Sécurité et confidentialité

ShinyHunters leader detained during Boeing unit extortion attempt

Jordanian authorities arrested Saif Al-din Khader, known as Rey, while ShinyHunters extorted Jeppesen ForeFlight. The group exploited a PeopleSoft zero-day to breach multiple organizations.

Illustration of a WAF shield failing to block a malicious URL string
Illustration générée pour cet article

Cet article est disponible uniquement en anglais.

Jordanian authorities have detained Saif Al-din Khader, a teenager from Amman suspected of leading the data theft and extortion group ShinyHunters. The arrest occurred in early October 2026 while the group was actively extorting Jeppesen ForeFlight, a navigation and digital aviation unit recently divested by Boeing. Khader, who operates under the handle "Rey," is reportedly cooperating with the FBI to identify other members of the criminal network.

What happened

The detention marks a significant blow to ShinyHunters, a group that has evolved into a franchise-like operation following the arrests of its original French core members. According to sources familiar with the investigation, the FBI prioritized the case after ShinyHunters targeted Jeppesen ForeFlight. The stolen data allegedly included sensitive information posing operational safety and security risks. Boeing confirmed the extortion attempts involving its former subsidiary, which it sold to Thoma Bravo for $10.55 billion in November 2025. Jeppesen ForeFlight stated that its investigation found no impact on operations or products.

Khader’s arrest follows the September 15 detention of Pepijn van der Stap, a 24-year-old Dutch cybercriminal accused of aiding ShinyHunters. Immediately after van der Stap’s arrest, Khader assumed public control of the ShinyHunters brand. He boasted on social media about stealing data from the FBI and extorting the ransomware group Cl0p. In an apparent effort to frame van der Stap, Khader posted memes featuring the Dutchman’s former hacker alias avatar, "Umbreon." However, within hours of being contacted for comment regarding his son’s activities, Khader began deleting his social media profiles, though his GitHub blog remained accessible.

The group’s recent activities relied heavily on exploiting a critical vulnerability in Oracle’s PeopleSoft platform. ShinyHunters used this access to breach dozens of systems across healthcare, government, and technology sectors. The FBI removed an Accenture contractor after the firm failed to patch the FBI recruitment website, resulting in the exposure of sensitive records for over 5,000 personnel. This failure highlighted the severe consequences of delayed patching in enterprise environments.

How it works

ShinyHunters gained initial access to many victims by exploiting CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft. This software-as-a-service platform is widely used for human resources, payroll, and benefits management. Oracle issued a fix in June 2026, and Mandiant released web application firewall (WAF) rules to protect organizations that could not immediately update their systems. However, ShinyHunters developers discovered a URL-encoding trick that bypassed these WAF rules, allowing them to continue mass-exploiting unpatched systems weeks after the initial disclosure.

The group operates less as a unified team and more as a network of affiliates. Freelancers feed stolen credentials from various SaaS platforms into the ShinyHunters infrastructure. In exchange, they receive a percentage of any ransoms paid by victims. This model allows the brand to persist even as key operators are arrested. Recent analysis suggests that Khader purchased old forum PGP keys to legitimize his claim to the ShinyHunters name, using the established reputation to negotiate deals and sell stolen data.

Key details

  • Suspect Saif Al-din Khader, known as "Rey," was detained in Amman, Jordan, in early October 2026.
  • The arrest coincided with an extortion attempt against Jeppesen ForeFlight, a former Boeing subsidiary.
  • ShinyHunters exploited CVE-2026-35273 in Oracle PeopleSoft, bypassing Mandiant WAF rules via URL encoding.
  • The FBI removed an Accenture contractor after a patching failure exposed data on 5,000+ FBI personnel.
  • Khader attempted to frame arrested Dutch hacker Pepijn van der Stap for recent high-profile breaches.
  • ShinyHunters now operates as a franchise, with affiliates earning 25–30% cuts of ransom negotiations.

Why it matters

For software engineers and IT leaders, this incident underscores the critical importance of rapid patch management and the limitations of virtual patches. While web application firewalls provide a temporary shield, they are not foolproof. ShinyHunters’ ability to bypass Mandiant’s rules demonstrates that determined attackers will find workarounds for known vulnerabilities. Relying solely on WAFs without applying vendor updates leaves organizations exposed to sophisticated exploitation techniques like URL encoding tricks.

The evolution of ShinyHunters into a franchise model also changes the threat landscape. Security teams can no longer assume that arresting a few high-profile leaders will dismantle the group. The decentralized nature of the operation means new actors can easily adopt the brand and continue attacks using stolen credentials and established infrastructure. This persistence requires continuous monitoring of credential leaks and robust access controls, rather than relying on the disruption of specific criminal individuals.

What you can do

  • Prioritize patching for Oracle PeopleSoft and other critical SaaS platforms immediately upon release.
  • Do not rely exclusively on WAF rules for long-term protection against known CVEs.
  • Audit third-party vendors and contractors for compliance with security patching schedules.
  • Monitor for leaked credentials associated with your organization’s SaaS accounts.
  • Implement multi-factor authentication to mitigate risks from stolen login details.
  • Review access logs for unusual URL encoding patterns that may indicate exploitation attempts.

Outils de la Boutique Bytechap

Continuer la lecture

Tous les articles