A Notorious Hacking Group’s Extortion Scheme Unravels as Key Suspect is Detained
A significant development has unfolded in the ongoing saga of ShinyHunters, a prolific data theft and extortion group that has been making headlines for months. According to reports, a teenager from Amman, Jordan, suspected of leading ShinyHunters, has been detained by Jordanian authorities and is reportedly cooperating with the FBI to identify other members of the hacking gang.
The suspect, who uses the hacker handle “Rey,” was allegedly in the process of extorting a business unit recently divested by Boeing, the global aerospace company. The unit, Jeppesen ForeFlight, was sold to private equity firm Thoma Bravo for $10.55 billion last year. Rey’s father works at Royal Jordanian Airlines, which uses planes manufactured by Boeing.
ShinyHunters gained notoriety in June when it began exploiting a vulnerability (CVE-2026-35273) in PeopleSoft, a software-as-a-service platform from Oracle. The hackers used this exploit to gain access to the FBI’s website and other victims’ systems. In recent weeks, ShinyHunters adapted their tactics by employing a well-known URL-encoding trick to bypass security measures put in place by Mandiant and Google Threat Intelligence Group.
The group’s methods have allowed them to steal sensitive data from dozens of organizations across various industries, including higher education, technology, healthcare, agriculture, transportation, and government. In one notable incident, ShinyHunters exposed sensitive information on over 5,000 FBI personnel, including their unit, specialization, medical records, and psychiatric notes.
The attempted extortion of the former Boeing unit is believed to have been in progress when Rey was apprehended by Jordanian authorities. The investigation into ShinyHunters has gained renewed urgency due to the group’s alleged theft of sensitive information that could pose operational safety and security risks.
Boeing acknowledged the extortion attempts by ShinyHunters, stating that the incident concerned data stolen from Jeppesen ForeFlight. While the full extent of the compromised data is not yet clear, it is evident that ShinyHunters’ activities have far-reaching implications for organizations across various industries.
The detention of Rey and potential cooperation with the FBI may be a significant blow to ShinyHunters’ operations. However, it remains to be seen whether this development will lead to a decline in the group’s activities or merely disrupt their plans temporarily. As the investigation unfolds, one thing is certain: organizations must remain vigilant and proactive in protecting themselves against such threats.
In light of these events, we urge readers to prioritize patching vulnerabilities in software-as-a-service platforms like PeopleSoft and to implement robust security measures to prevent data theft and extortion attempts. Stay informed about emerging threats and take steps to fortify your organization’s defenses against the ever-evolving landscape of cyber threats.
Source: Krebs on Security — 2026-10-07