A teenager in Amman known as “REY” (identified as Saif al-Din Khader) was detained and is cooperating with the FBI after allegedly leading ShinyHunters through a campaign that included extorting Jeppesen ForeFlight, a navigation and digital aviation unit Boeing divested to Thoma Bravo for $10.55 billion in November 2025. Investigators tie ShinyHunters to mass exploitation of an Oracle PeopleSoft vulnerability (CVE-2026-35273) first used as a zero-day in June to steal data from dozens of organizations across education, healthcare, technology, transportation and government. The intrusions exposed sensitive FBI recruitment records for more than 5,000 personnel, prompted removal of an Accenture contractor for failure to patch, and saw Rey publicly taunt the FBI and the Cl0p ransomware group after assuming the ShinyHunters brand following the arrest of Dutch suspect Pepijn van der Stap.
Reporting shows the current ShinyHunters operation functions as a franchise, with freelance affiliates supplying stolen credentials from SaaS platforms in exchange for cuts, and internal infighting and ridicule on Telegram undermining the brand. Rey deleted many social accounts but left a GitHub blog that doxxed alleged Cl0p operators; Dutch authorities also face allegations that Van der Stap tried to order murders despite claims of reformation. Boeing and Jeppesen ForeFlight say they are investigating; ForeFlight reports no operational impact to date.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.