# ShinyHunters Extorted Boeing Spin-off Prior to Arrests

> Details on the arrest of suspected ShinyHunters leader 'Rey' in Jordan following extortion attempts against a Boeing spin-off.

- Published: 2026-10-07T14:59:28.000Z
- Severity: high
- Category: Threat Intel
- Tags: ShinyHunters, Ransomware, Data Breach, Oracle, PeopleSoft
- CVEs: CVE-2026-35273 (CVSS 9.8)
- Author: Runtime Rebel Intel
- Primary source: https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/
- Canonical: https://runtimerebel.com/blog/shinyhunters-extorted-boeing-spin-off-prior-to-arrests

## Key points

- Immediate impact: The ShinyHunters cybercrime gang targeted and extorted a business unit recently divested by Boeing.
- Affected systems: Oracle PeopleSoft environments and associated enterprise databases.
- Remediation: Apply Oracle security updates and review WAF rules to detect URL-encoding evasion tactics.

## Overview of ShinyHunters Extortion Campaign

Recent law enforcement actions have disrupted operations tied to the prolific data theft and extortion collective known as ShinyHunters. According to [KrebsOnSecurity](https://krebsonsecurity.com/2026/10/shinyhunters-extorted-boeing-spin-off-prior-to-arrests/), Jordanian authorities detained a teenager from Amman, Jordan, suspected of leading the hacking group. The suspect, operating under the online handle "Rey," was apprehended while the gang was actively extorting a business unit recently divested by global aerospace manufacturer Boeing.

The investigation highlights an escalation in the group's targeting of enterprise environments. Following the arrest of Dutch national and alleged accomplice Pepijn van der Stap, the suspect assumed control over the ShinyHunters brand, publicly boasting about data thefts and utilizing sophisticated evasion techniques.

## Technical Analysis and Exploitation Vectors

Security researchers at Mandiant and the Google [Threat Intelligence](/glossary#threat-intelligence) Group (GTIG) confirmed that the threat actors mass-exploited [CVE-2026-35273](/cve/cve-2026-35273), a [vulnerability](/glossary#vulnerability) in Oracle's PeopleSoft platform. The flaw was initially weaponized as a [zero-day](/glossary#zero-day) in June, prompting Oracle to release emergency patches.

Key technical insights into the campaign include:

* **Zero-Day Exploitation:** The group leveraged the PeopleSoft vulnerability to target higher education, technology, healthcare, agriculture, transportation, and government entities.
* **[WAF](/glossary#waf) Evasion:** When initial web application [firewall](/glossary#firewall) (WAF) rules released by Mandiant blocked standard [exploit](/glossary#exploit) attempts, the attackers utilized a well-known URL-encoding trick to bypass security controls.
* **[Data Exfiltration](/glossary#data-exfiltration):** Breached systems included high-profile targets, such as an FBI recruitment portal handled by a contractor, exposing sensitive personnel data.

### Targeting Boeing Spin-off Jeppesen ForeFlight

The investigation into the arrested suspect gained urgency due to the extortion of Jeppesen ForeFlight, a navigation and digital aviation unit previously owned by Boeing and sold to Thoma Bravo. The attackers allegedly stole sensitive information from the former subsidiary that could pose operational safety and security risks. While Boeing acknowledged the extortion attempt and reviewed the incident, representatives for Jeppesen ForeFlight stated that ongoing investigations showed no operational impact.

## Mitigation and Defense Recommendations

Defenders managing enterprise human resources and SaaS platforms must prioritize rigorous asset management and timely patching schedules. Security teams should implement the following steps to secure vulnerable environments:

* **Apply Patches Immediately:** Ensure all Oracle PeopleSoft deployments are updated with the latest vendor patches to remediate known exploitation vectors.
* **Enhance WAF Monitoring:** Review web application firewall logs and signatures for anomalous URL-encoding patterns designed to bypass detection mechanisms.
* **Audit Contractor Access:** Closely monitor third-party vendors and contractors with access to internal recruitment and employee databases to minimize exposure from supply chain weaknesses.

**Related:** [ShinyHunters Arrest and PeopleSoft Zero-Day Exploitation](/blog/shinyhunters-arrest-and-peoplesoft-zero-day-exploitation), [ShinyHunters Hacker Detained in Jordan, Cooperating With FBI](/blog/shinyhunters-hacker-detained-in-jordan-cooperating-with-fbi)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/shinyhunters-extorted-boeing-spin-off-prior-to-arrests
