeFlight said its investigation had found no effect on its products or operations. That statement addresses the operational impact identified by the company, but does not determine whether information was accessed or removed.

The sources placed the alleged extortion attempt around Rey’s detention. No date is provided for any underlying intrusion, and the reporting does not link the Jeppesen ForeFlight matter to the separate exploitation of Oracle PeopleSoft described below.

Reuters identified the detained suspect as Saif Al-din Khader

Reuters reported on October 3 that Jordanian authorities had detained Saif Al-din Khader in Amman. Citing three unnamed sources, the news agency also reported that Khader was cooperating with the FBI.

The supplied material does not independently confirm the detention or cooperation. The October 3 date refers to Reuters’ report, not necessarily the date on which authorities acted.

KrebsOnSecurity had identified Khader as Rey in a November 2025 profile. In that earlier account, he acknowledged working with multiple ransomware groups.

The publication reported that Rey assumed control of the ShinyHunters name immediately after Dutch authorities arrested Pepijn van der Stap, 24, on the evening of September 15. Rey subsequently claimed to possess highly sensitive FBI information and issued threats against the Cl0p ransomware group.

He posted taunting material through a long-used Twitter/X account, including images associated with Van der Stap’s former alias, Umbreon. One meme described in the reporting was posted on September 22. Rey later withdrew his threats against the FBI and Cl0p, according to the account.

His public statements do not prove that he stole FBI data.

The reporting also describes evidence that Rey’s father used shared credentials to access multiple Royal Jordanian Airlines employee portals. That evidence came from data collected after password-stealing malware compromised the Khader family’s shared computer. It supports the account of portal access, but does not independently establish the father’s job title.

ShinyHunters functions as a changing brand, complicating attribution

Experts cited in the reporting distinguish the recent users of the ShinyHunters identity from the group’s earlier core membership. Many of the original participants were French citizens who had previously been arrested or imprisoned over alleged cybercrime.

Sources close to the investigation characterized the current structure as a loose network of operators and affiliates rather than an organization with continuous membership. They said the FBI was focusing on a remaining handful of freelancers or affiliates who allegedly supplied stolen credentials for access to software-as-a-service platforms used by major companies. In return, they reportedly received a share of ransom payments.

That account does not mean the credentials were stolen from the SaaS providers themselves.

Breaches claimed under the ShinyHunters name extend back to at least 2019. The reporting associates aligned cybercriminals with dozens of breaches involving billions of stolen records, but those aggregate figures cannot be assigned to Jeppesen ForeFlight, Rey or any single current operator.

A participant in a Telegram community allegedly run by Rey offered a further, unverified description of his activities. The participant claimed Rey obtained an older forum’s PGP key and used it to establish BreachForums sites and Telegram channels while impersonating ShinyHunters, extorting companies and selling or reselling data or forums. That remains an allegation by one community participant.

Van der Stap’s case creates an additional attribution issue. He was arrested in the Netherlands on suspicion of assisting ShinyHunters data thefts and extortion, according to an account published September 28. RTL separately reported on September 29 that investigators suspected him of attempting to arrange at least two murders abroad and believed there were indications he had ordered the attacks. Those claims are allegations attributed to RTL.

CVE-2026-35273 enabled remote PeopleSoft takeover

Separately from the Jeppesen ForeFlight allegations, ShinyHunters has been linked to exploitation of CVE-2026-35273, a critical vulnerability in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools.

NVD’s description identifies 8.61 and 8.62 as supported affected versions. A separate product-and-version field in the supplied NVD material lists only 8.61; the two entries are therefore not consistent.

The vulnerability carries a CVSS v3.1 base score of 9.8 and the following vector:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

It is classified as CWE-306. According to NVD, an unauthenticated attacker with network access over HTTP can exploit the flaw without user interaction. A successful attack can take over PeopleSoft Enterprise PeopleTools, with high potential impact on confidentiality, integrity and availability.

KrebsOnSecurity reported that ShinyHunters began exploiting the flaw as a zero-day in June. The relevant passage does not give a year. Oracle then issued a security update, while Mandiant supplied web application firewall rules for organizations that could not install the update promptly.

The reporting says ShinyHunters later applied a URL-encoding technique to bypass those WAF rules. They should consequently be treated as an interim control, not a replacement for Oracle’s update.

ShinyHunters told BleepingComputer in June that its initial objective had been to compromise the FBI’s PeopleSoft database. The group said those attempts were unsuccessful.

In a report released September 25, Mandiant and Google Threat Intelligence Group said ShinyHunters had exploited CVE-2026-35273 at scale, stealing data from dozens of systems. The affected sectors included higher education, technology, healthcare, agriculture, transportation and government.

CISA imposed a 2026-06-15 federal remediation deadline

CISA added CVE-2026-35273 to its Known Exploited Vulnerabilities catalog on 2026-06-12, making its exploitation an observed threat rather than a merely theoretical risk. The remediation deadline for U.S. federal agencies was 2026-06-15. The vulnerability is also recorded as used in ransomware campaigns.

CISA’s required action calls for mitigations consistent with vendor instructions and compliance with BOD 26-04 Prioritizing Security Updates Based on Risk and the agency’s Forensics Triage Requirements.

For cloud services, organizations must follow the applicable BOD 26-04 guidance or discontinue using the product if mitigations are unavailable. Stakeholders are also responsible for assessing each asset’s internet exposure and adhering to the patching guidance in BOD 26-04.

Administrators should apply Oracle’s security update to affected PeopleSoft Enterprise PeopleTools deployments. The supplied material does not identify a fixed-version number, so operators should follow Oracle’s instructions rather than assume a particular version threshold.

Organizations using Mandiant’s WAF rules should account for the reported URL-encoding bypass. No specific domains, IP addresses or file hashes are included in the supplied material.

CVE-2026-35273 is not Oracle’s only recent KEV entry. The catalog also added CVE-2015-5287 on 2026-08-26, CVE-2026-21962 on 2026-08-24 and CVE-2026-46817 on 2026-07-15.

FBI recruitment-site exposure is a separate reported incident

Reuters reported on October 5 that the FBI had removed an Accenture contractor over a failure to patch an FBI recruitment website targeted by ShinyHunters.

According to Reuters, the exposure affected more than 5,000 FBI personnel. That figure counts people, not individual records. The compromised information reportedly included personnel units and specializations, along with medical and psychiatric records.

This incident should not be merged with ShinyHunters’ claimed attempt to enter the FBI’s PeopleSoft database. The group described the PeopleSoft attempts as unsuccessful, while Reuters reported a successful exposure involving a recruitment website and a patching failure.

The supplied account does not provide technical evidence showing that CVE-2026-35273 was used against the recruitment site. It also does not establish that the PeopleSoft attempts and recruitment-site compromise formed a single operation or involved precisely the same individuals.

The distinction matters for response planning. One matter concerns demonstrated mass exploitation of a critical Oracle vulnerability; the other is a separately reported website exposure affecting more than 5,000 personnel.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →