Jordanian authorities have reportedly detained a teenager in Amman suspected of playing a leading role in the ShinyHunters data-theft and extortion group, according to Reuters and other reporting. The individual, known online as “Rey,” is said to be cooperating with the FBI as investigators seek to identify other alleged participants in the group.
The detention reportedly occurred while ShinyHunters was attempting to extort Jeppesen ForeFlight, a navigation and digital aviation business that Boeing sold to private-equity firm Thoma Bravo in late 2025. Sources cited in reporting said investigators viewed the incident as especially significant because allegedly stolen information could create operational security concerns.
Boeing said it was aware of threat-actor claims involving data allegedly connected to the company and its former subsidiary. “We are actively reviewing the matter with the Jeppesen ForeFlight team,” a Boeing spokesperson said in a statement. Jeppesen ForeFlight said its investigation had found no impact to its products or operations.
PeopleSoft exploitation linked to broader campaign
ShinyHunters has been associated with the exploitation of CVE-2026-35273, a vulnerability in Oracle PeopleSoft software used by organizations for human-resources, payroll and recruiting functions. Security researchers said the group initially used the flaw as a zero-day before Oracle issued a fix.
According to Mandiant and Google Threat Intelligence Group reporting, attackers later bypassed some web application firewall protections through URL-encoding techniques and used the vulnerability in a broad campaign affecting organizations in sectors including education, healthcare, technology, transportation and government.
- Organizations using affected PeopleSoft deployments should apply Oracle’s security updates as soon as possible.
- Security teams should review internet-facing PeopleSoft systems, web application firewall rules and logs for anomalous requests or encoding-based evasion attempts.
- Companies should investigate whether sensitive employee, applicant or operational data may have been exposed and prepare notification procedures where required.
The case follows reports that an FBI recruitment website was compromised after a contractor allegedly failed to apply the relevant patch. Reuters reported that the incident exposed personnel-related information for more than 5,000 FBI employees.
Authorities have not publicly released detailed charges or evidence concerning the Jordanian suspect. As with other cybercrime investigations, the alleged roles, victims and scope of the activity remain subject to ongoing law-enforcement review.
