Oracle PeopleSoft zero-day linked to ShinyHunters arrests

Jordanian authorities have detained alleged ShinyHunters member Saif al-Din Khader, believed to use the handle “Rey,” in a case that now spans mass exploitation of an Oracle PeopleSoft zero-day, an FBI recruitment data breach, and an attempted extortion of a former Boeing aviation unit.[1][4][13]

According to multiple reports, Khader was taken into custody in Amman at the end of September and is cooperating with the FBI to identify other members of the extortion-focused hacking group that claims to have stolen data on every FBI employee.[1][4][12][13] KrebsOnSecurity previously profiled “Rey” as a prolific young hacker tied to several ransomware operations and noted that he seized control of the ShinyHunters brand following the mid-September arrest of Dutch cybercriminal Pepijn van der Stap, boasting online about data thefts from the FBI and taunting both law enforcement and the Cl0p ransomware group. Those same reports linked Rey’s activities to an ongoing extortion attempt against Jeppesen ForeFlight, a digital aviation and navigation business Boeing sold to private equity firm Thoma Bravo in late 2025, raising questions about potential operational risk to an aviation provider closely aligned with the airline where Rey’s father is believed to work.

At the center of the technical fallout is CVE-2026-35273, a critical Oracle PeopleSoft vulnerability that security researchers say ShinyHunters weaponized at scale.[3][10] Mandiant and Google’s Threat Intelligence Group (GTIG), which track the actor as UNC6240, describe the bug as an unauthenticated Java deserialization remote code execution flaw in PeopleSoft’s Environment Management Hub (the PSEMHUB endpoint), with a CVSS score of 9.8 and inclusion in CISA’s Known Exploited Vulnerabilities catalog.[3][5][10] Oracle issued a patch for CVE-2026-35273 in June, but UNC6240 initially abused it as a zero-day and then resumed mass exploitation in September by bypassing common web application firewall rules that were deployed as a stopgap by organizations unable to patch quickly.[3][5][8][9] Instead of requesting the blocked path /PSEMHUB/, the group sent traffic to /%50SEMHUB/—percent-encoding the leading “P”—a one-character trick that evaded WAF filters that match literal paths before URL decoding while still reaching the vulnerable servlet.[3][5][8][10] Investigators say the campaign has planted web shells and tunneling tools across dozens of victims in higher education, technology, IT services, healthcare, agriculture, transportation and government.[3][5][7][9][10]

The FBI itself is among the most sensitive victims. ShinyHunters has claimed responsibility for breaching an FBI recruitment portal, and Reuters reporting indicates the incident exposed data on thousands of bureau personnel, including unit affiliations and specialized roles.[1] The cache reportedly included medical and psychiatric records, raising the stakes for both potential blackmail and long-term privacy harms. A subsequent Reuters dispatch said the FBI cut ties with a contractor over failures to patch the vulnerable PeopleSoft system, underscoring how basic software maintenance gaps can cascade into strategic national security issues. While the bureau has not publicly detailed technical indicators, the timing and tooling described by Mandiant and GTIG strongly suggest the recruitment site compromise is another branch of the CVE-2026-35273 exploitation wave.

Sources cited by KrebsOnSecurity say that as US law enforcement ramped up its investigation into ShinyHunters, the group was in the process of extorting Jeppesen ForeFlight over stolen data when Rey was detained. Boeing confirmed in a brief statement that a threat actor was making claims about data allegedly associated with the company and its former subsidiary and said it was working with Jeppesen ForeFlight to review the matter. Jeppesen ForeFlight, for its part, said its own investigation and “proactive security posture” showed no impact to operations or products, but did not dispute that data tied to the business was being used as leverage. That alleged overlap between Rey’s extortion campaign and the airline ecosystem his father is linked to has heightened scrutiny of potential insider insights or targeting decisions driven by familiarity with aviation infrastructure rather than random selection.

The saga also reaches into the Netherlands, where police arrested 24-year-old Pepijn van der Stap—known in earlier cases for data theft and extortion that netted an estimated €1.5–€2.7 million—on suspicion of aiding ShinyHunters.[11] Dutch media reports and a Reuters story say investigators are now probing explosive allegations that van der Stap attempted to orchestrate at least two murders abroad, allegedly ordering the attacks while presenting himself publicly as a reformed hacker working as “offensive security lead” at Amsterdam-based cybersecurity firm Neo Security.[11] Neo Security’s owner told Reuters that the company brought in an outside firm to check whether van der Stap had abused his position to hack the company or its clients and said no such evidence has been found so far.[11] Together with Khader’s detention in Jordan, the Dutch arrest and new murder-for-hire angle illustrate how the ShinyHunters investigation has evolved from a series of high-profile data breaches and extortion schemes into a sprawling international criminal case with overlapping cyber, physical and aviation-security dimensions.

References

  1. ShinyHunters hacker in FBI data theft detained in Jordan …
  2. Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, CISA KEV)
  3. Exclusive-ShinyHunters hacker in FBI data theft detained …
  4. September | 2026 | Scott Harvanek
  5. FortiMail Path-Traversal Zero-Day, Zammad Zero-Days Hit KEV, and Critical Fortra BoKS Auth Bypass
  6. The WAF rule blocked one spelling of the path. ShinyHunters …
  7. InfoSec / Cyber Security | Scott Harvanek
  8. Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft …
  9. ShinyHunters suspect also investigated for alleged murder orders, Dutch media report
  10. www.straitstimes.com › world › united-statesShinyHunters hacker detained in Jordan cooperating with FBI …
  11. ShinyHunters Hacker Helping FBI

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply