CVE-2026-35273 — a PeopleSoft vulnerability that ShinyHunters began exploiting as a zero-day in June — fueled a wave of data thefts that culminated in an alleged extortion attempt against a recently divested Boeing business unit and the detention of a suspected ShinyHunters leader in Amman, Jordan.
A teenager called “Rey” detained in Amman and reportedly cooperating with the FBI
KrebsOnSecurity reports that a teenager from Amman who uses the hacker handle “Rey” was detained by Jordanian authorities and is reportedly cooperating with the FBI. Reuters cited three unnamed sources on October 3 saying a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained and cooperating; KrebsOnSecurity had identified Rey as Khader in a November 2025 profile.
Sources familiar with the investigation told KrebsOnSecurity that Rey was in the process of extorting a navigation and digital aviation unit that Boeing sold in November 2025 when he was apprehended. Those sources said the FBI’s probe gained renewed urgency because the alleged extortion included theft of sensitive information that could pose operational safety and security risks.
The reporting also ties Rey’s family to aviation: there is strong evidence his father works for Royal Jordanian Airlines, and malware recovered from a shared family computer showed the father used the same credentials to log in to multiple Royal Jordanian employee portals. Rey had claimed on Telegram in early 2025 that his father was an airline pilot; that claim could not be independently confirmed, KrebsOnSecurity reported.
Jeppesen ForeFlight extortion — Boeing and the seller respond
KrebsOnSecurity’s sources and statements from the companies name Jeppesen ForeFlight as the divested unit targeted in the alleged extortion. Boeing acknowledged the claims in a brief statement: “We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight,” and added, “We are actively reviewing the matter with the Jeppesen ForeFlight team.”
Boeing sold Jeppesen ForeFlight in November 2025 to private equity firm Thoma Bravo for $10.55 billion. A Jeppesen ForeFlight spokesperson said in writing, “Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleHow CVE-2026-35273 and WAF workarounds enabled mass thefts
Security firms say the PeopleSoft vulnerability tracked as CVE-2026-35273 was the entry point for the breaches. Oracle issued a fix for CVE-2026-35273 after ShinyHunters began exploiting it as a zero-day in June. Mandiant published web application firewall (WAF) rules for organizations that could not apply the security update immediately.
Mandiant and the Google Threat Intelligence Group (GTIG) confirmed in a Sept. 25 report that ShinyHunters had mass-exploited the PeopleSoft flaw to steal data from dozens of systems across higher education, technology, healthcare, agriculture, transportation and government. In recent weeks, the group reportedly used a well-known URL-encoding trick to bypass Mandiant’s suggested WAF rules, widening the pool of successful intrusions.
Reporting also notes ShinyHunters told BleepingComputer in June that its original goal was to breach the FBI’s PeopleSoft database but that those attempts were unsuccessful. Reuters later reported on Oct. 5 that the FBI removed an Accenture contractor over failure to patch the FBI recruitment website hacked by ShinyHunters, an intrusion that exposed sensitive data on more than 5,000 FBI personnel, including unit, specialization and medical/psychiatric records.
ShinyHunters’ brand, doxxing, and the fractured criminal franchise
ShinyHunters has become what sources describe as a franchise: the name persists even as its operators change. Security reporting traces a succession of people using the ShinyHunters brand after core members — many French citizens — were arrested previously.
KrebsOnSecurity reports that when Dutch police arrested 24-year-old Pepijn van der Stap on Sept. 15, Rey publicly tried to assume control of the ShinyHunters brand. Rey boasted about stealing highly sensitive data from the FBI and extorting the ransomware group Cl0p, posted taunting memes to his Twitter/X account, and included imagery associated with Van der Stap’s former alias “Umbreon” in an apparent attempt to frame him.
The group dynamics turned hostile. A Telegram channel called “The Battle” began doxing and needling Rey and other alleged ShinyHunters members. Administrators of that channel wrote: “Rey (Saif Al‑Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters.” The same Telegram commentators claimed Rey’s activities “caused over $200 million in damages” and that he helped several friend groups negotiate deals for a reported 25–30% cut — claims attributed to that channel’s posts in the reporting.
Rey also maintained a cybersecurity blog on GitHub that in March 2026 named two Russian men as core developers of Cl0p, a post that doxed those individuals according to KrebsOnSecurity.
How Jeppesen ForeFlight, the FBI, and security teams are responding
- Jeppesen ForeFlight: The company says its investigation so far shows “no impact to our operations or products,” and Boeing has said it is reviewing the matter with the Jeppesen ForeFlight team.
- The FBI: The bureau has removed an Accenture contractor over failure to patch an affected FBI recruitment website and is reported to be working with Jordanian authorities after the detention and reported cooperation of the Amman suspect.
- Security teams and vendors: Oracle issued a fix for CVE-2026-35273 and Mandiant published WAF rules; security practitioners are confronting a bypass in the form of URL-encoding workarounds that ShinyHunters used to evade those mitigations.
The arrests and reported cooperation of a detained suspect have focused investigations on a remaining cohort of freelancers and affiliates who allegedly fed stolen credentials into the ShinyHunters network. With a released PeopleSoft patch, published WAF rules and a high-profile extortion tied to a major aviation software unit, investigators and defenders now face both technical evasion techniques and a fractured criminal ecosystem that can quickly regenerate a known brand.




