- KrebsOnSecurity reported that a teenager from Amman suspected of leading ShinyHunters was detained and was reportedly cooperating with the FBI.
- KrebsOnSecurity reported that sources said a navigation and digital aviation unit recently divested by Boeing was among the victims ShinyHunters was in the process of extorting.
- Jeppesen ForeFlight said its investigation found no impact to its operations or products.
A teenager suspected of leading ShinyHunters was detained as the group was extorting a business unit recently divested by Boeing, KrebsOnSecurity reported.
Boeing said it was aware of threat-actor claims involving data allegedly associated with Boeing and its former subsidiary. Jeppesen ForeFlight said its investigation found no impact to its operations or products.
On this page
ShinyHunters used a PeopleSoft vulnerability in earlier access
KrebsOnSecurity reported that ShinyHunters gained access to the FBI site and other victims by exploiting PeopleSoft vulnerability CVE-2026-35273.
Google Threat Intelligence Group said ShinyHunters expanded a PeopleSoft campaign across higher education, technology, IT services, healthcare, agriculture, transportation and government. Its analysis found web shells on dozens of systems globally.
Boeing and Jeppesen ForeFlight reviewed the claims
Boeing said it was aware of claims by a threat actor regarding data allegedly associated with Boeing and Jeppesen ForeFlight. The company said it was actively reviewing the matter with the Jeppesen ForeFlight team.
Jeppesen ForeFlight said, “Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.”
KrebsOnSecurity reported that Reuters identified the detained suspect as Saif Al-din Khader and said he was cooperating with the FBI. The report said the detention took place in Amman and that the suspect was detained by Jordanian authorities.
The FBI described ShinyHunters as an extortion group
The FBI said ShinyHunters specializes in large-scale data breaches and extortion and targets major companies across technology, finance and retail. It said the group commonly uses threatening messages, calls and swatting to pressure victims.
Wikipedia describes ShinyHunters as a black-hat criminal hacker and extortion group active since 2019.
The FBI encourages suspected ShinyHunters intrusions to be reported to the Internet Crime Complaint Center or a local FBI field office.
Boeing said it was actively reviewing the matter with the Jeppesen ForeFlight team. Jeppesen ForeFlight said its investigation was continuing from a proactive security posture and had found no impact to its operations or products.
KrebsOnSecurity reported that the FBI investigation gained renewed urgency with the attempted extortion of the former Boeing unit.
What to do now
- Verify urgent or unusual requests received through emails, texts or calls via another communication method before responding.
- Do not send payment or respond to ShinyHunters demands.
- Apply the Oracle Security Alert patch for CVE-2026-35273.
FAQ
Who was detained in the ShinyHunters case?
KrebsOnSecurity reported that Jordanian authorities detained a teenager from Amman suspected of leading ShinyHunters and known as Rey. Reuters identified the suspect as Saif Al-din Khader, according to KrebsOnSecurity.
Which company did ShinyHunters allegedly extort?
KrebsOnSecurity reported that sources identified a navigation and digital aviation unit recently divested by Boeing as a victim. The unit was identified as Jeppesen ForeFlight.
Did Jeppesen ForeFlight confirm an operational impact?
No. Jeppesen ForeFlight said its investigation found no impact to its operations or products.
How did ShinyHunters gain access in the reported campaign?
KrebsOnSecurity reported that the group exploited PeopleSoft vulnerability CVE-2026-35273 to gain access to the FBI site and other victims.
What is ShinyHunters known for?
The FBI said ShinyHunters specializes in large-scale data breaches and extortion and targets major companies across technology, finance and retail.
Sources
- Internet Crime Complaint Center (IC3) | ShinyHunters: Cyber Criminal Group Attacks Learning Management System, FBIPrimary
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft | Google Cloud Blog, Google CloudPrimary
- ShinyHunters Extorted Boeing Spin-off Prior to Arrests, KrebsOnSecurity
- ShinyHunters, Wikipedia
How we checked this story
| Claim | Source | Status |
|---|---|---|
| KrebsOnSecurity reported that a teenager from Amman suspected of leading ShinyHunters was detained and was reportedly cooperating with the FBI. | KrebsOnSecurity | Attributed |
| KrebsOnSecurity reported that the suspect was detained while ShinyHunters was extorting a business unit recently divested by Boeing. | KrebsOnSecurity | Attributed |
| KrebsOnSecurity reported that Reuters identified the suspect as Saif Al-din Khader and said he was cooperating with the FBI. | KrebsOnSecurity | Attributed |
| KrebsOnSecurity reported that two sources identified a recently divested Boeing navigation and digital aviation unit as a ShinyHunters extortion victim. | KrebsOnSecurity | Attributed |
| KrebsOnSecurity reported that the FBI investigation gained renewed urgency because of the attempted extortion of the former Boeing unit. | KrebsOnSecurity | Attributed |
| KrebsOnSecurity reported that the alleged theft could pose operational safety and security risks. | KrebsOnSecurity | Attributed |
| Boeing said it was aware of threat-actor claims involving data allegedly associated with Boeing and former subsidiary Jeppesen ForeFlight. | Boeing | Attributed |
| Boeing said it was actively reviewing the matter with the Jeppesen ForeFlight team. | Boeing | Attributed |
| Jeppesen ForeFlight said its investigation and proactive security posture found no impact to its operations or products. | Jeppesen ForeFlight | Attributed |
| KrebsOnSecurity reported that ShinyHunters used a PeopleSoft vulnerability to gain access to the FBI site and other victims. | KrebsOnSecurity | Attributed |
| Google Threat Intelligence Group reported that ShinyHunters expanded its PeopleSoft campaign across higher education, technology, IT services, healthcare, agriculture, transportation, and government. | Google Threat Intelligence Group, via Google Cloud | Confirmed |
| The FBI said ShinyHunters specializes in large-scale data breaches and extortion and targets major companies across technology, finance, and retail. | FBI | Confirmed |
| The FBI said ShinyHunters actors commonly use threatening messages, calls, and swatting to pressure victims. | FBI | Confirmed |
| The FBI recommended reporting suspected ShinyHunters intrusions to the Internet Crime Complaint Center or a local FBI field office. | FBI | Confirmed |
| Wikipedia describes ShinyHunters as a black-hat criminal hacker and extortion group active since 2019. | Wikipedia | Confirmed |
| ic3.gov published its report on May 15, 2026. | ic3.gov | Confirmed |
| Google Cloud published its report on Sep 25, 2026. | Google Cloud | Confirmed |
Could not verify
- Whether the alleged Boeing data theft occurred is not established.
- Whether ShinyHunters exploited the Boeing unit is not established.
- How many people or records were affected is not established.
- Whether the detained suspect is cooperating with the FBI is not independently established.



