Wed 07 Oct 2026 / 23:00 ET
Kernel
Security 3 min read

ShinyHunters reportedly targeted former Boeing unit before Jordan detention

Boeing says it is reviewing threat-actor claims involving Jeppesen ForeFlight, which says its operations and products were unaffected.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

ShinyHunters reportedly targeted former Boeing unit before Jordan detention
img: Krebs on Security

ShinyHunters’ reported extortion of Jeppesen ForeFlight was under way when Jordanian authorities detained a suspect known online as “Rey,” according to KrebsOnSecurity. The reported target was a former Boeing navigation and digital-aviation business, not Boeing itself. The distinction matters because Boeing has acknowledged claims about data allegedly tied to the former unit, while Jeppesen ForeFlight says it has found no impact to its operations or products.

Reuters reported on October 3, citing three unnamed sources, that authorities in Amman detained Saif Al-din Khader, a suspected ShinyHunters member, and that he was cooperating with the FBI. KrebsOnSecurity previously identified Khader as Rey. No supplied law-enforcement statement confirms the Jordanian detention or cooperation arrangement.

Two unnamed sources familiar with the investigation told KrebsOnSecurity that ShinyHunters was trying to extort Jeppesen ForeFlight when Rey was detained. Those sources also said the allegedly taken information could present operational safety and security risks. That assessment, the scope of any data taken, and Rey’s alleged part in the activity have not been publicly established through criminal findings.

What did Boeing and Jeppesen ForeFlight say about the ShinyHunters claims?

Boeing said it was aware of a threat actor’s claims involving data allegedly associated with Boeing and Jeppesen ForeFlight, and that it was reviewing the matter with the Jeppesen ForeFlight team. The company did not confirm a breach, identify the data involved, or say that any extortion demand was paid.

Jeppesen ForeFlight said that, based on its investigation to date and its security posture, it had found no impact to its operations or products. That is a narrower statement than a finding that no data was accessed or that the claim lacks merit.

Boeing sold Jeppesen ForeFlight to private-equity firm Thoma Bravo in November 2025 for $10.55 billion, according to KrebsOnSecurity. The sale means the business was no longer a Boeing subsidiary at the time of the reported extortion attempt.

How does the PeopleSoft campaign fit in?

The report arrives amid a wider ShinyHunters campaign against Oracle PeopleSoft systems. Mandiant and Google Threat Intelligence Group said in September that the group, tracked by them as UNC6240, had mass-exploited CVE-2026-35273 and placed web shells on dozens of systems in sectors including transportation, government, healthcare and technology.

The researchers said attackers evaded some web application firewall rules by URL-encoding a character in the PeopleSoft path. A filter looking only for the literal /PSEMHUB/ path could miss a request using /%50SEMHUB/, while the application server decodes it and routes it to the vulnerable component. Mandiant said applying Oracle’s patch, rather than relying on path filtering, is the needed remedy.

Neither Mandiant nor Google Threat Intelligence Group identified Jeppesen ForeFlight as a victim in that reporting, so the available evidence does not establish that this flaw was used in the reported extortion.

The FBI separately announced on September 29 that Dutch police had arrested an alleged ShinyHunters leader. The agency alleged that the group and co-conspirators had breached more than 140 organizations and collected at least $70 million in extortion payments since the prior year. That announcement concerned the Dutch case, not the later reported detention in Jordan.

This story draws on original reporting from Krebs on Security.

More Security/

view all ↗