A Prolific Hacker Gang’s Extortion Plot Foiled, But Questions Remain About Sensitive Data Stolen from Boeing Spin-off
The global aerospace company Boeing has been at the center of a cybersecurity storm after it was revealed that a notorious hacker gang, ShinyHunters, had been attempting to extort sensitive information from one of its former subsidiaries. The twist? The suspected leader of the hacking group, who uses the alias “Rey,” is none other than a teenager from Amman, Jordan whose father works for Royal Jordanian Airlines, which is also a Boeing client.
ShinyHunters has been making headlines in recent months due to their brazen data thefts and extortion attempts. The group’s exploits have included breaching the FBI’s own website, stealing sensitive information from Accenture contractors, and extorting other victims using clever tactics such as URL-encoding tricks to bypass security measures.
According to sources familiar with the investigation, ShinyHunters had gained access to the data of a Boeing spin-off company called Jeppesen ForeFlight, which was recently divested by Boeing. The hackers were attempting to extort sensitive information that could pose operational safety and security risks to aviation operations. However, before they could carry out their plans, Rey was detained by Jordanian authorities on October 3rd.
Rey’s arrest has raised questions about the extent of ShinyHunters’ reach and the vulnerabilities exploited by the group. The hacking gang had been using a vulnerability (CVE-2026-35273) in Oracle’s PeopleSoft platform to breach multiple systems across various industries, including higher education, technology, healthcare, agriculture, transportation, and government.
The FBI has since removed a contractor at Accenture over their failure to patch the FBI recruitment website hacked by ShinyHunters. This incident highlights the importance of timely patching and vulnerability management in preventing such data breaches.
Boeing has acknowledged the attempted extortion by ShinyHunters but has not disclosed further details about the extent of the breach or what sensitive information was stolen. The incident serves as a stark reminder that even well-established companies like Boeing can fall victim to sophisticated cyber threats.
As the investigation into ShinyHunters continues, one thing is clear: the hacking gang’s exploits have left a trail of vulnerabilities and exposed data in their wake. For organizations, this serves as a timely reminder to prioritize cybersecurity measures, including patching, vulnerability management, and employee education.
In practical terms, businesses can take several steps to mitigate the risk of such attacks:
* Ensure that all software and systems are up-to-date with the latest security patches.
* Implement robust web application firewall rules to prevent unauthorized access.
* Educate employees on cybersecurity best practices and phishing threats.
* Conduct regular vulnerability assessments and penetration testing.
By taking these measures, organizations can reduce their exposure to cyber threats like those posed by ShinyHunters.
Source: Krebs on Security — 2026-10-07