A ShinyHunters member, a teenager from Amman who uses the handle “Rey”, was detained by Jordanian authorities as the group was in the process of extorting Boeing’s Jeppesen ForeFlight unit, which Boeing divested in November 2025 to Thoma Bravo for $10.55 billion. Rey had previously claimed leadership of ShinyHunters and publicly boasted about stealing highly sensitive data from the FBI and extorting Cl0p.
The FBI investigation appeared to gain renewed urgency after Rey’s return to activity following the Dutch arrest of Pepijn van der Stap, with Rey allegedly assuming control of the ShinyHunters brand. Boeing acknowledged the extortion claims, while Jeppesen ForeFlight said there was no impact on its operations. Reuters cited reports that the targeted unit sat within Boeing’s former aviation portfolio, raising concerns about potential operational security risks from stolen data.
The group’s operational methods, and the evidence cited by security researchers, centre on a zero-day in Oracle’s PeopleSoft SaaS platform, tracked as CVE-2026-35273, first exploited by ShinyHunters in June 2026 and later bypassed by a URL-encoding technique to defeat Mandiant’s recommended WAF rules. Mandiant and Google Threat Intelligence Group documented mass exploitation against dozens of organisations across higher education, technology, healthcare, agriculture, transportation and government.
Reuters also reported that an Accenture contractor was removed after a breach linked to ShinyHunters exposed FBI personnel data via the agency’s recruitment site. Rey’s public communications repeatedly tied ShinyHunters to threats against victims and to the broader Cl0p ecosystem, even as the group’s leadership fragment appears to have shifted through arrests and alleged remakes of the brand.