ShinyHunters Leader Detained; Boeing Spin-off Unit Targeted Prior to Arrest
Teenager from Amman arrested in connection with extortion of aerospace spinoff; FBI cooperation reported

Key Takeaways
- ShinyHunters suspected leader Rey detained in Amman, Jordan.
- Arrest occurred during active extortion of a Boeing spin-off business unit.
- Rey is reportedly cooperating with the FBI to identify other gang members.
- The divested Boeing unit manufactures components for aircraft used by Royal Jordanian Airlines.
- No software patch applicable; incident resolved through law enforcement action.
Quick answers
- What happened?
- A teenager identified as Rey, suspected of leading the ShinyHunters extortion group, was detained in Amman, Jordan. According to KrebsOnSecurity, the arrest occurred as ShinyHunters was actively extorting a business unit recently spun off by Boeing. The suspect is reportedly cooperating with the FBI to identify other gang members. The divested business unit manufactures components for aircraft operated by Royal Jordanian Airlines, the employer of Rey's father.
- What should defenders do?
- Organizations should monitor law enforcement advisories regarding ShinyHunters activity. Implement standard data protection controls to mitigate extortion risk, including access controls, encryption, and incident response planning. Review third-party and spun-off business unit security postures following divestiture.
KrebsOnSecurity reports that a teenager from Amman, Jordan, suspected of leading the prolific data theft and extortion group ShinyHunters, has been detained and is cooperating with the FBI. The arrest, said to have taken place on October 7, 2026, occurred while the suspect group was in the process of extorting a business unit recently divested by the global aerospace company Boeing. The spun-off business unit is involved in manufacturing components for the fleet of planes used by Royal Jordanian Airlines, the employer of the suspect's father. The cooperation with the FBI is said to be aimed at identifying other members of the ShinyHunters gang. The timing of the arrest, coinciding with active extortion attempts against the Boeing spinoff, marks a significant development in the disruption of the group's operations. The specific method of data theft or initial access used by ShinyHunters against the target has not been detailed in the report. No software vulnerabilities or patches are relevant, as the incident pertains to law enforcement action and extortion rather than a technical exploit of software.
Security Details
Law enforcement detention of suspected ShinyHunters leader Rey in Amman, Jordan. Active extortion of a Boeing spin-off business unit was in progress at the time of arrest. The suspect's cooperation with the FBI is ongoing. The divested business unit is linked to Royal Jordanian Airlines via the suspect's father's employment. No software vulnerability or CVE associated; incident involves criminal extortion and data theft.
Mitigation
Organizations should monitor law enforcement advisories regarding ShinyHunters activity. Implement standard data protection controls to mitigate extortion risk, including access controls, encryption, and incident response planning. Review third-party and spun-off business unit security postures following divestiture.
Sources
Krebs on Security
ShinyHunters Extorted Boeing Spin-off Prior to Arrests
Oct 7, 2026 · 13:48
Original link
Related Security News

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
A multinational cybersecurity advisory issued on October 8, 2026, warns that Chinese government-linked threat actors, enabled by the China-based Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide. Activity spans US critical infrastructure sectors, government networks, and victims across Southeast Asia, Africa, and North America. Exploitation methods include scanning tools, cross-site scripting attacks, password spraying on Microsoft Exchange servers, and persistence via VPN software. The advisory provides indicators of compromise and mitigation guidance for network defenders.




