A teenage hacker, a Boeing spin-off, and the Oracle flaw tying them together

Jordanian authorities have detained the alleged leader of ShinyHunters as the group tried to extort a former Boeing aviation unit, using a critical Oracle PeopleSoft bug now on CISA's must-patch list.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 3 min read
Illustration: a dim airline operations room at dusk, rows of empty flight-planning monitors glowing faintly blue
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Jordanian police have detained a teenager known online as "Rey", the alleged leader of the ShinyHunters extortion crew, while the group was in the middle of trying to extort Jeppesen ForeFlight, an aviation navigation business Boeing sold to Thoma Bravo for $10.55 billion in November 2025.
  • The group broke into victims by exploiting CVE-2026-35273, a critical flaw in Oracle PeopleSoft human-resources software rated 9.8 out of 10 for severity.
  • US cyber agency CISA added the bug to its Known Exploited Vulnerabilities catalogue on 2026-06-12 and ordered federal agencies to patch it by 2026-06-15.
  • One confirmed victim was an FBI recruitment site run by a contractor, exposing data on more than 5,000 FBI personnel including medical and psychiatric records.
  • Threat Vectr has been tracking this vulnerability since 11 June 2026; our 26 September story was the first to report mass exploitation across sectors.

The arrest, first reported by KrebsOnSecurity, is the second blow to ShinyHunters in a month. Dutch police detained 24-year-old Pepijn van der Stap on 2025-09-15. Within hours, Rey took public control of the ShinyHunters brand and spent the next week taunting the FBI on social media.

That bravado didn't last. According to sources cited by Krebs, the FBI's urgency jumped sharply when the group began extorting Jeppesen ForeFlight, the flight-planning unit Boeing sold last year. Investigators were told the stolen data could carry operational safety and security risks.

Boeing confirmed the extortion attempt in a short statement. Jeppesen ForeFlight said its own investigation found "no impact to our operations or products".

How did the hackers get in?

Through a single Oracle bug. ShinyHunters exploited CVE-2026-35273, a missing-authentication flaw in Oracle PeopleSoft Enterprise PeopleTools, the software many large employers use to run hiring and payroll.

In plain terms, the bug lets a stranger on the internet take over the PeopleSoft system without a username or password. No login, no multi-factor prompt, nothing. That's why it scores 9.8 out of 10 on the standard severity scale.

Oracle shipped a fix. Google's Mandiant team published web filter rules for anyone who couldn't patch straight away. ShinyHunters then used a basic URL-encoding trick, essentially disguising the shape of their malicious web requests, to slip past those filter rules. Mandiant and Google's Threat Intelligence Group said in a 2025-09-25 report that the group mass-exploited the flaw across higher education, technology, healthcare, agriculture and government.

Multi-factor authentication wouldn't have saved anyone here. The flaw sits before the login screen, which is exactly what makes it so dangerous.

Who is Rey and why does the family link matter?

Rey is the online handle of Saif Al-din Khader, a teenager from Amman. Krebs reported in November 2025 that Rey had worked with multiple ransomware crews. His father is believed to work for Royal Jordanian Airlines, which flies a long-haul fleet built by Boeing.

That connection is what makes the Jeppesen ForeFlight extortion attempt so odd. Jeppesen's charts and flight-planning tools are used by airlines worldwide, including the kind of carrier that employs Rey's father.

What should ordinary people do?

For most readers the practical risk is small. If you've ever applied for a job through an employer running PeopleSoft, assume your application data could be in a leaked set and watch for targeted phishing emails that reference real details from that application. FBI applicants named in the recruitment-site breach are being contacted directly.

Item Detail
CVE CVE-2026-35273
Severity 9.8 (critical)
Affected Oracle PeopleSoft Enterprise PeopleTools
CISA KEV added 2026-06-12
Federal patch deadline 2026-06-15
FBI personnel exposed 5,000+

One judgement from this beat: the Oracle flaw is the story, not the arrests. ShinyHunters is a brand, not a fixed crew, and the same unauthenticated takeover bug is still sitting on PeopleTools instances nobody has patched. Expect copycats before Christmas.

© 2026 Threat Vectr