A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey’s father — Royal Jordanian Airlines.

The logo for Jeppesen ForeFlight, a business unit divested last year by the aerospace firm Boeing.
On October 3, Reuters cited three unnamed sources saying a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity identified Rey as Khader in a November 2025 profile, in which the young man admitted working with multiple ransomware groups.
Rey was featured again in a September 28 exclusive about the Dutch police arresting 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding in data thefts and extortions by ShinyHunters. The story noted that immediately following the Dutchman’s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the FBI and extorting the ransomware group Cl0p.
Rey taunted both the FBI and Cl0p with memes posted to his longtime account on Twitter/X, while simultaneously including images of the avatar used by Van Der Stap’s former hacker alias “Umbreon” in an apparent attempt to frame the Dutchman for both hacks.

A taunting meme uploaded to Twitter/X by Rey on Sept. 22. A giant sized version of the Pokemon character Umbreon can be seen in the bottom left.
As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in PeopleSoft, a software-as-a-service platform from the tech giant Oracle that is broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle quickly issued a fix for CVE-2026-35273, which ShinyHunters first began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations that couldn’t apply the security update quickly enough.
ShinyHunters told BleepingComputer in June that the original goal behind exploiting the PeopleSoft vulnerability was to breach the FBI’s own PeopleSoft database, but the hackers said those attacks were unsuccessful for some reason. In recent weeks, however, ShinyHunters turned to a well-known URL-encoding trick to bypass Mandiant’s suggested web application firewall rules.
In a report released Sept. 25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government.
Reuters reported October 5 that the FBI has removed a contractor at Accenture over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel, including each’s person’s unit and specialization, as well as medical and psychiatric records.
According to two sources familiar with the ShinyHunters investigation, a navigation and digital aviation unit recently divested by the global aerospace company Boeing was among the victims that ShinyHunters was in the process of extorting when Rey was apprehended by Jordanian authorities.
Those sources said the FBI’s investigation into ShinyHunters gained renewed urgency with the group’s attempted extortion of the former Boeing unit, which allegedly included the theft of sensitive information that sources said could pose operational safety and security risks.
In a brief statement shared with KrebsOnSecurity, Boeing acknowledged the extortion attempts by ShinyHunters, and said the incident concerned data stolen from Jeppesen ForeFlight, a subsidiary that Boeing sold in November 2025 to the private equity firm Thoma Bravo for $10.55 billion.
“We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight,” a Boeing spokesperson shared. “We are actively reviewing the matter with the Jeppesen ForeFlight team.”
A spokesperson for Jeppesen ForeFlight shared a written statement in response to questions, saying the company has seen no impact on their end. “Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.”
Rey’s alleged involvement in attempting to extort the former Boeing unit is noteworthy because there is strong evidence that his father works for Royal Jordanian Airlines, which is mostly controlled by the Jordanian government and operates its long-haul fleet on passenger planes built by Boeing. Rey claimed on Telegram in early 2025 that his father was an airline pilot, although that could not be independently confirmed.
However, as noted in our November 2025 profile of Rey, his family’s shared computer was at one point compromised by password-stealing malware, and the data collected by that malware clearly shows Rey’s father used the same credentials to log in at multiple online portals for Royal Jordanian Airlines employees.
Royal Jordanian Airlines has not yet responded to a request for comment. In advance of our September 28 story, KrebsOnSecurity once again emailed Rey’s father to seek comment and update him on his son’s alleged activities. Neither of the Khaders have responded. But just hours after that request was sent, Rey began deleting his various social media accounts, including the Twitter/X account he previously used to taunt the FBI, Cl0p, and other ShinyHunters victims.
Rey may have nixed many of his social media profiles, but his cybersecurity blog on GitHub somehow escaped the purge, and it shows that Rey was fixated on the leaders of the Cl0p ransomware group. In March 2026, Rey’s blog featured a lengthy post that identified two Russian men as the core developers and hackers behind Cl0p.

Rey’s blog on GitHub. This post doxes two Russian men as the core operators behind Cl0p, one of the oldest and most established ransomware groups still in operation today.
Meanwhile, news outlets in the Netherlands reported explosive new allegations leveled at Van der Stap, whose supposed personal transformation from convicted to reformed hacker has been widely covered in the tech news media. The Dutch daily RTL reported on Sept. 29 that investigators suspect Van der Stap tried to orchestrate at least two murders. According to RTL, the murders were allegedly to be committed abroad, and there are indications Van der Stap gave the order for these attacks.
Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million. In an interview with KrebsOnSecurity on September 9, Van der Stap described his new role as “offensive security lead” at the Dutch cybersecurity company Neo Security, saying the job involved probing client networks for security vulnerabilities.
Neo Security’s owner Benjamin Korper told Reuters he has hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but that so far investigators have found no evidence he acted against his employer or clients. Korper said Dutch forensic investigators visited his office on September 15, the night Van der Stap was arrested in a dramatic police raid that reportedly involved flash bang grenades.

A screenshot of a Sept 16 story by the Dutch news outlet at5.nl, describing a police raid on Van Der Stap’s residence that reportedly used flash-bang grenades.
Prior to his first arrest in 2023, Van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD) — even as he was hacking into and extorting a number of large organizations.
When asked in a recent interview why anyone should believe the word of a self-described “reformed” cybercriminal who had so casually deceived countless friends, co-workers and journalists for years, Van der Stap replied that his work spoke for itself and there was nothing he could say that would convince his worst critics.
“You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced,” Van der Stap told KrebsOnSecurity on Sept. 9. “I’m doing what I can to repay victims, and that’s all I can do. If someone doesn’t want to believe me, then that’s on them.”
Cybercriminals aligned with ShinyHunters have been responsible for dozens of data breaches involving billions of stolen records, and breaches claimed by the group stretch back to at least 2019. But experts say the people recently operating behind the ShinyHunters name are not the same core members that populated the group in its early days, most of whom are French citizens who have been arrested (if not also imprisoned) on at least one prior occasion for alleged cybercrime activity.
More to the point, ShinyHunters has become something of a franchise. Think the Dread Pirate Roberts character in the 1980s cult movie classic “The Princess Bride,” only succession by death is replaced with succession by arrest, and there can be multiple simultaneous Dread Pirate Robertses. Sources close to the investigation say the FBI is focusing on a remaining handful of cybercriminal freelancers or affiliates who have been feeding the group stolen credentials to various software-as-a-service (SaaS) platforms used by major companies in exchange for a cut of any data ransoms later paid by victims.
In the days after the news broke of Van der Stap’s arrest, a cybercrime-focused chat server on Telegram that was allegedly operated by Rey erupted with hot takes, with most participants heaping ridicule on the teenage hacker after he publicly backed down from threats against the FBI and Cl0p, and again when the ShinyHunters’s darknet website suddenly went offline. Several commentators accused Rey of resurrecting the ShinyHunters brand after its core members were rounded up in France, and making a mockery of the group’s name and reputation ever since.
“He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke,” one member recounted.
A relatively new Telegram channel called “The Battle” has been doxing and needling Rey and other alleged ShinyHunters members for several weeks, and it has gained a considerable readership among the cybercrime communities operating on Telegram. One of the coordinators of that harassment campaign repeatedly portrayed Rey as clueless greenhorn who sought to ride the coattails of a cybercriminal brand that has long enjoyed a reputation for ruthlessly selling or publishing data stolen from victim companies who refuse to give in to extortion demands.
“Rey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters,” wrote the administrators of The Battle server on Telegram. “That group had already been dismantled, with many of its members either arrested or imprisoned, yet Rey still chose to use its name while carrying out his crimes. We’re aware of claims that [Rey] caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25–30% cut over the past few months.”
In an interview with The Register, ShinyHunters claimed they hacked the FBI to counter the agency’s narrative in a May 2026 alert that advised victims against paying a ransom to the group, which came off looking unprofessional and capricious in the FBI’s advisory.

A flash notice on ShinyHunters released by the FBI on May 15, 2026.
The public notice warned the group has been known to pursue a number of different victim harassment strategies, from sending threatening text messages and phone calls to victims and their family members to in some cases swatting victims. The FBI warned ShinyHunters members “may also falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”
The hackers told The Register their attack on the FBI “demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers.” At the same time, the group’s leaders seemed to acknowledge that the FBI’s warning materially harmed their prospects for convincing victims to pay, saying “this was fundamentally a public relations and marketing initiative for our business.”

yt-dlp has over 195,000 stars on GitHub, supports thousands of platforms, and is actively maintained by a global developer community. Unfortunately, the IFPI would like to see it on the EU's piracy watchlist.
Just so you know, the International Federation of the Phonographic Industry (IFPI) represents around 8,000 music labels across 70 countries.
In its submission to the EU's Counterfeit and Piracy Watch List consultation, the group calls yt-dlp "a major problem for the music industry" and names four of its maintainers by their GitHub handles.

Run by the European Commission's Directorate-General for Trade and Economic Security, the Watch List identifies online services and physical marketplaces outside the EU reported to engage in or facilitate copyright infringement.
While it sounds serious, the undertaking isn't meant to gather legal findings and does not mandate any form of direct action. It's closer to a naming exercise intended to pressure operators and governments outside the EU into addressing the identified services.
The 2027 edition is being compiled from submissions received through September 2026, with the final list expected in Q2 2027.
IFPI's submission covers a wide range of copyright enforcement concerns, from AI music generators and cyberlockers to streaming fraud services and domain registrars. yt-dlp appears under the "stream ripping" section, grouped with commercial websites like Y2mate and Savefrom.
They describe the tool as an application that retrieves content by parsing web page data and interacting with platform playback endpoints, with GitHub serving as the primary delivery method for its source code, pre-compiled binaries, and installation instructions.
IFPI names four of the project's maintainers by their GitHub handles: pukkandan, who founded the project and led it between 2021 and 2024, and some core maintainers mentioned in the project's Maintainers.md file, like coletdjnz, bashonly, and Grub4K.
The same submission also flags X, Discord, Telegram, and Vimeo as platforms facilitating copyright infringement at scale.

The Watch List, as described by the European Commission, targets online service providers and physical marketplaces located outside the EU. yt-dlp fits neither description in any conventional sense.
IFPI acknowledges this by noting that the project's open source nature, its Unlicense licensing, and an extensive international developer community make it "difficult to contain and/or remove."
From their point of view, there's no central domain to block, no payment processor to cut off, and no hosting provider to strongarm into complying with a takedown request.
The source code is distributed globally and can be compiled by anyone with the skills to do so. But that doesn't mean yt-dlp is a piracy platform.
It's a command-line tool for downloading audio and video content, and categorizing it alongside dedicated ripping or piracy websites conflates a general-purpose downloader with services whose primary purpose is facilitating unauthorized copying.
The Watch List has been used in connection with enforcement against commercial stream-ripping platforms before.
Y2mate.com and eleven other stream-ripping sites were shut down in Vietnam in 2025, and Y2mate had previously appeared on the list.
Before that, in 2024, a German court held the host provider for youtube-dl.org liable in connection with facilitating circumvention. This shows that grouping an open source command-line tool with those commercial services in the same breath does not, by itself, make the tool one of those.
Via: TorrentFreak
The first service call from an application that uses the AWS SDK for Java 2.x takes longer than subsequent calls. This problem is known as cold start. The new SDK client warm-up feature reduces cold-start latency. One call to SdkWarmUp.warmUp() during application startup exercises the SDK request path before your first service call. With AWS Lambda SnapStart, the warm-up becomes part of the snapshot, so the first request after every restore benefits as well.
On the first service call, the JVM loads and initializes the SDK classes for the request path, then runs that code in the interpreter until the just-in-time (JIT) compiler compiles it to native code. Establishing the connection adds a DNS lookup, a TLS handshake, and certificate chain validation. The calls that follow reuse the loaded code and a pooled connection, so they complete faster.
SDK client warm-up loads that code during application startup. It warms both the service client and the HTTP client:
SDK client warm-up ships in Java SDK version 2.54.0 and later as part of the sdk-core module, so it is available to every service client without an additional dependency. For more information about project setup, see Set up an Apache Maven project.
The following pom.xml adds the Amazon Simple Storage Service (Amazon S3) module :
<dependencies>
<dependency>
<groupId>software.amazon.awssdk</groupId>
<artifactId>s3</artifactId>
<version>2.54.0</version>
</dependency>
</dependencies>
SdkWarmUp.warmUp() warms every service client on your classpath, along with the HTTP clients that they use. Use this method when your application calls each of those clients.
Invoke warmUp() with no arguments to warm all the clients on your classpath:
import software.amazon.awssdk.core.warmup.SdkWarmUp;
SdkWarmUp.warmUp();
The SdkWarmUp.warmUp(Class<? extends SdkClient>... clients) overload warms only the clients you name, passed as SdkClient class objects. A synchronous client class warms the synchronous path (the service client and the synchronous HTTP clients), and an asynchronous client class warms the asynchronous path (the service client and the asynchronous HTTP clients).
If a dependency brings in service modules you don’t need, warmUp() warms those unused clients too, which adds to your startup time. To warm the clients you need and skip the rest, use the warmUp(Class...)overload.
The following example warms the synchronous service clients for Amazon S3 and Amazon DynamoDB:
import software.amazon.awssdk.core.warmup.SdkWarmUp;
import software.amazon.awssdk.services.s3.S3Client;
import software.amazon.awssdk.services.dynamodb.DynamoDbClient;
SdkWarmUp.warmUp(S3Client.class, DynamoDbClient.class);
Warm-up applies to any application that starts a new JVM, not only to functions that use SnapStart. In a service that runs on Amazon EC2 or in a container, call SdkWarmUp.warmUp() during startup, before the instance registers with a load balancer or reports itself healthy. The SDK request path is then already initialized when the first request arrives.
AWS Lambda SnapStart reduces cold starts by taking a snapshot of your initialized function and restoring from it on later invocations. When the warm-up is part of that snapshot, every restore starts with warm clients.
Call SdkWarmUp.warmUp() in the constructor of your function handler class:
import com.amazonaws.services.lambda.runtime.Context;
import com.amazonaws.services.lambda.runtime.RequestHandler;
import software.amazon.awssdk.core.warmup.SdkWarmUp;
public class MyHandler implements RequestHandler<String, String> {
public MyHandler() {
// Warm-up runs during initialization, before SnapStart takes the snapshot.
SdkWarmUp.warmUp();
// Your other initialization here.
}
@Override
public String handleRequest(String input, Context context) {
// Your handler logic here.
}
}
For more information, see Lambda SnapStart and Java runtime hooks for SnapStart.
For more examples of SDK warmup, see the AWS SDK for Java 2.x Developer Guide.
In this post, I introduced SDK client warm-up, a new feature in the AWS SDK for Java 2.x that moves SDK initialization from your first request to startup. I showed you how to warm every client on your classpath with a single call, and how to use warm-up in both long-running services and functions that use AWS Lambda SnapStart.
To learn more, see the SDK client warm-up topic in the AWS SDK for Java 2.x Developer Guide. Try it out today and share your feedback by creating an issue in the aws-sdk-java-v2 GitHub repository.
What’s new for command completion in IntelliJ IDEA
Modern IDEs are packed with power. The real challenge isn’t whether your IDE can do something – it’s remembering how to trigger it.
Some features live behind shortcuts. Others are available through intention menus, Search Everywhere, postfix completion, live templates, or tool windows. Discoverability is a constant tax on developer focus: As an IDE grows more capable, keeping every feature within reach gets harder.
That’s why we created command completion, a context-aware entry point to useful functionality from the place where you spend most of your time – the editor.

Typing .. anywhere in a file surfaces intelligent actions tailored to your current code and caret position. Whether you need to refactor, navigate, generate, document, explain, or fix code, you can act immediately without breaking your flow.
Rather than answering “What can I type here?”, command completion addresses a more useful question: “What can I do here?”
This feature has already been around for a while. In IntelliJ IDEA 2026.3 EAP, it is taking another big step toward becoming your primary interface for everyday coding assistance.
Here’s what’s new and improved:
Debugging with temporary println() statements is a habit many of us struggle to break. You add print statements, re-run the app, read the console, and then manually clean up the code afterward.
Logpoints are a cleaner, non-intrusive alternative – and now they are accessible right through command completion:
Simply type .. over an expression or block to drop a logpoint instantly, using the current expression or context as the logged value. Even better: IntelliJ IDEA will now suggest replacing existing print statements with logpoints, helping you move from messy code edits to clean, debugger-supported logging.
If you’re new to logpoints, take a look at the logpoints tutorial. It explains how to combine them with your AI agents in IntelliJ IDEA. If you missed our 2026.2 updates, logpoints got a revised UI, AI agent support, improved navigation, and faster evaluation, making them one of the most versatile debugging tools in your toolkit.
You can now trigger AI actions using the same .. workflow. Need to explain a complex method, generate docstrings, or refactor a block? You no longer have to interrupt your flow, switch tools, or describe the exact location to the agent. Because the IDE already knows your active file, language, line number, and selected expression, it can give the agent this rich context.
Note: If you have the Air plugin installed, your requests will be automatically routed through it.
For actions that affect a specific class, method, or declaration, IntelliJ IDEA now highlights the target so it is clearer what the selected command will apply to before you run it.
As part of our effort to unify completion workflows, postfix completion, live templates, and command completion now share a consistent interface. You’ll notice clearer filtering, sharper preview panels, and more intuitive discoverability directly from the completion popup.

Command completion is also becoming useful in more contexts, including binary files and decompiled code.
We’ve also expanded support to structured and framework-specific environments. You can now use .. inside properties files, Spring workflows, and other domain-specific formats, with support for build scripts coming soon.
Command completion isn’t just another flavor of autocompletion. It is a fundamental shift in how you discover IDE functionality.
Instead of searching through top-level menus or memorizing hotkeys, you can start from where you already are – the code. IntelliJ IDEA continuously analyzes your syntax tree, scope, inspection state, and available actions to present only what is relevant in the moment.
For high-frequency actions, shortcuts remain the fastest choice. For everything else, command completion gives you a discoverable path directly from your code.
Open any Java, Kotlin, or Scala file in IntelliJ IDEA 2026.2 or 2026.3 EAP and type .. anywhere in the editor. Try it near a method, an expression, a regular expression, a declaration that needs documentation, or a place where you would normally open Search Everywhere. The completion popup will reflect what’s possible in that exact spot.
Command completion is continuously evolving, and we have big plans for future releases. Our core mission remains simple: one familiar entry point for whatever you want to do next in code.

But then in 2020, they spent $200 million to make that fraud legal, so now they won't have to pay that again in the future!
According to methane-breathing money-ghouls who run our world, this was a great investment: they could have just spent an additional $50M/year on salaries, but now they legalized an across-the-board salary reduction that pays itself back in only 4 years. Half that, actually, because they went halfsies on it with Uber! Someone's getting a raise.
This goes way beyond "a fine is a price".
("allegations")
San Francisco City Attorney David Chiu said it was "the largest wage-and-hour settlement in California history." [...]
That's a time before voters approved Proposition 22, an Uber- and Lyft-funded ballot measure that classified ride-hail drivers as independent contractors, meaning they would not receive the benefits and wage protections afforded to other workers. The gig companies spent more than $200 million on the measure.
Previously, previously, previously, previously, previously, previously, previously, previously, previously, previously, previously, previously, previously, previously, previously, previously, previously.