ShinyHunters Extorted Boeing Spin-Off Prior to Arrests
63 points by speckx 8 hours ago | 15 comments

socketcluster 20 minutes ago
I was never interested in hacking but as a software engineer with 15 years of experience, I frequently encounter tricky situations in the code where I think to myself that it would present a perfect hacking opportunity and probably present in a large percentage of software.

Last time I tried my hand at whitehat hacking on HackerOne, it took me 30 minutes to find a major system crash/DoS vulnerability in a major platform. The company acknowledged that the issue was real but denied me the bounty payment because they said I would have to 'prove' that it leads to catastrophic failure. I had already done so in the sense that you could reliably infer it from the data I had provided, but it seemed like they were baiting me into committing a felony (DoS attack) to prove my point, which I wasn't prepared to do but I'm sure I could have done cheaply. So yeah, whitehat hacking seems to be a waste of time. Most software today is incredibly insecure.

reply
SoftTalker 4 hours ago
A Jordanian teen is behind ShinyHunters? I don't know if this is impressive or just a sad commentary on the state of security at the organizations they ransomed.
reply
whizzter 4 hours ago
Never underestimate the amount of free time a teenager has (both in doing things and teaching themselves), most might not be up to adult levels but many capable ones are far more capable than many adults doing their jobs.

I was offered my first outside job after the second year of highschool, I kinda accidentally interviewed for a at the time respected gamedev firm (since I was looking for a summerjob heh) and when we started talking about when to start and I mentioned my school semesters the interviewer realized that I was younger than he had assumed.

reply
ChrisMarshallNY 3 hours ago
I seem to remember something similar, with Fluffi Bunni, a notoriously good *NIX hacker group.

I think it turned out to be mostly one guy, but he wasn't a teenager, anymore, when they finally got him[0]. I know that after that arrest, the group disappeared.

I think that some of the kids they are nailing for ShinyHunters actually ordered hits.

Maybe publicly going after the FBI wasn't such a bright move... They could have kept it quiet, and made millions, selling to bad guys.

[0] https://www.csoonline.com/article/510783/data-protection-flu...

reply
ourmandave 3 hours ago
The original group behind ShinyHunters went to prison and Rey took it over.

They're trolling him saying he's not nearly as good and tarnishing the ShinyHunters rep.

I have no idea what's true, but they can all go to hell.

reply
vablings 3 hours ago
I would be inclined to doubt it based on the history of the group. Its more likely he is just a fall guy
reply
ShinyLeftPad 3 hours ago
yeah otherwise why would their rules forbid targeting PRC/DPRK/Russia/Belarus companies but not Jordan...
reply
orbital-decay 4 hours ago
Hard-to-reach targets probably become a lot easier to reach when you have years' worth of stolen credentials and private data.
reply
ocdtrekkie 4 hours ago
I think more modern security is an "emperor has no clothes" situation than people think. The LLMs are gonna have a field day.
reply
baby_souffle 4 hours ago
> I think more modern security is an "emperor has no clothes" situation than people think.

Outside of a few cases, it's always been a box checking exercise. If you're fortunate, the boxes are kept up to date / written by somebody that knows what they're doing. If you're like most, the box hasn't changed since the 90s when "complex passwords, changed quarterly" was in vogue.

reply
whizzter 4 hours ago
Companies always prioritize features/capabilities up until shit starts hitting the fan, but even then the culture and requirements makes everything just a job of trying to patch a sinking ship if you're lucky.
reply
mmooss 3 hours ago
I wouldn't leap to the conclusion that they have the right people; I would wait for evidence. They seem to have found them with incredible speed - how often has an attack been resolved this quickly? It would not be the first time the wrong person was arrested (and smeared) in a high pressure situation.

They need a head on a pike to save face for the FBI, both in front of the public and for internal credibility in government, law enforcement, and within their own origanization. Imagine how the FBI would look if they couldn't find or apprehend the perpetrators. And the current FBI - the leadership and their superiors, at least - seems much more focused on politics than predecessors.

reply
trhway 4 hours ago
interesting "rules of engagement" they have, including "no PRC companies"! :

https://krebsonsecurity.com/wp-content/uploads/2025/11/slsh-...

(from https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-sc... linked in the original post)

reply
JumpCrisscross 3 hours ago
> including "no PRC companies"

It could be practical.

Van der Stap “was sentenced to four years in prison (one suspended) and a three-year probationary period” in 2023, released from prison “in the beginning of 2026,” and then promptly charged “with attempted incitement of two murders” which will presumably put him in jail for a couple more years [1].

China wouldn’t be so lenient.

[1] https://en.wikipedia.org/wiki/Pepijn_van_der_Stap

reply
Computer0 4 hours ago
I support shinyhunters in all their endeavors.
reply