As reported by Krebs on Security, the detention of a suspected ShinyHunters leader in Amman, Jordan — identified as Saif Al-din Khader, aka "Rey" — provides a rare window into the operational lifecycle of a modern data-theft extortion group. The timing is notable: Khader was reportedly cooperating with the FBI while ShinyHunters was actively extorting Jeppesen ForeFlight, a Boeing divested business unit. The arrest follows the September detention of alleged accomplice Pepijn van der Stap in the Netherlands, suggesting a coordinated multinational takedown.
What makes this case operationally significant for defenders is not the arrest itself but the attack chain it exposes. ShinyHunters' primary initial-access vector was CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft that the group began exploiting in June 2026. Oracle has since released a patch, and Mandiant published WAF rules as an interim mitigation. However, Krebs reports that ShinyHunters recently bypassed those WAF rules using a URL-encoding trick — a classic evasive technique that underscores the danger of relying on virtual patching as a long-term substitute for actual remediation.
Vulnerability Details
| Field | Details |
|---|---|
| CVE ID | CVE-2026-35273 |
| Severity | Critical (exact CVSS pending in NVD) |
| Affected Product | Oracle PeopleSoft (SaaS HR/payroll platform) |
| Vendor | Oracle Corporation |
| Patch Available | Yes — Oracle has released a fix |
| Active Exploitation | Yes — ShinyHunters exploited as zero-day since June 2026; WAF bypass observed |
| WAF Mitigation | Mandiant rules published but bypassed via URL-encoding |
Who Is at Risk
Any organization running unpatched Oracle PeopleSoft deployments is at elevated risk. This includes large enterprises, government agencies, and educational institutions that use PeopleSoft for HR, payroll, benefits administration, and hiring. ShinyHunters reportedly targeted the FBI's own PeopleSoft instance (unsuccessfully), demonstrating the group's ambition and the attractiveness of HR systems as data-rich targets. Organizations that delayed patching in favor of WAF rules are now fully exposed, as the bypass renders those rules ineffective.
The WAF bypass is the critical detail here. Virtual patching buys time — it does not close the vulnerability. ShinyHunters' URL-encoding evasion demonstrates that threat actors actively iterate against published mitigations. Any organization still relying on Mandiant's WAF rules instead of the Oracle patch should treat their environment as fully exposed.
Broader Implications
- HR systems as prime targets: PeopleSoft and similar platforms aggregate sensitive employee data — PII, SSNs, compensation, benefits — making them high-value for extortion. Defenders should treat HR/Payroll systems with the same criticality as financial systems.
- Extortion over encryption: ShinyHunters exemplifies the shift toward data-theft extortion without deploying ransomware. The data itself is the leverage, reducing operational complexity for attackers.
- Brand continuity after arrests: After Van der Stap's arrest, Rey assumed control of the ShinyHunters brand within days. Arrests disrupt but do not necessarily dismantle the operational capability — affiliate networks persist.
- Insider-adjacent targeting: The targeting of Jeppesen ForeFlight — whose parent Boeing manufactures aircraft for Royal Jordanian Airlines, Rey's father's employer — suggests threat actors leverage personal knowledge and connections to select targets.
Shield53 Recommendations
Immediate Actions
Strategic Actions
- Inventory all SaaS HR/payroll platforms and ensure they are included in vulnerability management SLAs with patching deadlines measured in days, not weeks, for critical-severity issues.
- Conduct tabletop exercises simulating data-theft extortion scenarios (no ransomware deployment) to test incident response readiness and communication protocols.
- Review third-party and divested business unit relationships for residual data exposure. Boeing's divestiture of Jeppesen ForeFlight did not eliminate the data risk — transition periods often create security gaps.