INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FBI Arrests ShinyHunters Suspect Linked to Boeing Extortion Case

| 2026-10-09 17:55 CRITICAL HIGH RANSOMWARE & EXTORTION DATA BREACH LAW ENFORCEMENT
Executive Summary
AI-generated
The FBI arrested Edward Dubrovsky, a Canadian man and co-founder of the cybersecurity firm Cypfer, on October 8 in Pennsylvania on suspicion of assisting ShinyHunters hacking group. The suspect's company specialized in handling ransomware negotiations with cybercrime groups. One person affected is Dubrovsky himself, who was previously associated with another Canadian security firm called CyberSteward and had plans to attend the Cyber Risk Summit with his team. The attack works by exploiting vulnerabilities in cybersecurity systems to negotiate ransom demands from hackers. As of October 10, Dubrovsky is currently being held at a federal facility in Philadelphia after the case was moved to the Eastern District of Texas, where it has become the epicenter of the FBI's ShinyHunters investigation.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-35273 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ap•••••.gov
ap•••••.fbijobs
ha•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation KillSwitchOperation KillSwitch ShinyHuntersShinyHuntersScattered SpiderScattered SpiderLAPSUS$LAPSUS$ UmbreonUmbreonSysUpdateSysUpdate CVE-2026-35273CVE-2026-35273
Target & Sectors
NORTH_AMERICA NORTH_AMERICA BENELUX BENELUX educationeducation governmentgovernment transportationtransportation mediamedia healthhealth aerospaceaerospace aviationaviation technologytechnology
Incident Timeline
‎May 2020
ShinyHunters, a group that emerged publicly around April or May 2020, extorted Boeing's spin-off company prior to their arrests.
threat_actor ShinyHunters
‎late 2024
Threat actors associated with the ransomware group Hellcat leaked data prior to their eventual arrest.
tactic Ransomware
tactic Data Leak
‎March 2025
Threat actors known as ShinyHunters extorted a Boeing spin-off using phishing emails, identified through I.D.O. in Puerto Rico and U.S.B.L. in Washington state, prior to their subsequent arrests.
target_region Puerto Rico
organisation I.D.O.
organisation U.S.B.L.
‎at least June 2025
Threat actors known as ShinyHunters extorted a Boeing spin-off prior to Khader's cooperation with law enforcement starting at least June 2025.
‎September 2025
Threat actors known as ShinyHunters extorted a Boeing spin-off using phishing attacks in Puerto Rico, Washington state, and Louisiana between March 2025 and September 2025.
target_region Puerto Rico
organisation I.D.O.
organisation U.S.B.L.
‎2025/09/29
Threat actors associated with ShinyHunters allegedly breached more than 140 organizations and took at least $70 million in extortion payments prior to their arrests.
tactic Extortion
attribution FBI
financial $70 group
victims 140 organizations
‎2025/10/03
ShinyHunters and its alleged co-conspirators breached more than 140 organisations since last year, collecting at least $70 million in extortion payments.
tactic Extortion
attribution FBI
threat_actor ShinyHunters
financial $70 group
general_metric 140 organisations
‎2025/10/04
Threat actors known as ShinyHunters allegedly breached more than 140 organizations and took at least $70 million in extortion payments prior to their arrests.
tactic Extortion
attribution FBI
financial $70 group
victims 140 organizations
‎2025/10/07
Threat actors known as ShinyHunters demanded ransom in exchange for the release of sensitive data from Jeppesen ForeFlight, a business unit divested by Boeing.
‎late 2025
Threat actors known as ShinyHunters allegedly attempted to extort a navigation and digital aviation unit from Boeing prior to Rey's arrest.
organisation Boeing
‎early 2025
Rey claimed on Telegram in early 2025 that his father was an airline pilot.
organisation Telegram
‎November 2025
Threat actors associated with ShinyHunters allegedly placed extortion demands targeting Boeing's subsidiary Jeppesen ForeFlight prior to the arrests of individuals involved in the conspiracy.
tactic Ransomware
tactic Extortion
threat_actor ShinyHunters
organisation Thoma Bravo
threat_actor LAPSUS$
organisation SLH
threat_actor Scattered Spider
source_region Jordan
organisation Krebs
organisation Signal
‎March 2026
Threat actors using the Cl0p hacking group, allegedly linked to Russian developers and hackers, targeted Boeing's spin-off company prior to their eventual arrest.
source_region Russian Federation
‎May 2026
ShinyHunters claimed they hacked the FBI to counter the agency's narrative in a May 2026 alert advising victims against paying ransom.
attribution FBI
threat_actor ShinyHunters
organisation Register
‎May 15, 2026
The FBI released a flash notice on May 15, 2026, announcing extortion by ShinyHunters targeting Boeing's spin-off.
industry Aviation
industry Aerospace
industry Media
attribution FBI
threat_actor ShinyHunters
‎2026/09/01
A Dutch national was indicted in Puerto Rico for his alleged role as a negotiator for ShinyHunters, facing up to 10 years in prison.
target_region Netherlands
target_region Puerto Rico
‎2026/09/03
Threat actors, identified as Dutch hacker Pepijn van der Stap (Umbreon), took control of the ShinyHunters brand prior to their arrest on September 3, 2026.
threat_actor ShinyHunters
malware Umbreon
source_region Netherlands
‎September 9
Threat actors known as ShinyHunters extorted a Boeing spin-off prior to Van der Stap's arrest and subsequent appointment as offensive security lead at Neo Security.
source_region Netherlands
organisation Neo Security
‎Sept. 9
Threat actors known as ShinyHunters demanded ransom from Boeing's spin-off company, reportedly using a phishing attack.
‎2026/09/10
The FBI has been analyzing devices seized from Pepijn van der Stap, a convicted cybercriminal linked to ShinyHunters, in connection with the Dutch police arrest.
attribution FBI
threat_actor ShinyHunters
tactic Ransomware
target_region Netherlands
organisation Pepijn
‎September 15
Threat actors, identified as ShinyHunters led by Pepijn van der Stap, extorted a Boeing spin-off prior to their arrest on September 15 in the Netherlands.
attribution FBI
threat_actor ShinyHunters
tactic Ransomware
source_region Netherlands
organisation Korper
tactic Extortion
‎Sept 16
Police in the Netherlands used flash-bang grenades during a raid on Van Der Stap's residence on September 16.
source_region Netherlands
‎Sept. 22
Rey uploaded a taunting meme to Twitter on September 22.
‎2026/09/22
ShinyHunters allegedly extorted Boeing's spin-off company prior to their arrest by authorities.
tactic Extortion
attribution FBI
threat_actor ShinyHunters
‎Sept. 25
ShinyHunters mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across various industries.
threat_actor ShinyHunters
attribution Google Threat Intelligence Group
‎2026/09/27
Threat actors known as ShinyHunters used extortion to target a Boeing spin-off prior to their arrest of a 24-year-old Amsterdam man.
threat_actor ShinyHunters
‎September 28
ShinyHunters exploited a vulnerability (CVE-2026-35273) in PeopleSoft to gain access to the FBI site and other victims.
attribution FBI
threat_actor ShinyHunters
vulnerability CVE-2026-35273
organisation PeopleSoft
organisation Oracle
target_region Netherlands
source_region Jordan
attribution Reuters
‎2026/09/28
A 24-year-old man from Amsterdam was arrested by the FBI as part of an investigation into ShinyHunters.
organisation ShinyHunter
threat_actor ShinyHunters
organisation Telegram
attribution FBI
target_region Netherlands
‎September 29, 2026
Rey, a suspect in the ShinyHunters extortion case against Boeing's spin-off company, was brought into custody on September 29, 2026.
industry Aviation
industry Aerospace
industry Media
attribution the U.S. Federal Bureau of Investigation (FBI
‎Sept. 29
Threat actors ShinyHunters allegedly extorted a Boeing spin-off prior to their arrest, which was reported by the Dutch daily RTL on September 29.
target_region Netherlands
‎September 29
Threat actors ShinyHunters extorted a Boeing spin-off prior to the arrest of Pepijn van der Stap on September 29.
attribution FBI
organisation Pepijn
attribution the Dutch National Police
‎29 September
ShinyHunters' leak site continued showing activity after Rey was reportedly detained on 29 September.
threat_actor ShinyHunters
tactic Sabotage
‎1 October 2026
ShinyHunters posted updated dark web leak sites featuring stolen data from O'Reilly Automotive and DexCom on 1 October 2026.
threat_actor ShinyHunters
industry Automotive
organisation DexCom
‎2026/10/03
Reuters reported that Saif Al-din Khader, a teenager identified as Rey, had been detained and was cooperating with FBI investigators.
attribution FBI
organisation Reuters
‎October 3
A suspected ShinyHunters member, identified as Saif al-Din Khader, was detained by Jordanian authorities and began cooperating with the FBI on October 3.
attribution FBI
threat_actor ShinyHunters
organisation Reuters
target_region Jordan
‎3 October
ShinyHunters deleted both listings four days after Rey's reported detention on 3 October.
‎October 5
ShinyHunters hacked the FBI recruitment website, exposing sensitive data on over 5,000 FBI personnel.
attribution FBI
threat_actor ShinyHunters
general_metric 5,000 FBI personnel
‎October 7
Threat actors known as ShinyHunters allegedly extorted a navigation and digital aviation unit from Boeing prior to Rey's arrest on October 7.
organisation Boeing
‎2026/10/07
Two Russian men were identified as the core operators behind Cl0p, a long-established ransomware group.
tactic Ransomware
target_region Russian Federation
organisation HIRE
‎October 8
Threat actors known as ShinyHunters extorted Boeing's spin-off company prior to Edward Dobrovsky's arrest on October 8.
tactic Extortion
‎between Oct. 5 and Oct. 7
Threat actors used the Loews Philadelphia Hotel as a venue for the Cyber Risk Summit between October 5 and October 7, potentially exposing attendees to phishing or other attacks.
organisation the Loews Philadelphia Hotel
‎October 9
The ShinyHunters extortion case against a Boeing spin-off was moved to the Eastern District of Texas court on October 9.
attribution FBI
threat_actor ShinyHunters
organisation CourtListener
‎2026/10/09
A suspected member of the ShinyHunters hacking group, identified as Saif al-Din Khader, was detained by Jordanian authorities.
threat_actor ShinyHunters
infrastructure 1.5
infrastructure 2.7
financial €1.5 prosecutors
data_breach 2 terabytes
financial $70 group
victims 140 organizations
organisation Van der Stap
organisation Tor
organisation Reuters
organisation SIM
organisation Sekoia
organisation Beazley Security
organisation GnosticPlayers
organisation MFA
data_breach 3 TB
victims 500 organizations
organisation Kill Security Ransomware Group
organisation Founder of Ransomware Negotiation Firm
organisation Federal Bureau of Investigation
organisation KrebsOnSecurity
organisation Times
organisation Van der Stap’s
organisation BleepingComputer
organisation Cl0p
organisation Khader’s
organisation Recorded Future News
organisation AT&T
organisation McGraw Hill
organisation Carnival Cruise Line
organisation Social Security
victims 5,000 FBI employees
organisation Pepijn
organisation X. Related
organisation Microsoft
organisation Official X Account
organisation PII
organisation PHI
organisation Grav CMS
organisation Canvas
organisation Rockstar
organisation Boeing
organisation Mandiant
organisation PGP
organisation Cyber Security News
organisation PeopleSoft
organisation Verizon Related
organisation US Court
organisation Come Forward
organisation Second Major Detention
organisation Khader
organisation Google
organisation Salesforce
organisation UNC6240
organisation CVE-2026
organisation Krebs On Security
organisation Oracle PeopleSoft
organisation Rockstar’s Snowflake
organisation Anodot
organisation KrebsOnSecurity the
organisation Identify Alleged
organisation Ransomware
organisation CyberSteward
organisation the Dutch company Neo Security
organisation the Cyber Risk Summit
organisation Courtlistener.com
organisation U.S. Bureau of Prisons
organisation Amazon
organisation Neo Security’s
organisation Dread Pirate
organisation Dread Pirate Robertses
financial $200 Rey
organisation Fouad Eltibrizi
organisation the Justice Department
organisation Accelerated Academy
organisation TB
organisation the Scattered Lapsus$ Hunters
organisation Groups
organisation BreachForums
organisation Leatherman
organisation RaidForums
organisation PwnForums
organisation Hackread.com
data_breach 3.65 TB
victims 275 users
organisation Europol
organisation KillSec
data_breach 110 terabytes
organisation Eltibrizi
‎2026/10/10
The FBI arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters.
attribution FBI
threat_actor ShinyHunters
source_region Canada
organisation The New York Times
Tactical Metrics
Metrics
financial
70,000,000
Financial Impact / Stolen Funds
Metrics
infrastructure
‎1.5
Software Version
Metrics
infrastructure
‎2.7
Software Version
Metrics
financial
1,500,000
Financial Impact / Stolen Funds
Metrics
financial
200,000,000
Financial Impact / Stolen Funds
Metrics
victims
5,000
Fbi Employees
Metrics
data_breach
2
Terabytes
Metrics
victims
140
Organizations
Metrics
data_breach
3
Tb
Metrics
data_breach
4
Tb
Metrics
victims
275,000,000
Users
Metrics
victims
500
Organizations
Metrics
data_breach
110
Terabytes