Skip to content
Rota Nacional

Cyber ·

ShinyHunters extorted Boeing spin-off unit before arrests

A KrebsOnSecurity report links an extortion attempt against a spun-off Boeing business unit to the ShinyHunters group, the arrest of a suspect in Jordan, and exploitation of CVE-2026-35273 in PeopleSoft.

According to the KrebsOnSecurity report, carried in the feed as an automatic translation and dated October 7, 2026, a young man from Amman, Jordan, suspected of leading the ShinyHunters data theft and extortion group, was detained and, according to reports, is cooperating with the FBI to identify other members. The arrest happened while the group was trying to extort a recently spun-off Boeing business unit, Jeppesen ForeFlight, whose aircraft fleet is the same as that used by the airline employing the suspect's father. The report says the group exploited vulnerability CVE-2026-35273 in PeopleSoft, an Oracle software-as-a-service platform used for recruiting, human resources, benefits and payroll. Oracle published a fix, but the group began exploiting the flaw as a zero-day in June, and Mandiant published web application firewall rules for organizations unable to patch quickly. In recent weeks, according to the report, the group used a well-known URL encoding technique to bypass those rules. A September 25 report is cited, but the text received is truncated, so its details are not included.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free