ThreatPaper
Extortion & BlackmailData BreachHigh

Jeppesen ForeFlight extortion: ShinyHunters hits Boeing-divested aviation unit as FBI arrests mount

By Sethu Satheesh · 9 Oct 2026 · 15 min read

Source: krebsonsecurity.com

Threat Actor: ShinyHunters · Target: Jeppesen ForeFlight (aviation navigation; divested by Boeing to Thoma Bravo)


Executive Summary

The data-theft extortion collective tracked as ShinyHunters attempted to extort Jeppesen ForeFlight, the aviation navigation and flight-planning business that Boeing divested to private-equity firm Thoma Bravo for $10.55 billion in November 2025. KrebsOnSecurity first reported the extortion on October 7, 2026. Boeing acknowledged the matter, stating that it was "aware of claims by a threat actor regarding data allegedly associated with Boeing" and that it was "actively reviewing the matter with the Jeppesen ForeFlight team." Jeppesen ForeFlight said there "was no impact to our operations or products."1

The episode is significant for two reasons that sit in tension. ForeFlight's charts, navigation data and flight-planning tools are used widely in general and business aviation, and two sources cited by KrebsOnSecurity said the stolen data could pose operational safety and security risks — a characterisation that directly conflicts with the company's own "no impact" statement.1 At the same time, the extortion unfolded against the backdrop of a fast-moving law-enforcement operation: a figure who uses the self-chosen handle "Rey" — a ShinyHunters-linked actor — was reportedly detained in Jordan in late September 2026 and is said to be cooperating with the U.S. Federal Bureau of Investigation (FBI) to identify other members.12

The detention and cooperation are reported by Reuters on the basis of three unnamed people familiar with the matter; the FBI declined to comment on any specific arrest or activity abroad.2 They are therefore recorded here as reported-by-sources, not as confirmed fact. What the FBI has confirmed on the record is broader: that it "continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters," having "already worked with partners to arrest multiple subjects."2 The FBI has not publicly named "Rey" or confirmed his arrest.

This paper takes the better-sourced Jeppesen ForeFlight extortion — acknowledged by Boeing and addressed by the target itself — as its spine, and treats the arrests as the developing story around it. ShinyHunters is an intelligence-tracked collective (Google tracks the operators of its recent Oracle PeopleSoft campaign as UNC6240), not a single charged individual; "Rey" appears within the actor profile only as a self-identified, detained-but-uncharged member, referred to by handle alone because the one journalistic identification of him names an uncharged person.13

Weekly Digest

Get the next investigation in your inbox

New research, once a week. No vendor pitches.

Verification of Claims

  1. Claim: ShinyHunters extorted Jeppesen ForeFlight, a business Boeing divested to Thoma Bravo. → Verified → KrebsOnSecurity reported the extortion and obtained statements from both Boeing ("aware of claims by a threat actor regarding data allegedly associated with Boeing"; "actively reviewing the matter with the Jeppesen ForeFlight team") and Jeppesen ForeFlight ("no impact to our operations or products"). The $10.55 billion November 2025 divestiture to Thoma Bravo is documented in the same report and corroborated by aviation trade press.1

  2. Claim: The stolen data could pose operational safety and security risks. → Partially verified → Two sources cited by KrebsOnSecurity made this assessment. It conflicts with Jeppesen ForeFlight's own statement that there was "no impact to our operations or products." No independent technical analysis of the data has been published, and ThreatPaper has not seen the data. The assessment is reportable; it is not established, and the first-party statement points the other way.1

  3. Claim: A ShinyHunters figure known as "Rey" was detained in Jordan and is cooperating with the FBI. → Partially verified → Reuters reported this on October 3, 2026, citing three people familiar with the matter, two of whom said he was taken into custody on a Tuesday (reported elsewhere as September 29, 2026) and was "walking investigators through his electronic devices and digital correspondence." The FBI declined to comment on any specific arrest or activity abroad, and Reuters could not determine the circumstances of the detention or where he is held.2

  4. Claim: The FBI has confirmed the arrest of "Rey." → Unverified → The FBI confirmed only that it had "already worked with partners to arrest multiple subjects" and continues to investigate; it declined to comment on any specific arrest or activity abroad and has not publicly named "Rey." The sole on-record arrest the bureau's statements and the reporting attach a name to is a separate September 15, 2026 Dutch arrest. "Rey"'s detention rests entirely on anonymous sourcing.12

  5. Claim: ShinyHunters and its co-conspirators breached 140+ organisations and took $70M+ in extortion payments. → Partially verified → These are the FBI's own figures, attributed by multiple outlets to the bureau and to its cyber division. They describe alleged, unadjudicated conduct across the group's wider activity since 2025, not the Jeppesen ForeFlight incident specifically, and no breakdown of how the counts were derived has been published.24

Timeline

Date Actor Event Source
November 2025 Boeing / Thoma Bravo Boeing completes divestiture of Jeppesen ForeFlight to Thoma Bravo for $10.55 billion 1
November 2025 KrebsOnSecurity Publishes profile identifying the actor behind the handle "Rey" 1
May 27 – June 9, 2026 ShinyHunters (UNC6240) Exploits Oracle PeopleSoft flaw CVE-2026-35273 as a zero-day, predominantly against universities 3
June 10, 2026 Oracle Releases out-of-band Security Alert for CVE-2026-35273 3
September 15, 2026 Dutch police Arrest a 24-year-old man in the ShinyHunters investigation 14
September 22, 2026 ShinyHunters Claims via "Rey" to have breached FBI infrastructure through a PeopleSoft server 13
September 25, 2026 Google Threat Intelligence Group / Mandiant Publishes report on renewed PeopleSoft mass-exploitation campaign and WAF-bypass trick 3
September 29, 2026 FBI (Brett Leatherman) Calls on remaining ShinyHunters members to come forward 4
~September 29, 2026 Jordanian authorities Reportedly detain "Rey" in Jordan (per Reuters' sources) 2
September 30, 2026 ShinyHunters Group's darknet leak site goes offline after an FBI deadline expires 1
October 3, 2026 Reuters Reports "Rey"'s detention and cooperation with the FBI, citing three unnamed sources 2
October 7, 2026 KrebsOnSecurity Reports the Jeppesen ForeFlight extortion; Boeing and Jeppesen ForeFlight issue statements 1

Attack Anatomy

The specific intrusion vector into the data "allegedly associated with Boeing" was not disclosed by Boeing, Jeppesen ForeFlight, or KrebsOnSecurity, and is marked unknown below. What is documented is ShinyHunters' mode of operation across its 2025–2026 activity, which runs on two parallel tracks — social-engineering of SaaS platforms and mass exploitation of an enterprise application flaw — both ending in data-theft extortion rather than file encryption.13

Initial access — unknown for this victim; two documented group vectors

For the Jeppesen ForeFlight data itself, no access vector has been published.1 Across the wider campaign, ShinyHunters is associated with two methods. The first is voice-phishing (vishing) of enterprise staff to obtain credentials and OAuth access to cloud CRM platforms such as Salesforce, from which bulk records are pulled (T1566.004, T1078).1 The second, documented in detail by Google's Mandiant, is exploitation of the public-facing Oracle PeopleSoft Environment Management Hub via CVE-2026-35273, reached at the endpoint POST /%50SEMHUB/hub (T1190).3

Web application firewall bypass

Where defenders had blocked the vulnerable PeopleSoft endpoint with web-application-firewall (WAF) rules instead of patching, the operators bypassed them with a single URL-encoded character: requesting /%50SEMHUB/ in place of /PSEMHUB/, where %50 is the percent-encoded form of P. WAF and proxy rules that match the literal path before decoding do not fire, while Oracle WebLogic decodes the request and routes it to the vulnerable servlet (T1190).3

Installation and persistence

Mandiant observed JSP web shells deployed inside PSEMHUB.war: x.jsp, the primary cross-platform command shell (accepting hex-encoded commands via a c POST parameter), and u.jsp/u2.jsp, a chunked Base64 upload stager (T1505.003). Some operations ran commands without writing a web shell to disk, so file-based hunting alone can miss the activity. On Windows, the actors dropped a backdoor Mandiant tracks as SIDEEYE, delivered as Ple64.exe — a 5.2 MB trojanised installer masquerading as the Light Alloy media player and signed with a valid Extended Validation certificate issued to "Tobias Weihmann Software Development OU" via Sectigo, which GTIG asked Sectigo to revoke (T1553.002). On Linux, the legitimate remote-management tool MeshAgent was installed for persistence (T1219).3

Command, control and lateral movement

SIDEEYE communicates with 162[.]219[.]30[.]165 over raw TCP, using control port 3333 and data port 3334, and can steal browser and desktop credentials, manage files and processes, and open an interactive reverse shell and reverse proxy (T1555.003). The open-source Neo-reGeorg toolkit was deployed as tunnel.jsp/tunnel.jspx to route SOCKS5 traffic over ordinary HTTP/HTTPS, enabling internal discovery and lateral movement (T1572).3

Actions on objectives — exfiltration and extortion

The objective throughout is bulk data theft followed by extortion: the group stages a darknet leak site and threatens publication unless paid, with affiliates reportedly supplying stolen SaaS credentials in exchange for a cut of any ransom (T1657). ShinyHunters' leak site went offline on September 30, 2026 after an FBI deadline expired. In the Jeppesen ForeFlight case, the extortion attempt is confirmed by Boeing's acknowledgement; whether any data was published, and whether any payment was demanded or made, has not been disclosed.1

Loading diagram...

Threat Actor Profile

Name: ShinyHunters Aliases: Tracked by Google/Mandiant as UNC6240 for the Oracle PeopleSoft campaign; frequently associated in reporting with the "Scattered LAPSUS$ Hunters" umbrella (a blend of Scattered Spider, LAPSUS$ and ShinyHunters) Attribution confidence: The Jeppesen ForeFlight extortion is attributed to ShinyHunters by KrebsOnSecurity's reporting and by Boeing's acknowledgement of a threat-actor claim; the PeopleSoft campaign is attributed to ShinyHunters (UNC6240) by Google's Mandiant on the basis of its own incident response13 Motivation: Financial — data-theft extortion

ShinyHunters has operated since around April–May 2020 and is best understood today as a brand and business model rather than a fixed roster: researchers cited in reporting have described it as "less a group than a brand and business model that has outlived its founders," with lineage traced by Sekoia and Beazley Security back to actors such as TheDarkOverlord and GnosticPlayers. Current operators are reportedly not the original, largely French core members, several of whom were previously arrested. The operation runs as a franchise, with affiliates feeding stolen SaaS credentials to the brand for a share of extortion proceeds.14

The individual using the handle "Rey" is described as a key member who previously administered the Hellcat ransomware data-leak site and took over the BreachForums cybercrime forum in 2024, and who claimed responsibility for ShinyHunters' September 2026 breach of an FBI recruitment portal built on PeopleSoft.1 KrebsOnSecurity identified "Rey" as a specific named individual in a November 2025 profile. Because that person has not been charged with any offence, this paper does not reproduce the legal name and refers to him only by the self-chosen handle; a journalist's identification of an uncharged person is not a basis on which ThreatPaper publishes a name. "Rey" is reported to have been detained in Jordan and to be cooperating with investigators, but has not been charged or publicly named by the FBI as of October 10, 2026.2

MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):

ID Technique
T1566.004 Phishing: Spearphishing Voice
T1078 Valid Accounts
T1190 Exploit Public-Facing Application
T1505.003 Server Software Component: Web Shell
T1553.002 Subvert Trust Controls: Code Signing
T1219 Remote Access Tools
T1555.003 Credentials from Password Stores: Credentials from Web Browsers
T1572 Protocol Tunneling
T1657 Financial Theft

OPSEC: The group runs public-facing darknet leak sites and negotiates openly, and its members have maintained visible personas on Telegram, GitHub and cybercrime forums — a high-profile posture that is itself a tracking surface. Where its OPSEC appears to have broken down is the human layer: the reported cooperation of a detained member, said to be walking investigators through his own devices and correspondence, and the reuse of persistent handles across Hellcat, BreachForums and public taunts aimed at the FBI.12

Technical Indicators

note: >
  The indicators below are from Google/Mandiant's September 25, 2026 report on
  the ShinyHunters (UNC6240) Oracle PeopleSoft campaign, which is the group's
  documented mode of operation. No indicators specific to the Jeppesen ForeFlight
  extortion were disclosed by Boeing, Jeppesen ForeFlight, or KrebsOnSecurity.
cve:
  - CVE-2026-35273  # Oracle PeopleSoft Environment Management Hub RCE, zero-day
exploited_endpoint:
  - 'POST /%50SEMHUB/hub'   # %50 = URL-encoded "P", used to bypass WAF path rules
web_shells:
  - x.jsp      # sha256 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494
  - u.jsp      # sha256 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7
  - u2.jsp
  - tunnel.jsp
  - tunnel.jspx            # Neo-reGeorg SOCKS5-over-HTTP tunneling
backdoor_sideeye:
  file: Ple64.exe          # trojanised "Light Alloy" installer, 5.2 MB
  sha256: 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3
  signing: EV certificate "Tobias Weihmann Software Development OU" via Sectigo (revocation requested)
  c2: 162.219.30[.]165     # raw TCP; control 3333/tcp, data 3334/tcp
meshagent_infrastructure:
  - azurenetfiles[.]net
  - microsoft-entra[.]net
  - enroll.azuredevice[.]cloud
  - winmanage-me[.]network   # on 104.219.234[.]138 (September 2026 intrusions)

The FBI has confirmed an active investigation into ShinyHunters and stated that it had "already worked with partners to arrest multiple subjects," adding "we will spare no resource in bringing each of the responsible individuals to justice." On September 29, 2026 the FBI's cyber division assistant director, Brett Leatherman, publicly urged remaining members to come forward ("I suggest you reach out first while the choice is still yours"), and FBI Director Kash Patel posted that "More arrests are on the table."24

On the record, the only named arrest in the investigation is a 24-year-old detained by Dutch police on September 15, 2026. The reported detention of "Rey" in Jordan and his cooperation with the FBI come solely from three unnamed sources cited by Reuters; the FBI declined to comment on any specific arrest or activity abroad, and no charges against "Rey" have been made public.12 Oracle issued an out-of-band Security Alert for CVE-2026-35273 on June 10, 2026 in response to the wider PeopleSoft campaign.3 As of October 10, 2026, no securities disclosure, data-breach regulatory notification, or lawsuit specific to the Jeppesen ForeFlight extortion had been published by Boeing, Thoma Bravo, or Jeppesen ForeFlight.1

Impact Assessment

  • Confirmed: ShinyHunters attempted to extort Jeppesen ForeFlight; Boeing acknowledged being "aware of claims by a threat actor regarding data allegedly associated with Boeing" and was "actively reviewing the matter with the Jeppesen ForeFlight team."1
  • Confirmed (first-party): Jeppesen ForeFlight stated there "was no impact to our operations or products."1
  • Reported, not independently confirmed: Two sources cited by KrebsOnSecurity said the stolen data could pose operational safety and security risks — a characterisation that conflicts with the company's "no impact" statement.1
  • Reported, not independently confirmed: "Rey" was detained in Jordan around September 29, 2026 and is cooperating with the FBI (Reuters, three unnamed sources).2
  • Reported (wider campaign, FBI allegation): ShinyHunters and co-conspirators allegedly breached more than 140 organisations and took at least $70 million in extortion payments since 2025.24
  • Unknown: What data was taken from the Boeing-associated systems, its sensitivity, whether it was published, and whether any ransom was demanded or paid.

Lessons and Defensive Recommendations

For SOC/defenders:

  • Hunt PeopleSoft logs for both literal and URL-encoded requests to the Environment Management Hub (/PSEMHUB/ and /%50SEMHUB/), and inspect PSEMHUB.war and PeopleSoft directories for unexpected JSP files such as x.jsp, u.jsp and tunnel.jsp.3
  • Alert on the SIDEEYE C2 (162[.]219[.]30[.]165, ports 3333/3334), MeshAgent artefacts in /tmp (meshagent, meshagent.msh, meshagent.db), and the listed look-alike domains.3

For developers / platform teams:

  • Treat WAF path rules as a stopgap, never a substitute for patching: a single percent-encoded character defeated them. Normalise and decode request paths before matching, and apply Oracle's CVE-2026-35273 update rather than relying on endpoint blocks.3

For platform/cloud teams:

  • Harden SaaS CRM tenants (Salesforce and similar) against vishing-driven OAuth abuse: enforce phishing-resistant MFA, restrict connected-app authorisation, and monitor for bulk record exports — the social-engineering half of ShinyHunters' model does not touch a CVE.1

For leadership:

  • Acquisition and divestiture change who owns the breach, not whether the data is exposed: data "associated with Boeing" surfaced after the business moved to new ownership. Diligence and incident-response ownership should survive a sale.1
  • Where a product bears on physical safety, reconcile a "no impact to operations" statement with an independent assessment of what the stolen data could enable before treating the matter as closed.1

Sources

Footnotes

  1. KrebsOnSecurity — ShinyHunters Extorted Boeing Spin-off Prior to Arrests — October 7, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29

  2. Reuters (via The Star) — Exclusive: ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say — October 3, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14

  3. Google Cloud / Mandiant (GTIG) — ShinyHunters renewed mass exploitation campaign targeting Oracle PeopleSoft — September 25, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15

  4. The Hacker News — ShinyHunters Suspect 'Rey' Reportedly Detained in Jordan, Cooperating With FBI — October 4, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6

Topics: #shinyhunters#jeppesen-foreflight#boeing#thoma-bravo#data-extortion#oracle-peoplesoft#cve-2026-35273#fbi
Original Incident Report →

Related Research

Dutch police arrested a 24-year-old Amsterdam man on Sept 15, 2026 in the ShinyHunters investigation; a Rotterdam court remanded him 90 days, and the FBI called him an 'alleged leader.' A separate inquiry into two planned murders abroad is, police say, not part of the ShinyHunters case.

Data BreachExtortion & Blackmail

ShinyHunters claims it breached the FBI, defaced FBIjobs.gov, and stole ~2TB on almost all agents via a PeopleSoft zero-day. The defacement is observed and 404 Media matched a data sample to public records — but the FBI says the breach point is undetermined and most is unverified.

Data BreachExtortion & Blackmail

GTIG tracked UNC6240 (linked to ShinyHunters) mass-exploiting PeopleSoft's CVE-2026-35273 (CVSS 9.8 unauth RCE). Defenders who blocked /PSEMHUB at a WAF instead of patching were bypassed: the actor requested /%50SEMHUB/, one URL-encoded character, then dropped web shells and the SIDEEYE backdoor.

Data BreachMalwareExtortion & Blackmail