INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
FBI Arrests ShinyHunters Suspect Linked to Boeing Extortion Case
| 2026-10-09 17:55 CRITICAL HIGH RANSOMWARE & EXTORTION DATA BREACH LAW ENFORCEMENT
Executive Summary
AI-generated
The FBI arrested Edward Dubrovsky, a Canadian man and co-founder of the cybersecurity firm Cypfer, on October 8 in Pennsylvania on suspicion of assisting ShinyHunters hacking group. The suspect's company specialized in handling ransomware negotiations with cybercrime groups. One person affected is Dubrovsky himself, who was previously associated with another Canadian security firm called CyberSteward and had plans to attend the Cyber Risk Summit with his team. The attack works by exploiting vulnerabilities in cybersecurity systems to negotiate ransom demands from hackers. As of October 10, Dubrovsky is currently being held at a federal facility in Philadelphia after the case was moved to the Eastern District of Texas, where it has become the epicenter of the FBI's ShinyHunters investigation.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-35273 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ap•••••.gov
ap•••••.fbijobs
ha•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation KillSwitchOperation KillSwitch
ShinyHuntersShinyHuntersScattered SpiderScattered SpiderLAPSUS$LAPSUS$
UmbreonUmbreonSysUpdateSysUpdate
CVE-2026-35273CVE-2026-35273
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
BENELUX
BENELUX
educationeducation
governmentgovernment
transportationtransportation
mediamedia
healthhealth
aerospaceaerospace
aviationaviation
technologytechnology
Incident Timeline
May 2020
ShinyHunters, a group that emerged publicly around April or May 2020, extorted Boeing's spin-off company prior to their arrests.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The ShinyHunters brand emerged publicly around April or May 2020.
late 2024
Threat actors associated with the ransomware group Hellcat leaked data prior to their eventual arrest.
Click on any entity below to view its context and source!
tactic
Ransomware
"Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024," Krebs noted at the time.
tactic
Data Leak
"Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024," Krebs noted at the time.
March 2025
Threat actors known as ShinyHunters extorted a Boeing spin-off using phishing emails, identified through I.D.O. in Puerto Rico and U.S.B.L. in Washington state, prior to their subsequent arrests.
Click on any entity below to view its context and source!
target_region
Puerto Rico
This list includes I.D.O. in Puerto Rico in March 2025, U.S.B.L. in Washington state in March 2025 and A.A. in Louisiana in September 2025.
organisation
I.D.O.
This list includes I.D.O. in Puerto Rico in March 2025, U.S.B.L. in Washington state in March 2025 and A.A. in Louisiana in September 2025.
organisation
U.S.B.L.
This list includes I.D.O. in Puerto Rico in March 2025, U.S.B.L. in Washington state in March 2025 and A.A. in Louisiana in September 2025.
at least June 2025
Threat actors known as ShinyHunters extorted a Boeing spin-off prior to Khader's cooperation with law enforcement starting at least June 2025.
September 2025
Threat actors known as ShinyHunters extorted a Boeing spin-off using phishing attacks in Puerto Rico, Washington state, and Louisiana between March 2025 and September 2025.
Click on any entity below to view its context and source!
target_region
Puerto Rico
This list includes I.D.O. in Puerto Rico in March 2025, U.S.B.L. in Washington state in March 2025 and A.A. in Louisiana in September 2025.
organisation
I.D.O.
This list includes I.D.O. in Puerto Rico in March 2025, U.S.B.L. in Washington state in March 2025 and A.A. in Louisiana in September 2025.
organisation
U.S.B.L.
This list includes I.D.O. in Puerto Rico in March 2025, U.S.B.L. in Washington state in March 2025 and A.A. in Louisiana in September 2025.
2025/09/29
Threat actors associated with ShinyHunters allegedly breached more than 140 organizations and took at least $70 million in extortion payments prior to their arrests.
Click on any entity below to view its context and source!
tactic
Extortion
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a
statement on YouTube
Tuesday.
attribution
FBI
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a
statement on YouTube
Tuesday.
financial
$70 group
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a
statement on YouTube
Tuesday.
victims
140 organizations
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a
statement on YouTube
Tuesday.
2025/10/03
ShinyHunters and its alleged co-conspirators breached more than 140 organisations since last year, collecting at least $70 million in extortion payments.
Click on any entity below to view its context and source!
tactic
Extortion
The
FBI says
ShinyHunters and its alleged co-conspirators have breached more than 140 organisations since last year and collected at least $70 million in extortion payments.
attribution
FBI
The
FBI says
ShinyHunters and its alleged co-conspirators have breached more than 140 organisations since last year and collected at least $70 million in extortion payments.
threat_actor
ShinyHunters
The
FBI says
ShinyHunters and its alleged co-conspirators have breached more than 140 organisations since last year and collected at least $70 million in extortion payments.
financial
$70 group
The
FBI says
ShinyHunters and its alleged co-conspirators have breached more than 140 organisations since last year and collected at least $70 million in extortion payments.
general_metric
140 organisations
The
FBI says
ShinyHunters and its alleged co-conspirators have breached more than 140 organisations since last year and collected at least $70 million in extortion payments.
2025/10/04
Threat actors known as ShinyHunters allegedly breached more than 140 organizations and took at least $70 million in extortion payments prior to their arrests.
Click on any entity below to view its context and source!
tactic
Extortion
"Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement.
attribution
FBI
"Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement.
financial
$70 group
"Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement.
victims
140 organizations
"Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement.
2025/10/07
Threat actors known as ShinyHunters demanded ransom in exchange for the release of sensitive data from Jeppesen ForeFlight, a business unit divested by Boeing.
late 2025
Threat actors known as ShinyHunters allegedly attempted to extort a navigation and digital aviation unit from Boeing prior to Rey's arrest.
Click on any entity below to view its context and source!
organisation
Boeing
On October 7, we
detailed
how Rey was apprehended as the cybercrime group allegedly sought to extort a navigation and digital aviation unit that was divested by Boeing in late 2025.
early 2025
Rey claimed on Telegram in early 2025 that his father was an airline pilot.
Click on any entity below to view its context and source!
organisation
Telegram
Rey claimed on Telegram in early 2025 that his father was an airline pilot, although that could not be independently confirmed.
November 2025
Threat actors associated with ShinyHunters allegedly placed extortion demands targeting Boeing's subsidiary Jeppesen ForeFlight prior to the arrests of individuals involved in the conspiracy.
Click on any entity below to view its context and source!
tactic
Ransomware
KrebsOnSecurity identified Rey as Khader in
a November 2025 profile
, in which the young man admitted working with multiple ransomware groups.
tactic
Extortion
In a brief statement shared with KrebsOnSecurity, Boeing acknowledged the extortion attempts by ShinyHunters, and said the incident concerned data stolen from
Jeppesen ForeFlight
, a subsidiary that Boeing
sold in November 2025
to the private equity firm Thoma Bravo for $10.55 billion.
In November 2025, cybersecurity journalist Brian Krebs identified Rey as a teenager from Amman, Jordan, allegedly involved with Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider and LAPSUS$. Khader reportedly spoke with Krebs over Signal and claimed at the time that he was leaving data theft and extortion behind.
Prosecutors accuse Eltibrizi, who allegedly participated in the conspiracy from at least March through November 2025, of placing calls as a KillSec representative in at least one of those extortion demands.
threat_actor
ShinyHunters
In a brief statement shared with KrebsOnSecurity, Boeing acknowledged the extortion attempts by ShinyHunters, and said the incident concerned data stolen from
Jeppesen ForeFlight
, a subsidiary that Boeing
sold in November 2025
to the private equity firm Thoma Bravo for $10.55 billion.
In a report
published
in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of
Scattered LAPSUS$ Hunters
(SLH or SLSH), a group that's assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.
In November 2025, cybersecurity journalist Brian Krebs identified Rey as a teenager from Amman, Jordan, allegedly involved with Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider and LAPSUS$. Khader reportedly spoke with Krebs over Signal and claimed at the time that he was leaving data theft and extortion behind.
organisation
Thoma Bravo
In a brief statement shared with KrebsOnSecurity, Boeing acknowledged the extortion attempts by ShinyHunters, and said the incident concerned data stolen from
Jeppesen ForeFlight
, a subsidiary that Boeing
sold in November 2025
to the private equity firm Thoma Bravo for $10.55 billion.
threat_actor
LAPSUS$
In a report
published
in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of
Scattered LAPSUS$ Hunters
(SLH or SLSH), a group that's assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.
In November 2025, cybersecurity journalist Brian Krebs identified Rey as a teenager from Amman, Jordan, allegedly involved with Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider and LAPSUS$. Khader reportedly spoke with Krebs over Signal and claimed at the time that he was leaving data theft and extortion behind.
organisation
SLH
In a report
published
in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of
Scattered LAPSUS$ Hunters
(SLH or SLSH), a group that's assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.
threat_actor
Scattered Spider
In a report
published
in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of
Scattered LAPSUS$ Hunters
(SLH or SLSH), a group that's assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.
In November 2025, cybersecurity journalist Brian Krebs identified Rey as a teenager from Amman, Jordan, allegedly involved with Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider and LAPSUS$. Khader reportedly spoke with Krebs over Signal and claimed at the time that he was leaving data theft and extortion behind.
source_region
Jordan
In November 2025, cybersecurity journalist Brian Krebs identified Rey as a teenager from Amman, Jordan, allegedly involved with Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider and LAPSUS$. Khader reportedly spoke with Krebs over Signal and claimed at the time that he was leaving data theft and extortion behind.
organisation
Krebs
In November 2025, cybersecurity journalist Brian Krebs identified Rey as a teenager from Amman, Jordan, allegedly involved with Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider and LAPSUS$. Khader reportedly spoke with Krebs over Signal and claimed at the time that he was leaving data theft and extortion behind.
organisation
Signal
In November 2025, cybersecurity journalist Brian Krebs identified Rey as a teenager from Amman, Jordan, allegedly involved with Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider and LAPSUS$. Khader reportedly spoke with Krebs over Signal and claimed at the time that he was leaving data theft and extortion behind.
March 2026
Threat actors using the Cl0p hacking group, allegedly linked to Russian developers and hackers, targeted Boeing's spin-off company prior to their eventual arrest.
Click on any entity below to view its context and source!
source_region
Russian Federation
In March 2026, Rey’s blog featured
a lengthy post
that identified two Russian men as the core developers and hackers behind Cl0p.
May 2026
ShinyHunters claimed they hacked the FBI to counter the agency's narrative in a May 2026 alert advising victims against paying ransom.
Click on any entity below to view its context and source!
attribution
FBI
In an interview with
The Register
, ShinyHunters claimed they hacked the FBI to counter the agency’s narrative in
a May 2026 alert
that advised victims against paying a ransom to the group, which came off looking unprofessional and capricious in the FBI’s advisory.
threat_actor
ShinyHunters
In an interview with
The Register
, ShinyHunters claimed they hacked the FBI to counter the agency’s narrative in
a May 2026 alert
that advised victims against paying a ransom to the group, which came off looking unprofessional and capricious in the FBI’s advisory.
organisation
Register
In an interview with
The Register
, ShinyHunters claimed they hacked the FBI to counter the agency’s narrative in
a May 2026 alert
that advised victims against paying a ransom to the group, which came off looking unprofessional and capricious in the FBI’s advisory.
May 15, 2026
The FBI released a flash notice on May 15, 2026, announcing extortion by ShinyHunters targeting Boeing's spin-off.
Click on any entity below to view its context and source!
industry
Aviation
General Document Context
industry
Aerospace
General Document Context
industry
Media
General Document Context
attribution
FBI
A flash notice on ShinyHunters released by the FBI on May 15, 2026.
threat_actor
ShinyHunters
A flash notice on ShinyHunters released by the FBI on May 15, 2026.
2026/09/01
A Dutch national was indicted in Puerto Rico for his alleged role as a negotiator for ShinyHunters, facing up to 10 years in prison.
Click on any entity below to view its context and source!
target_region
Netherlands
The Dutch national, who is accused of acting as a negotiator for the group, was indicted last month in Puerto Rico and faces up to 10 years in prison for unauthorized computer access conspiracy.
target_region
Puerto Rico
The Dutch national, who is accused of acting as a negotiator for the group, was indicted last month in Puerto Rico and faces up to 10 years in prison for unauthorized computer access conspiracy.
2026/09/03
Threat actors, identified as Dutch hacker Pepijn van der Stap (Umbreon), took control of the ShinyHunters brand prior to their arrest on September 3, 2026.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Sources cited by Krebs last month described Rey as having taken control of the ShinyHunters brand amid an internal dispute involving Dutch hacker Pepijn van der Stap, also known as Umbreon.
malware
Umbreon
Sources cited by Krebs last month described Rey as having taken control of the ShinyHunters brand amid an internal dispute involving Dutch hacker Pepijn van der Stap, also known as Umbreon.
source_region
Netherlands
Sources cited by Krebs last month described Rey as having taken control of the ShinyHunters brand amid an internal dispute involving Dutch hacker Pepijn van der Stap, also known as Umbreon.
September 9
Threat actors known as ShinyHunters extorted a Boeing spin-off prior to Van der Stap's arrest and subsequent appointment as offensive security lead at Neo Security.
Click on any entity below to view its context and source!
source_region
Netherlands
In an interview with KrebsOnSecurity on September 9, Van der Stap described his new role as “offensive security lead” at the Dutch cybersecurity company
Neo Security
, saying the job involved probing client networks for security vulnerabilities.
organisation
Neo Security
In an interview with KrebsOnSecurity on September 9, Van der Stap described his new role as “offensive security lead” at the Dutch cybersecurity company
Neo Security
, saying the job involved probing client networks for security vulnerabilities.
Sept. 9
Threat actors known as ShinyHunters demanded ransom from Boeing's spin-off company, reportedly using a phishing attack.
2026/09/10
The FBI has been analyzing devices seized from Pepijn van der Stap, a convicted cybercriminal linked to ShinyHunters, in connection with the Dutch police arrest.
Click on any entity below to view its context and source!
attribution
FBI
Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police
arrested the convicted cybercriminal Pepijn van der Stap
in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming.
threat_actor
ShinyHunters
Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police
arrested the convicted cybercriminal Pepijn van der Stap
in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming.
tactic
Ransomware
Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police
arrested the convicted cybercriminal Pepijn van der Stap
in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming.
target_region
Netherlands
Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police
arrested the convicted cybercriminal Pepijn van der Stap
in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming.
organisation
Pepijn
Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police
arrested the convicted cybercriminal Pepijn van der Stap
in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming.
September 15
Threat actors, identified as ShinyHunters led by Pepijn van der Stap, extorted a Boeing spin-off prior to their arrest on September 15 in the Netherlands.
Click on any entity below to view its context and source!
attribution
FBI
The story noted that immediately following the Dutchman’s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the
FBI
and extorting the ransomware group
Cl0p
.
threat_actor
ShinyHunters
The story noted that immediately following the Dutchman’s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the
FBI
and extorting the ransomware group
Cl0p
.
tactic
Ransomware
The story noted that immediately following the Dutchman’s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the
FBI
and extorting the ransomware group
Cl0p
.
source_region
Netherlands
Korper said Dutch forensic investigators visited his office on September 15, the night Van der Stap was arrested in a dramatic police raid that reportedly involved
flash bang grenades
.
The suspected leader, Pepijn van der Stap, of Amsterdam,
was arrested
on September 15 in the Netherlands while on probation after serving three of the four-year prison term he was sentenced to in 2023 over hacking and extortion activities.
organisation
Korper
Korper said Dutch forensic investigators visited his office on September 15, the night Van der Stap was arrested in a dramatic police raid that reportedly involved
flash bang grenades
.
tactic
Extortion
The suspected leader, Pepijn van der Stap, of Amsterdam,
was arrested
on September 15 in the Netherlands while on probation after serving three of the four-year prison term he was sentenced to in 2023 over hacking and extortion activities.
Sept 16
Police in the Netherlands used flash-bang grenades during a raid on Van Der Stap's residence on September 16.
Click on any entity below to view its context and source!
source_region
Netherlands
A screenshot of a Sept 16 story by the Dutch news outlet at5.nl, describing a police raid on Van Der Stap’s residence that reportedly used flash-bang grenades.
Sept. 22
Rey uploaded a taunting meme to Twitter on September 22.
2026/09/22
ShinyHunters allegedly extorted Boeing's spin-off company prior to their arrest by authorities.
Click on any entity below to view its context and source!
tactic
Extortion
Authorities arrested an alleged leader of ShinyHunters, the notorious cybercrime group responsible for a string of high profile extortion attacks since 2025, including last week’s
attack on the FBI
.
attribution
FBI
Authorities arrested an alleged leader of ShinyHunters, the notorious cybercrime group responsible for a string of high profile extortion attacks since 2025, including last week’s
attack on the FBI
.
threat_actor
ShinyHunters
Authorities arrested an alleged leader of ShinyHunters, the notorious cybercrime group responsible for a string of high profile extortion attacks since 2025, including last week’s
attack on the FBI
.
Sept. 25
ShinyHunters mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across various industries.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
attribution
Google Threat Intelligence Group
In
a report
released Sept. 25, security experts at
Mandiant
and the
Google Threat Intelligence Group
(GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
2026/09/27
Threat actors known as ShinyHunters used extortion to target a Boeing spin-off prior to their arrest of a 24-year-old Amsterdam man.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The development is the latest action in the ShinyHunters saga, which also saw the
arrest of a 24-year-old Amsterdam man
last week for their involvement in the threat actor's malicious cyber operations.
September 28
ShinyHunters exploited a vulnerability (CVE-2026-35273) in PeopleSoft to gain access to the FBI site and other victims.
Click on any entity below to view its context and source!
attribution
FBI
As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in
PeopleSoft
, a software-as-a-service platform from the tech giant
Oracle
that is broadly used by companies to manage hiring and human resources, benefits and payroll.
Multiple FBI sources
told
Reuters on Saturday that Saif al-Din Khader was arrested in Jordan on September 28.
Khader, according to Reuters, is now cooperating with the FBI and other law enforcement agencies to help locate other members of ShinyHunters — a cybercriminal group responsible for several high-profile incidents including the FBI breach.
threat_actor
ShinyHunters
As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in
PeopleSoft
, a software-as-a-service platform from the tech giant
Oracle
that is broadly used by companies to manage hiring and human resources, benefits and payroll.
Rey was featured again in
a September 28 exclusive
about the Dutch police arresting 24-year-old convicted cybercriminal
Pepijn van der Stap
on suspicion of aiding in data thefts and extortions by ShinyHunters.
Multiple FBI sources
told
Reuters on Saturday that Saif al-Din Khader was arrested in Jordan on September 28.
Khader, according to Reuters, is now cooperating with the FBI and other law enforcement agencies to help locate other members of ShinyHunters — a cybercriminal group responsible for several high-profile incidents including the FBI breach.
vulnerability
CVE-2026-35273
As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in
PeopleSoft
, a software-as-a-service platform from the tech giant
Oracle
that is broadly used by companies to manage hiring and human resources, benefits and payroll.
organisation
PeopleSoft
As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in
PeopleSoft
, a software-as-a-service platform from the tech giant
Oracle
that is broadly used by companies to manage hiring and human resources, benefits and payroll.
organisation
Oracle
As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in
PeopleSoft
, a software-as-a-service platform from the tech giant
Oracle
that is broadly used by companies to manage hiring and human resources, benefits and payroll.
target_region
Netherlands
Rey was featured again in
a September 28 exclusive
about the Dutch police arresting 24-year-old convicted cybercriminal
Pepijn van der Stap
on suspicion of aiding in data thefts and extortions by ShinyHunters.
source_region
Jordan
Multiple FBI sources
told
Reuters on Saturday that Saif al-Din Khader was arrested in Jordan on September 28.
Khader, according to Reuters, is now cooperating with the FBI and other law enforcement agencies to help locate other members of ShinyHunters — a cybercriminal group responsible for several high-profile incidents including the FBI breach.
attribution
Reuters
Multiple FBI sources
told
Reuters on Saturday that Saif al-Din Khader was arrested in Jordan on September 28.
Khader, according to Reuters, is now cooperating with the FBI and other law enforcement agencies to help locate other members of ShinyHunters — a cybercriminal group responsible for several high-profile incidents including the FBI breach.
2026/09/28
A 24-year-old man from Amsterdam was arrested by the FBI as part of an investigation into ShinyHunters.
Click on any entity below to view its context and source!
organisation
ShinyHunter
His arrest follows the detention of another alleged ShinyHunter member last week.
threat_actor
ShinyHunters
Reappearing on Telegram
The ShinyHunters leak site was taken down last week, allegedly by law enforcement agencies.
Last week, the Dutch police
announced the arrest
of a 24-year-old man from Amsterdam as part of the FBI’s investigation into ShinyHunters.
The FBI last week said it was actively working with partners to pursue additional leads in its ShinyHunters investigation.
organisation
Telegram
Reappearing on Telegram
The ShinyHunters leak site was taken down last week, allegedly by law enforcement agencies.
attribution
FBI
Last week, the Dutch police
announced the arrest
of a 24-year-old man from Amsterdam as part of the FBI’s investigation into ShinyHunters.
The FBI last week said it was actively working with partners to pursue additional leads in its ShinyHunters investigation.
target_region
Netherlands
Last week, the Dutch police
announced the arrest
of a 24-year-old man from Amsterdam as part of the FBI’s investigation into ShinyHunters.
September 29, 2026
Rey, a suspect in the ShinyHunters extortion case against Boeing's spin-off company, was brought into custody on September 29, 2026.
Click on any entity below to view its context and source!
industry
Aviation
General Document Context
industry
Aerospace
General Document Context
industry
Media
General Document Context
attribution
the U.S. Federal Bureau of Investigation (FBI
Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and law enforcement to identify other members of the group.
Sept. 29
Threat actors ShinyHunters allegedly extorted a Boeing spin-off prior to their arrest, which was reported by the Dutch daily RTL on September 29.
Click on any entity below to view its context and source!
target_region
Netherlands
The Dutch daily
RTL reported on Sept. 29
that investigators suspect Van der Stap tried to orchestrate at least two murders.
September 29
Threat actors ShinyHunters extorted a Boeing spin-off prior to the arrest of Pepijn van der Stap on September 29.
Click on any entity below to view its context and source!
attribution
FBI
On September 29, the FBI and the Dutch National Police
announced
the arrest of Pepijn van der Stap — a well-known cybercriminal who was released this year after serving years in prison on a previous hacking conviction.
organisation
Pepijn
On September 29, the FBI and the Dutch National Police
announced
the arrest of Pepijn van der Stap — a well-known cybercriminal who was released this year after serving years in prison on a previous hacking conviction.
attribution
the Dutch National Police
On September 29, the FBI and the Dutch National Police
announced
the arrest of Pepijn van der Stap — a well-known cybercriminal who was released this year after serving years in prison on a previous hacking conviction.
29 September
ShinyHunters' leak site continued showing activity after Rey was reportedly detained on 29 September.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The operators later attributed the outage to sabotage by rivals and an unrelated disruption.
ShinyHunters’ leak site continued showing activity after Rey was reportedly detained on 29 September.
tactic
Sabotage
The operators later attributed the outage to sabotage by rivals and an unrelated disruption.
ShinyHunters’ leak site continued showing activity after Rey was reportedly detained on 29 September.
1 October 2026
ShinyHunters posted updated dark web leak sites featuring stolen data from O'Reilly Automotive and DexCom on 1 October 2026.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Screenshot of the ShinyHunters dark web leak site showing O’Reilly Automotive and DexCom entries marked “NEW” and updated on 1 October 2026.
industry
Automotive
Screenshot of the ShinyHunters dark web leak site showing O’Reilly Automotive and DexCom entries marked “NEW” and updated on 1 October 2026.
organisation
DexCom
Screenshot of the ShinyHunters dark web leak site showing O’Reilly Automotive and DexCom entries marked “NEW” and updated on 1 October 2026.
2026/10/03
Reuters reported that Saif Al-din Khader, a teenager identified as Rey, had been detained and was cooperating with FBI investigators.
Click on any entity below to view its context and source!
attribution
FBI
Last week, Reuters reported that Rey — identified as a teenager named
Saif Al-din Khader
— had been detained and was cooperating with FBI investigators.
organisation
Reuters
Last week, Reuters reported that Rey — identified as a teenager named
Saif Al-din Khader
— had been detained and was cooperating with FBI investigators.
October 3
A suspected ShinyHunters member, identified as Saif al-Din Khader, was detained by Jordanian authorities and began cooperating with the FBI on October 3.
Click on any entity below to view its context and source!
attribution
FBI
On October 3,
Reuters
cited
three unnamed sources saying a suspected ShinyHunters member in Amman named
Saif Al-din Khader
was detained by Jordanian authorities and was cooperating with the FBI.
threat_actor
ShinyHunters
On October 3,
Reuters
cited
three unnamed sources saying a suspected ShinyHunters member in Amman named
Saif Al-din Khader
was detained by Jordanian authorities and was cooperating with the FBI.
organisation
Reuters
On October 3,
Reuters
cited
three unnamed sources saying a suspected ShinyHunters member in Amman named
Saif Al-din Khader
was detained by Jordanian authorities and was cooperating with the FBI.
Reuters reported on October 3 that three people familiar with the matter confirmed the detention of Saif al-Din Khader, whose alleged online nickname is Rey.
target_region
Jordan
On October 3,
Reuters
cited
three unnamed sources saying a suspected ShinyHunters member in Amman named
Saif Al-din Khader
was detained by Jordanian authorities and was cooperating with the FBI.
3 October
ShinyHunters deleted both listings four days after Rey's reported detention on 3 October.
October 5
ShinyHunters hacked the FBI recruitment website, exposing sensitive data on over 5,000 FBI personnel.
Click on any entity below to view its context and source!
attribution
FBI
Reuters
reported October 5
that the FBI has removed a contractor at
Accenture
over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel, including each’s person’s unit and specialization, as well as medical and psychiatric records.
threat_actor
ShinyHunters
Reuters
reported October 5
that the FBI has removed a contractor at
Accenture
over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel, including each’s person’s unit and specialization, as well as medical and psychiatric records.
general_metric
5,000 FBI personnel
Reuters
reported October 5
that the FBI has removed a contractor at
Accenture
over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel, including each’s person’s unit and specialization, as well as medical and psychiatric records.
October 7
Threat actors known as ShinyHunters allegedly extorted a navigation and digital aviation unit from Boeing prior to Rey's arrest on October 7.
Click on any entity below to view its context and source!
organisation
Boeing
On October 7, we
detailed
how Rey was apprehended as the cybercrime group allegedly sought to extort a navigation and digital aviation unit that was divested by Boeing in late 2025.
2026/10/07
Two Russian men were identified as the core operators behind Cl0p, a long-established ransomware group.
Click on any entity below to view its context and source!
tactic
Ransomware
This post doxes two Russian men as the core operators behind Cl0p, one of the oldest and most established ransomware groups still in operation today.
MURDER FOR HIRE?
target_region
Russian Federation
This post doxes two Russian men as the core operators behind Cl0p, one of the oldest and most established ransomware groups still in operation today.
MURDER FOR HIRE?
organisation
HIRE
This post doxes two Russian men as the core operators behind Cl0p, one of the oldest and most established ransomware groups still in operation today.
MURDER FOR HIRE?
October 8
Threat actors known as ShinyHunters extorted Boeing's spin-off company prior to Edward Dobrovsky's arrest on October 8.
Click on any entity below to view its context and source!
tactic
Extortion
Federal court records show that on October 8, an Edward Dobrovsky (note the slight misspelling of the last name) was arrested in Pennsylvania on cyber extortion and conspiracy charges.
between Oct. 5 and Oct. 7
Threat actors used the Loews Philadelphia Hotel as a venue for the Cyber Risk Summit between October 5 and October 7, potentially exposing attendees to phishing or other attacks.
Click on any entity below to view its context and source!
organisation
the Loews Philadelphia Hotel
An online search reveals the
Cyber Risk Summit
was held at the Loews Philadelphia Hotel between Oct. 5 and Oct. 7.
October 9
The ShinyHunters extortion case against a Boeing spin-off was moved to the Eastern District of Texas court on October 9.
Click on any entity below to view its context and source!
attribution
FBI
But
the court records
indexed by CourtListener include a notice filed on October 9 that moved the case to the Eastern District of Texas, which sources say is now the epicenter of the FBI’s ShinyHunters investigation.
threat_actor
ShinyHunters
But
the court records
indexed by CourtListener include a notice filed on October 9 that moved the case to the Eastern District of Texas, which sources say is now the epicenter of the FBI’s ShinyHunters investigation.
organisation
CourtListener
But
the court records
indexed by CourtListener include a notice filed on October 9 that moved the case to the Eastern District of Texas, which sources say is now the epicenter of the FBI’s ShinyHunters investigation.
2026/10/09
A suspected member of the ShinyHunters hacking group, identified as Saif al-Din Khader, was detained by Jordanian authorities.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday.
New, by me: ShinyHunters Extorted Boeing Spin-off Prior to A....
New, by me: ShinyHunters Extorted Boeing Spin-off Prior to Arrests
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang.
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group
ShinyHunters
has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang.
Those sources said the FBI’s investigation into ShinyHunters gained renewed urgency with the group’s attempted extortion of the former Boeing unit, which allegedly included the theft of sensitive information that sources said could pose operational safety and security risks.
An individual believed to be the leader of the extortion group ShinyHunters was reportedly arrested in Jordan and is cooperating with the FBI.
This week, ShinyHunters provided the following
statement
to the
media
:
“Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated.
Not extortion, ShinyHunters says
Before the FBI’s statement, the hacking group appeared confident that making headlines over the past week has helped it gain more attention, rather than hurting its business.
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters
reported
, citing three people familiar with the matter.
"
In a deep-dive report tracing ShinyHunters' origins and their tactical evolution, cybersecurity companies Sekoia and Beazley Security said its lineage goes back to two progenitor hacking groups, TheDarkOverlord and GnosticPlayers, that specialized in extortion and data leak operations.
FBI arrests another suspected ShinyHunters hacker after agency breach.
Agents with the
Federal Bureau of Investigation
(FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the
ShinyHunters
hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.
Another shared that control over the ShinyHunters investigation has been centralized at an FBI field office in Texas.
Immediately after Van der Stap’s arrest, another member of ShinyHunters named “
Rey
” assumed control over the group and began taunting the FBI over data the group stole from the agency’s online recruitment portal, which included each’s person’s unit and specialization, as well as medical and psychiatric records.
ShinyHunters
told BleepingComputer in June
that the original goal behind exploiting the PeopleSoft vulnerability was to breach the FBI’s own PeopleSoft database, but the hackers said those attacks were unsuccessful for some reason.
But just hours after that request was sent, Rey began deleting his various social media accounts, including the Twitter/X account he previously used to taunt the FBI, Cl0p, and other ShinyHunters victims.
In the days after the news broke of Van der Stap’s arrest, a cybercrime-focused chat server on Telegram that was allegedly operated by Rey erupted with hot takes, with most participants heaping ridicule on the teenage hacker after he publicly backed down from threats against the FBI and Cl0p, and again when
the ShinyHunters’s darknet website suddenly went offline
.
The FBI warned ShinyHunters members “may also falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”
The FBI declined to comment on Khader’s alleged arrest, only telling Recorded Future News that it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters.
ShinyHunters has claimed dozens of high-profile data thefts in recent months and has been in the crosshairs of the FBI for nearly a year after dozens of attacks on large companies like
Ticketmaster
and
AT&T
as well as educational publisher
McGraw Hill
,
Carnival Cruise Line
,
7-Eleven
and
other
companies
.
ShinyHunters told several news outlets in messages that it would not release the stolen information and did not want to escalate their feud with the FBI — which they said started because of
an advisory
about their actions that they disagreed with.
ShinyHunters sent a sample list of 5,000 FBI employees to the media, claiming to be in possession of the personal and health information of all current and former FBI employees.
The suspect, Saif al-Din Khader, known as Rey, a teenage cybercriminal from Amman, is helping the FBI identify other ShinyHunters members, Reuters
reports
.
A suspected ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group.
The FBI on Tuesday called on ShinyHunters group members to come forward in the wake of the alleged leader’s arrest.
Some suggest that the group has decided against extorting the FBI due to the implications: the agency would be even more motivated to identify and hunt down ShinyHunters members.
ShinyHunters insisted that it's not seeking a monetary payoff in the FBI case, but rather apply pressure on the FBI to amend what it said were false allegations about the group and challenge claims made by the agency about its connections with
The Com
, a
loose-knit
cybercrime collective
notorious for social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, a…
ShinyHunters hacker “Rey,” allegedly involved in FBI data theft, detained in Jordan.
Jana Winter, Raphael Satter, and A.J. Vicens report:
A key member of the ShinyHunters hacking group, which claims to have stolen data on every FBI employee, was detained this week in Jordan, three people familiar with the matter told Reuters.
A suspected key member of
ShinyHunters
known online as “Rey” has been detained in Jordan and is reportedly cooperating with the FBI, days after the hacking group claimed one of its most sensitive breaches yet: the theft of personnel information belonging to FBI employees.
The FBI declined to confirm a specific arrest abroad, but said it is continuing to investigate the recent incident allegedly involving ShinyHunters and has already worked with international partners to arrest multiple suspects.
Hackread.com
later obtained a statement from ShinyHunters
saying it had never intended to publish or sell the FBI data.
From Canvas and Rockstar to Large SaaS Data Theft
The FBI incident followed an aggressive year for ShinyHunters.
The FBI described Van der Stap as one of the group’s alleged leaders, although ShinyHunters
denied to Hackread.com
that he had any association with them.
The arrest, which occurred about a week before ShinyHunters claims it broke into FBI systems and stole reams of data containing
sensitive information on almost every FBI agent
, marks a major development for global law enforcement’s push to track down and arrest the group’s members.
ShinyHunters typically uses phishing and stolen credentials to siphon data from corporate accounts at software-as-a-service companies, and then threatens to publish the stolen data online unless a ransom demand is paid.
KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey’s father — Royal Jordanian Airlines.
Several commentators accused Rey of resurrecting the ShinyHunters brand after its core members were rounded up in France, and making a mockery of the group’s name and reputation ever since.
Oracle quickly issued a fix for CVE-2026-35273, which ShinyHunters first began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations that couldn’t apply the security update quickly enough.
ShinyHunters Extorted Boeing Spin-off Prior to Arrests.
KrebsOnSecurity has learned that the suspect, who uses the hacker handle “
Rey
,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company
Boeing
, which manufactures the fleet of planes used by the employer of Rey’s father —
Royal Jordanian Airlines
.
In recent weeks, however, ShinyHunters
turned to a well-known URL-encoding trick
to bypass Mandiant’s suggested web application firewall rules.
‘REY’ MEANS KING, AS IN ROYAL
According to two sources familiar with the ShinyHunters investigation, a navigation and digital aviation unit recently divested by the global aerospace company
Boeing
was among the victims that ShinyHunters was in the process of extorting when Rey was apprehended by Jordanian authorities.
If someone doesn’t want to believe me, then that’s on them.”
FRANCHISING AND BURNING A BRAND
Cybercriminals aligned with ShinyHunters have been responsible for
dozens of data breaches
involving billions of stolen records, and breaches claimed by the group stretch back to at least 2019.
But experts say the people recently operating behind the ShinyHunters name are not the same core members that populated the group in its early days, most of whom are French citizens who have been arrested (if not also imprisoned) on
at least one prior occasion
for alleged cybercrime activity.
More to the point, ShinyHunters has become something of a franchise.
“He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke,” one member recounted.
A relatively new Telegram channel called “The Battle” has been doxing and needling Rey and other alleged ShinyHunters members for several weeks, and it has gained a considerable readership among the cybercrime communities operating on Telegram.
“Rey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters,” wrote the administrators of The Battle server on Telegram.
Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement.
Khader was
identified
last November by cybersecurity journalist Brian Krebs as a key figure within ShinyHunters.
Krebs
reported
that van der Stap was a key figure in ShinyHunters and was allegedly locked in a power struggle with Khader for control of the cybercriminal operation.
Alleged ShinyHunters Leader Arrested in Jordan.
ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers.
Two sources said Jordanian authorities took Khader into […] The post ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers appeared first on Cyber Security News .
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
NightmareStresser DDoS Service Disrupted in International Operation
ShinyHunters Defiant After FBI Calls on Members to Come Forward.
The Dutch police on Tuesday said the 24-year-old man is suspected of “playing a role within the hacking group ShinyHunters” and of planning two murders.
According to Leatherman, other ShinyHunters group members should take notice of the arrest and come forward before the authorities find them.
“To the remaining members of ShinyHunters: You’ve heard about the arrest of your colleague.
Referring to
the hack of FBIJobs.gov
and the one-week ultimatum it gave to the Bureau to retract a previous report stating the group tends to exaggerate its claims, ShinyHunters now says all was a marketing campaign meant to protect its brand.
Will ShinyHunters survive?
Others, however, suggest that foreign intelligence agencies might have promised ShinyHunters protection in exchange for the data.
Even subsequent arrests may not result in ShinyHunters’ demise as a whole.
ShinyHunters operates like a brand, not a fixed crew.
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members.
A ShinyHunters spokesperson subsequently denied having any connections with van der Stap.
"Six years on, ShinyHunters is less a group than a brand and business model that has outlived its founders," researchers Enzo Saez and Robert (Bobby) Venal
said
.
ShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI.
Second Major Detention in Weeks
Khader’s detention follows the September arrest in the Netherlands of
Pepijn van der Stap
, a previously convicted hacker suspected by Dutch investigators of playing a role in ShinyHunters.
Google has also
documented
a much larger ShinyHunters-branded campaign involving voice phishing, fake credential pages and theft from cloud services including Salesforce.
Google tracks several related clusters separately because membership and partnerships within the ShinyHunters infrastructure can change and impersonation is also a concern.
Google Threat Intelligence Group and Mandiant separately documented ShinyHunters, tracked as UNC6240, mass-exploiting CVE-2026-35273 against PeopleSoft systems.
More recent reporting, however, placed him much closer to ShinyHunters’ operations.
Image credit: Krebs On Security
FBI Breach Put ShinyHunters Under Intense Pressure
The detention follows ShinyHunters’ September
attack on the FBI Jobs portal
.
ShinyHunters
claimed it used an Oracle PeopleSoft vulnerability
for the attack.
ShinyHunters
claimed in April
that it gained access to Rockstar’s Snowflake environment through credentials or tokens exposed following a third-party incident involving Anodot.
Reuters lost contact with ShinyHunters through an account previously used by the group on Tuesday.
Alleged ShinyHunters leader arrested in the Netherlands.
ShinyHunters is among the most prolific cybercrime groups currently in operation.
Previous victims of ShinyHunters this year include
Instructure
,
Salesforce
, Snowflake and
McKesson
.
Leatherman, who described van der Stap as an alleged leader of the group, pulled further on that thread, speaking directly to other members of ShinyHunters in his recorded statement.
infrastructure
1.5
Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million.
infrastructure
2.7
Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million.
financial
€1.5 prosecutors
Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million.
data_breach
2 terabytes
The arrest was made shortly after the extortion group hacked and defaced
the FBI’s jobs site
, FBIJobs.gov, boasting about stealing 2-3 terabytes of data.
It sent a sample list of 5,000 FBI employees to multiple media outlets, stating that it stole 2-3 terabytes of data.
The group claimed it entered through
apply.fbijobs.gov
, defaced the site and obtained between 2TB and 3TB of information after accessing other systems.
financial
$70 group
The FBI later
confirmed the arrest
, saying the individual was involved in the hacking of more than 140 organizations, as well as in collecting at least $70 million in extortion payments.
Since 2025, the authorities say, he has been involved in the hacking of over 140 organizations and in collecting at least $70 million in extortion payments.
According to the FBI, the group has extorted more than $70 million from victims so far this year.
victims
140 organizations
The FBI later
confirmed the arrest
, saying the individual was involved in the hacking of more than 140 organizations, as well as in collecting at least $70 million in extortion payments.
Since 2025, the authorities say, he has been involved in the hacking of over 140 organizations and in collecting at least $70 million in extortion payments.
organisation
Van der Stap
Van der Stap used the nickname Umbreon in his extortion activities, investigative journalist Brian Krebs reported.
The FBI described Van der Stap as one of the group’s alleged leaders, although ShinyHunters
denied to Hackread.com
that he had any association with them.
Meanwhile, news outlets in the Netherlands reported explosive new allegations leveled at Van der Stap, whose supposed personal transformation from convicted to reformed hacker has been widely covered in the tech news media.
organisation
Tor
In a fresh statement on its Tor-based leak site, the extortion group says its operations and infrastructure have not been affected by the recent events, warning victim organizations that they should continue negotiations to prevent the leak of stolen data.
organisation
Reuters
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters
reported
, citing three people familiar with the matter.
The suspect, Saif al-Din Khader, known as Rey, a teenage cybercriminal from Amman, is helping the FBI identify other ShinyHunters members, Reuters
reports
.
Jana Winter, Raphael Satter, and A.J. Vicens report:
A key member of the ShinyHunters hacking group, which claims to have stolen data on every FBI employee, was detained this week in Jordan, three people familiar with the matter told Reuters.
Jordanian authorities detained Saif al-Din Khader this week, according to three people familiar with the case who
spoke to Reuters
.
organisation
SIM
…that it's not seeking a monetary payoff in the FBI case, but rather apply pressure on the FBI to amend what it said were false allegations about the group and challenge claims made by the agency about its connections with
The Com
, a
loose-knit
cybercrime collective
notorious for social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, and physical violence.
organisation
Sekoia
"
In a deep-dive report tracing ShinyHunters' origins and their tactical evolution, cybersecurity companies Sekoia and Beazley Security said its lineage goes back to two progenitor hacking groups, TheDarkOverlord and GnosticPlayers, that specialized in extortion and data leak operations.
organisation
Beazley Security
"
In a deep-dive report tracing ShinyHunters' origins and their tactical evolution, cybersecurity companies Sekoia and Beazley Security said its lineage goes back to two progenitor hacking groups, TheDarkOverlord and GnosticPlayers, that specialized in extortion and data leak operations.
organisation
GnosticPlayers
"
In a deep-dive report tracing ShinyHunters' origins and their tactical evolution, cybersecurity companies Sekoia and Beazley Security said its lineage goes back to two progenitor hacking groups, TheDarkOverlord and GnosticPlayers, that specialized in extortion and data leak operations.
organisation
MFA
The operations targeted corporate SSO credentials and MFA codes before extracting data from SaaS platforms and using it for extortion.
data_breach
3 TB
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members.
The group claimed it entered through
apply.fbijobs.gov
, defaced the site and obtained between 2TB and 3TB of information after accessing other systems.
victims
500 organizations
Authorities arrested the alleged leader and two additional members of KillSec, a data extortion group primarily run by teenagers that successfully compromised about 500 organizations since 2024,
Europol
and the
Justice Department
said Thursday.
organisation
Kill Security Ransomware Group
The cybercrime group, which was also known as Kill Security Ransomware Group, exploited various defects to intrude victims’ computers or cloud-based network infrastructure and steal sensitive data for extortion demands.
organisation
Founder of Ransomware Negotiation Firm
FBI Arrests Founder of Ransomware Negotiation Firm.
organisation
Federal Bureau of Investigation
Agents with the
Federal Bureau of Investigation
(FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the
ShinyHunters
hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.
organisation
KrebsOnSecurity
Agents with the
Federal Bureau of Investigation
(FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the
ShinyHunters
hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.
KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey’s father — Royal Jordanian Airlines.
KrebsOnSecurity has learned that the suspect, who uses the hacker handle “
Rey
,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company
Boeing
, which manufactures the fleet of planes used by the employer of Rey’s father —
Royal Jordanian Airlines
.
organisation
Times
The Times story did not identify the man, nor did
a statement
on Twitter/X about the arrest from
FBI Director Kash Patel
.
organisation
Van der Stap’s
Immediately after Van der Stap’s arrest, another member of ShinyHunters named “
Rey
” assumed control over the group and began taunting the FBI over data the group stole from the agency’s online recruitment portal, which included each’s person’s unit and specialization, as well as medical and psychiatric records.
In the days after the news broke of Van der Stap’s arrest, a cybercrime-focused chat server on Telegram that was allegedly operated by Rey erupted with hot takes, with most participants heaping ridicule on the teenage hacker after he publicly backed down from threats against the FBI and Cl0p, and again when
the ShinyHunters’s darknet website suddenly went offline
.
organisation
BleepingComputer
ShinyHunters
told BleepingComputer in June
that the original goal behind exploiting the PeopleSoft vulnerability was to breach the FBI’s own PeopleSoft database, but the hackers said those attacks were unsuccessful for some reason.
organisation
Cl0p
But just hours after that request was sent, Rey began deleting his various social media accounts, including the Twitter/X account he previously used to taunt the FBI, Cl0p, and other ShinyHunters victims.
organisation
Khader’s
The FBI declined to comment on Khader’s alleged arrest, only telling Recorded Future News that it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters.
The exact circumstances of Khader’s detention and his current location have not been disclosed.
organisation
Recorded Future News
The FBI declined to comment on Khader’s alleged arrest, only telling Recorded Future News that it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters.
organisation
AT&T
ShinyHunters has claimed dozens of high-profile data thefts in recent months and has been in the crosshairs of the FBI for nearly a year after dozens of attacks on large companies like
Ticketmaster
and
AT&T
as well as educational publisher
McGraw Hill
,
Carnival Cruise Line
,
7-Eleven
and
other
companies
.
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
NightmareStresser DDoS Service Disrupted in International Operation
organisation
McGraw Hill
ShinyHunters has claimed dozens of high-profile data thefts in recent months and has been in the crosshairs of the FBI for nearly a year after dozens of attacks on large companies like
Ticketmaster
and
AT&T
as well as educational publisher
McGraw Hill
,
Carnival Cruise Line
,
7-Eleven
and
other
companies
.
organisation
Carnival Cruise Line
ShinyHunters has claimed dozens of high-profile data thefts in recent months and has been in the crosshairs of the FBI for nearly a year after dozens of attacks on large companies like
Ticketmaster
and
AT&T
as well as educational publisher
McGraw Hill
,
Carnival Cruise Line
,
7-Eleven
and
other
companies
.
organisation
Social Security
The FBI incident stirred anxiety within the agency, exposing the names, home addresses, cell phone numbers, Social Security numbers, FBI email addresses, employee ID numbers and much more of nearly every FBI agent.
victims
5,000 FBI employees
ShinyHunters sent a sample list of 5,000 FBI employees to the media, claiming to be in possession of the personal and health information of all current and former FBI employees.
It sent a sample list of 5,000 FBI employees to multiple media outlets, stating that it stole 2-3 terabytes of data.
organisation
Pepijn
While the Dutch police and the FBI refrained from revealing the suspect’s identity, independent reports have suggested he is Pepijn van der Stap, who was convicted in 2023 for hacking and extorting numerous organizations and was on supervised release after serving three years in prison.
Although his identity has not been disclosed, independent reports revealed that it was Pepijn van der Stap, a reformed hacker who has been employed as an offensive security lead at the Dutch company Neo Security.
organisation
X.
Related
“More arrests are on the table,” FBI Director Kash Patel
posted
on X.
Related:
Crypto Scammers Hijack Microsoft’s Official X Account
Related:
organisation
Microsoft
“More arrests are on the table,” FBI Director Kash Patel
posted
on X.
Related:
Crypto Scammers Hijack Microsoft’s Official X Account
Related:
organisation
Official X Account
“More arrests are on the table,” FBI Director Kash Patel
posted
on X.
Related:
Crypto Scammers Hijack Microsoft’s Official X Account
Related:
organisation
PII
The group previously claimed it stole from the FBI’s jobs site the personally identifiable information (PII) and protected health information (PHI) of all current and former FBI employees.
organisation
PHI
The group previously claimed it stole from the FBI’s jobs site the personally identifiable information (PII) and protected health information (PHI) of all current and former FBI employees.
organisation
Grav CMS
"
In recent weeks, the prolific hacking crew has come under the spotlight for
hijacking
the
darknet website
of a fellow cybercriminal outfit, Cl0p, by exploiting an
unpatched flaw
in Grav CMS and its
hack of the FBI's "apply.fbijobs[.]gov" portal
, stealing around three terabytes of sensitive data.
organisation
Canvas
From Canvas and Rockstar to Large SaaS Data Theft
The FBI incident followed an aggressive year for ShinyHunters.
organisation
Rockstar
From Canvas and Rockstar to Large SaaS Data Theft
The FBI incident followed an aggressive year for ShinyHunters.
organisation
Boeing
KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey’s father — Royal Jordanian Airlines.
KrebsOnSecurity has learned that the suspect, who uses the hacker handle “
Rey
,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company
Boeing
, which manufactures the fleet of planes used by the employer of Rey’s father —
Royal Jordanian Airlines
.
organisation
Mandiant
Oracle quickly issued a fix for CVE-2026-35273, which ShinyHunters first began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations that couldn’t apply the security update quickly enough.
Google Threat Intelligence Group and Mandiant separately documented ShinyHunters, tracked as UNC6240, mass-exploiting CVE-2026-35273 against PeopleSoft systems.
organisation
PGP
“He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke,” one member recounted.
organisation
Cyber Security News
Two sources said Jordanian authorities took Khader into […] The post ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers appeared first on Cyber Security News .
organisation
PeopleSoft
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
NightmareStresser DDoS Service Disrupted in International Operation
Google Threat Intelligence Group and Mandiant separately documented ShinyHunters, tracked as UNC6240, mass-exploiting CVE-2026-35273 against PeopleSoft systems.
organisation
Verizon
Related
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
NightmareStresser DDoS Service Disrupted in International Operation
organisation
US Court
Related:
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
Related:
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related:
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Related:
NightmareStresser DDoS Service Disrupted in International Operation
organisation
Come Forward
ShinyHunters Defiant After FBI Calls on Members to Come Forward.
organisation
Second Major Detention
Second Major Detention in Weeks
Khader’s detention follows the September arrest in the Netherlands of
Pepijn van der Stap
, a previously convicted hacker suspected by Dutch investigators of playing a role in ShinyHunters.
organisation
Khader
Second Major Detention in Weeks
Khader’s detention follows the September arrest in the Netherlands of
Pepijn van der Stap
, a previously convicted hacker suspected by Dutch investigators of playing a role in ShinyHunters.
organisation
Google
Google has also
documented
a much larger ShinyHunters-branded campaign involving voice phishing, fake credential pages and theft from cloud services including Salesforce.
organisation
Salesforce
Google has also
documented
a much larger ShinyHunters-branded campaign involving voice phishing, fake credential pages and theft from cloud services including Salesforce.
organisation
UNC6240
Google Threat Intelligence Group and Mandiant separately documented ShinyHunters, tracked as UNC6240, mass-exploiting CVE-2026-35273 against PeopleSoft systems.
organisation
CVE-2026
Google Threat Intelligence Group and Mandiant separately documented ShinyHunters, tracked as UNC6240, mass-exploiting CVE-2026-35273 against PeopleSoft systems.
organisation
Krebs On Security
Image credit: Krebs On Security
FBI Breach Put ShinyHunters Under Intense Pressure
organisation
Oracle PeopleSoft
ShinyHunters
claimed it used an Oracle PeopleSoft vulnerability
for the attack.
organisation
Rockstar’s Snowflake
ShinyHunters
claimed in April
that it gained access to Rockstar’s Snowflake environment through credentials or tokens exposed following a third-party incident involving Anodot.
organisation
Anodot
ShinyHunters
claimed in April
that it gained access to Rockstar’s Snowflake environment through credentials or tokens exposed following a third-party incident involving Anodot.
organisation
KrebsOnSecurity the
One source close to the investigation told KrebsOnSecurity the Canadian person arrested this week was visiting Pennsylvania for a cyber insurance conference, and that the suspect’s company specialized in handling ransomware negotiations with cybercrime groups.
organisation
Identify Alleged
Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader
Related:
organisation
Ransomware
“Ransomware remains a serious and evolving threat to all sectors of our economy, from critical infrastructure to small businesses,” he added.
organisation
CyberSteward
According to LinkedIn, Cypher was co-founded by a Canadian man named
Edward Dubrovsky
, who is now associated with another Canadian security firm and sponsor called
CyberSteward
.
organisation
the Dutch company Neo Security
Although his identity has not been disclosed, independent reports revealed that it was Pepijn van der Stap, a reformed hacker who has been employed as an offensive security lead at the Dutch company Neo Security.
organisation
the Cyber Risk Summit
In a post to LinkedIn approximately one month ago, Dubrovsky said he had plans to attend the Cyber Risk Summit with the rest of the CyberSteward team.
organisation
Courtlistener.com
But a handful of them were
indexed at Courtlistener.com
, including a summary of the complaint, which charges the defendant with “conspiracy to threaten to impair the confidentiality of information with the intent to extort money,” and “interference with commerce by threats.”
Image: Courtlistener.com
The inmate locator at the
U.S. Bureau of Prisons
website reports that a 54-year-old Edwar…
organisation
U.S. Bureau of Prisons
But a handful of them were
indexed at Courtlistener.com
, including a summary of the complaint, which charges the defendant with “conspiracy to threaten to impair the confidentiality of information with the intent to extort money,” and “interference with commerce by threats.”
Image: Courtlistener.com
The inmate locator at the
U.S. Bureau of Prisons
website reports that a 54-year-old Edwar…
organisation
Amazon
“At the heart of the book is a critical distinction: communicating with a criminal is not the same as negotiating a payment, and negotiating is not a commitment to pay,” reads an excerpt from the book’s listing on Amazon.
organisation
Neo Security’s
Neo Security’s owner
Benjamin Korper
told Reuters he has hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but that so far investigators have found no evidence he acted against his employer or clients.
organisation
Dread Pirate
Think the
Dread Pirate Roberts
character in the 1980s cult movie classic “The Princess Bride,” only succession by death is replaced with succession by arrest, and there can be multiple simultaneous Dread Pirate Robertses.
organisation
Dread Pirate Robertses
Think the
Dread Pirate Roberts
character in the 1980s cult movie classic “The Princess Bride,” only succession by death is replaced with succession by arrest, and there can be multiple simultaneous Dread Pirate Robertses.
financial
$200 Rey
We’re aware of claims that [Rey] caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25–30% cut over the past few months.”
organisation
Fouad Eltibrizi
One of the group’s accused members, Fouad Eltibrizi, was arrested Wednesday in the United Kingdom and awaits extradition to the United States, the Justice Department said.
organisation
the Justice Department
One of the group’s accused members, Fouad Eltibrizi, was arrested Wednesday in the United Kingdom and awaits extradition to the United States, the Justice Department said.
organisation
Accelerated Academy
Three of those victims align with organizations that were listed on KillSec’s data-leak site for
Instituto de Ojos
,
US BioTek Laboratories
and
Accelerated Academy
.
organisation
TB
The group claimed it entered through
apply.fbijobs.gov
, defaced the site and obtained between 2TB and 3TB of information after accessing other systems.
organisation
the Scattered Lapsus$ Hunters
Khader is also a known member of the Scattered Lapsus$ Hunters group.
organisation
Groups
“Groups like this don’t win with new exploits alone.
organisation
BreachForums
"Also in 2024, Rey would take over as administrator of the most recent incarnation of BreachForums."
organisation
Leatherman
"
Leatherman, who described van der Stap as an alleged leader of the group, also urged other members to speak out and said that they can no longer hide behind perceived international anonymity and evade detection.
organisation
RaidForums
"What began in 2020 as a small crew trading stolen databases on RaidForums has become a persistent, self-renewing group that has absorbed indictments, arrests, and forum seizures without ever going quiet for long.
organisation
PwnForums
A redacted PwnForums screenshot showing the profile of “Rey” alongside a panel containing alleged personal and family details.
organisation
Hackread.com
The alleged personal information shown has not been independently verified (Image credit: Hackread.com)
Hackread.com
reported on the identification
at the time, noting that Rey disputed some of the claims linking him to the group.
data_breach
3.65 TB
In May,
the group targeted Instructure’s Canvas
learning platform, claiming it stole 3.65TB of information connected to nearly 9,000 institutions and roughly 275 million users.
victims
275 users
In May,
the group targeted Instructure’s Canvas
learning platform, claiming it stole 3.65TB of information connected to nearly 9,000 institutions and roughly 275 million users.
organisation
Europol
Europol said a suspected developer involved in the group committed multiple crimes before they turned 18 in August.
organisation
KillSec
Officials seized KillSec’s data-leak site and at least 110 terabytes of data, including information on the group’s criminal proceeds.
data_breach
110 terabytes
Officials seized KillSec’s data-leak site and at least 110 terabytes of data, including information on the group’s criminal proceeds.
organisation
Eltibrizi
Some of the group’s victims were identified by initials and the location and date of the attack in the indictment filed against Eltibrizi.
2026/10/10
The FBI arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters.
Click on any entity below to view its context and source!
attribution
FBI
The New York Times
reported today
that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters.
threat_actor
ShinyHunters
The New York Times
reported today
that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters.
source_region
Canada
The New York Times
reported today
that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters.
organisation
The New York Times
The New York Times
reported today
that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters.
Tactical Metrics
Metrics
financial
70,000,000
Financial Impact / Stolen Funds
Click for context!
According to the FBI, the group has extorted more than $70 million from victims so far this year.
The FBI later
confirmed the arrest
, saying the individual was involved in the hacking of more than 140 organizations, as well as in collecting at least $70 million in extortion payments.
Since 2025, the authorities say, he has been involved in the hacking of over 140 organizations and in collecting at least $70 million in extortion payments.
"Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement.
The
FBI says
ShinyHunters and its alleged co-conspirators have breached more than 140 organisations since last year and collected at least $70 million in extortion payments.
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a
statement on YouTube
Tuesday.
Metrics
infrastructure
1.5
Software Version
Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million.
Metrics
infrastructure
2.7
Software Version
Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million.
Metrics
financial
1,500,000
Financial Impact / Stolen Funds
Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million.
Metrics
financial
200,000,000
Financial Impact / Stolen Funds
We’re aware of claims that [Rey] caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25–30% cut over the past few months.”
Metrics
victims
5,000
Fbi Employees
ShinyHunters sent a sample list of 5,000 FBI employees to the media, claiming to be in possession of the personal and health information of all current and former FBI employees.
It sent a sample list of 5,000 FBI employees to multiple media outlets, stating that it stole 2-3 terabytes of data.
Metrics
data_breach
2
Terabytes
The arrest was made shortly after the extortion group hacked and defaced
the FBI’s jobs site
, FBIJobs.gov, boasting about stealing 2-3 terabytes of data.
It sent a sample list of 5,000 FBI employees to multiple media outlets, stating that it stole 2-3 terabytes of data.
The group claimed it entered through
apply.fbijobs.gov
, defaced the site and obtained between 2TB and 3TB of information after accessing other systems.
Metrics
victims
140
Organizations
The FBI later
confirmed the arrest
, saying the individual was involved in the hacking of more than 140 organizations, as well as in collecting at least $70 million in extortion payments.
Since 2025, the authorities say, he has been involved in the hacking of over 140 organizations and in collecting at least $70 million in extortion payments.
"Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement.
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a
statement on YouTube
Tuesday.
Metrics
data_breach
3
Tb
The group claimed it entered through
apply.fbijobs.gov
, defaced the site and obtained between 2TB and 3TB of information after accessing other systems.
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members.
Metrics
data_breach
4
Tb
In May,
the group targeted Instructure’s Canvas
learning platform, claiming it stole 3.65TB of information connected to nearly 9,000 institutions and roughly 275 million users.
Metrics
victims
275,000,000
Users
In May,
the group targeted Instructure’s Canvas
learning platform, claiming it stole 3.65TB of information connected to nearly 9,000 institutions and roughly 275 million users.
Metrics
victims
500
Organizations
Authorities arrested the alleged leader and two additional members of KillSec, a data extortion group primarily run by teenagers that successfully compromised about 500 organizations since 2024,
Europol
and the
Justice Department
said Thursday.
Metrics
data_breach
110
Terabytes
Officials seized KillSec’s data-leak site and at least 110 terabytes of data, including information on the group’s criminal proceeds.
Intelligence Sources
CyberScoop
2026-09-29
Krebs On Security
2026-10-10
FBI Arrests Founder of Ransomware Negotiation Firm
Krebs On Security
AlienVault OTX
2026-10-09
TheRecord
2026-10-05
CyberScoop
2026-10-01
HackRead
2026-10-03
Data Breaches
2026-10-03
The Hacker News
2026-10-04
AlienVault OTX
2026-10-03
SecurityWeek
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T12:05
Comprehensive Tactical Telemetry
Highly Correlated Entities
93x
organisation
Identified Entity
Founder of Ransomware Negotiation Firm
entity
54x
timeline
Temporal Reference
October 8
date
16x
attribution
Attributing Entity
FBI
authority
10x
tactic
Cyber Operation Type
Extortion
tactic
10x
industry
Targeted Sector
Aviation
sector
9x
target region
Target Country
Netherlands
country
8x
source region
Origin Country
Canada
country
3x
threat actor
APT Group
ShinyHunters
actor
3x
financial
Financial Impact / Stolen Funds
70,000,000
group
2x
infrastructure
Software Version
1.5
version
2x
malware
Malware Payload
Umbreon
tool
2x
data breach
Terabytes
2
terabytes
2x
victims
Organizations
140
organizations
2x
data breach
Tb
3
tb
Contextual Telemetry
Context Block
12 METRICS
vulnerability
Exploited CVE
CVE-2026-35273
cve
general metric
Fbi Personnel
5,000
fbi personnel
general metric
Eleven
7
eleven
victims
Fbi Employees
5,000
fbi employees
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
general metric
Organisations
140
organisations
general metric
Unc6240
35,273
unc6240
general metric
Institutions
9,000
institutions
victims
Users
275,000,000
users
target region
Target Region
EUROPE
region
campaign
Campaign
Operation KillSwitch
operation
general metric
Countries
10
countries
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.