// AI threat desk · 8 Oct 2026
Home/AI-ATK · AI-Powered Attacks
AI-Powered AttacksMediumEXTORTCVSS not assigned

Teen suspected of leading ShinyHunters detained amid Boeing unit extortion

KrebsOnSecurity reported that a teenager suspected of leading ShinyHunters was detained as the group was extorting a business unit recently divested by Boeing.

AI-generated image of cybersecurity analysts reviewing a suspected extortion case in an operations room.
AI-generated image, not a photo of the event.
Key takeaways
  • KrebsOnSecurity reported that a teenager from Amman suspected of leading ShinyHunters was detained and was reportedly cooperating with the FBI.
  • KrebsOnSecurity reported that sources said a navigation and digital aviation unit recently divested by Boeing was among the victims ShinyHunters was in the process of extorting.
  • Jeppesen ForeFlight said its investigation found no impact to its operations or products.

A teenager suspected of leading ShinyHunters was detained as the group was extorting a business unit recently divested by Boeing, KrebsOnSecurity reported.

Boeing said it was aware of threat-actor claims involving data allegedly associated with Boeing and its former subsidiary. Jeppesen ForeFlight said its investigation found no impact to its operations or products.

On this page

ShinyHunters used a PeopleSoft vulnerability in earlier access

KrebsOnSecurity reported that ShinyHunters gained access to the FBI site and other victims by exploiting PeopleSoft vulnerability CVE-2026-35273.

Google Threat Intelligence Group said ShinyHunters expanded a PeopleSoft campaign across higher education, technology, IT services, healthcare, agriculture, transportation and government. Its analysis found web shells on dozens of systems globally.

Boeing and Jeppesen ForeFlight reviewed the claims

Boeing said it was aware of claims by a threat actor regarding data allegedly associated with Boeing and Jeppesen ForeFlight. The company said it was actively reviewing the matter with the Jeppesen ForeFlight team.

Jeppesen ForeFlight said, “Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.”

KrebsOnSecurity reported that Reuters identified the detained suspect as Saif Al-din Khader and said he was cooperating with the FBI. The report said the detention took place in Amman and that the suspect was detained by Jordanian authorities.

The FBI described ShinyHunters as an extortion group

The FBI said ShinyHunters specializes in large-scale data breaches and extortion and targets major companies across technology, finance and retail. It said the group commonly uses threatening messages, calls and swatting to pressure victims.

Wikipedia describes ShinyHunters as a black-hat criminal hacker and extortion group active since 2019.

The FBI encourages suspected ShinyHunters intrusions to be reported to the Internet Crime Complaint Center or a local FBI field office.

Boeing said it was actively reviewing the matter with the Jeppesen ForeFlight team. Jeppesen ForeFlight said its investigation was continuing from a proactive security posture and had found no impact to its operations or products.

KrebsOnSecurity reported that the FBI investigation gained renewed urgency with the attempted extortion of the former Boeing unit.

What to do now

  1. Verify urgent or unusual requests received through emails, texts or calls via another communication method before responding.
  2. Do not send payment or respond to ShinyHunters demands.
  3. Apply the Oracle Security Alert patch for CVE-2026-35273.

FAQ

Who was detained in the ShinyHunters case?

KrebsOnSecurity reported that Jordanian authorities detained a teenager from Amman suspected of leading ShinyHunters and known as Rey. Reuters identified the suspect as Saif Al-din Khader, according to KrebsOnSecurity.

Which company did ShinyHunters allegedly extort?

KrebsOnSecurity reported that sources identified a navigation and digital aviation unit recently divested by Boeing as a victim. The unit was identified as Jeppesen ForeFlight.

Did Jeppesen ForeFlight confirm an operational impact?

No. Jeppesen ForeFlight said its investigation found no impact to its operations or products.

How did ShinyHunters gain access in the reported campaign?

KrebsOnSecurity reported that the group exploited PeopleSoft vulnerability CVE-2026-35273 to gain access to the FBI site and other victims.

What is ShinyHunters known for?

The FBI said ShinyHunters specializes in large-scale data breaches and extortion and targets major companies across technology, finance and retail.

Sources

  1. Internet Crime Complaint Center (IC3) | ShinyHunters: Cyber Criminal Group Attacks Learning Management System, FBIPrimary
  2. ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft | Google Cloud Blog, Google CloudPrimary
  3. ShinyHunters Extorted Boeing Spin-off Prior to Arrests, KrebsOnSecurity
  4. ShinyHunters, Wikipedia
How we checked this story
ClaimSourceStatus
KrebsOnSecurity reported that a teenager from Amman suspected of leading ShinyHunters was detained and was reportedly cooperating with the FBI.KrebsOnSecurityAttributed
KrebsOnSecurity reported that the suspect was detained while ShinyHunters was extorting a business unit recently divested by Boeing.KrebsOnSecurityAttributed
KrebsOnSecurity reported that Reuters identified the suspect as Saif Al-din Khader and said he was cooperating with the FBI.KrebsOnSecurityAttributed
KrebsOnSecurity reported that two sources identified a recently divested Boeing navigation and digital aviation unit as a ShinyHunters extortion victim.KrebsOnSecurityAttributed
KrebsOnSecurity reported that the FBI investigation gained renewed urgency because of the attempted extortion of the former Boeing unit.KrebsOnSecurityAttributed
KrebsOnSecurity reported that the alleged theft could pose operational safety and security risks.KrebsOnSecurityAttributed
Boeing said it was aware of threat-actor claims involving data allegedly associated with Boeing and former subsidiary Jeppesen ForeFlight.BoeingAttributed
Boeing said it was actively reviewing the matter with the Jeppesen ForeFlight team.BoeingAttributed
Jeppesen ForeFlight said its investigation and proactive security posture found no impact to its operations or products.Jeppesen ForeFlightAttributed
KrebsOnSecurity reported that ShinyHunters used a PeopleSoft vulnerability to gain access to the FBI site and other victims.KrebsOnSecurityAttributed
Google Threat Intelligence Group reported that ShinyHunters expanded its PeopleSoft campaign across higher education, technology, IT services, healthcare, agriculture, transportation, and government.Google Threat Intelligence Group, via Google CloudConfirmed
The FBI said ShinyHunters specializes in large-scale data breaches and extortion and targets major companies across technology, finance, and retail.FBIConfirmed
The FBI said ShinyHunters actors commonly use threatening messages, calls, and swatting to pressure victims.FBIConfirmed
The FBI recommended reporting suspected ShinyHunters intrusions to the Internet Crime Complaint Center or a local FBI field office.FBIConfirmed
Wikipedia describes ShinyHunters as a black-hat criminal hacker and extortion group active since 2019.WikipediaConfirmed
ic3.gov published its report on May 15, 2026.ic3.govConfirmed
Google Cloud published its report on Sep 25, 2026.Google CloudConfirmed

Could not verify

  • Whether the alleged Boeing data theft occurred is not established.
  • Whether ShinyHunters exploited the Boeing unit is not established.
  • How many people or records were affected is not established.
  • Whether the detained suspect is cooperating with the FBI is not independently established.
Explore with AI