rkj dev

ShinyHunters Hacker 'Rey' Detained in Jordan, Cooperating with FBI

Saif al-Din Khader, known online as Rey, is walking law enforcement through his devices as the international crackdown on the cybercrime group accelerates.

Digital illustration of law enforcement cyber specialists examining forensic network data in a control center
Illustration: International law enforcement agencies are analyzing forensic evidence and digital communications from detained cybercrime suspects.AI-generated illustration

Key takeaways

  • Jordanian authorities detained Saif al-Din Khader, the hacker known as 'Rey,' on September 29, 2026.
  • Khader is actively cooperating with the FBI by walking agents through his digital communications and electronic devices.
  • The detention follows the September 15 arrest of alleged ShinyHunters member Pepijn van der Stap in the Netherlands.
  • The FBI reports that the cybercrime syndicate and its co-conspirators have breached over 140 organizations and extorted at least $70 million.

A suspected member of the prolific ShinyHunters digital extortion syndicate has been detained in Jordan and is cooperating with U.S. and international law enforcement. The suspect, identified as Saif al-Din Khader and known online by the aliases "Rey" and "ReyXBF," was taken into custody on September 29, 2026, according to reporting from Reuters via BleepingComputer.

Sources familiar with the investigation stated that Khader is walking the Federal Bureau of Investigation (FBI) and international investigators through his electronic devices and digital communications to identify and locate alleged co-conspirators. The detention marks a major step forward for federal investigators working to dismantle the group responsible for high-profile cyberattacks and millions of dollars in extorted payments.

Digital illustration of electronic devices being analyzed in a forensic laboratory
Illustration: Investigators are reviewing confiscated electronic devices and communication records to trace hacking affiliates.AI-generated illustration

Escalating Crackdown Following FBI Portal Breach

The operation against the group intensified after ShinyHunters targeted the FBI itself in September 2026. According to CBS News, the hacking crew claimed responsibility for infiltrating the bureau's job recruitment portal, "apply.fbijobs[.]gov," defacing the site and asserting that they stole between 2TB and 3TB of data involving current and former bureau employees, applicants, and medical records.

ShinyHunters claimed it gained access using an alleged zero-day flaw in Oracle PeopleSoft before pivoting across lateral networks into FBI-managed AWS GovCloud systems. As reported by PCMag, the threat actors claimed the intrusion was not an extortion attempt for ransom, but rather a campaign to force the FBI to retract a public advisory from May 2026 that downplayed the group's capabilities.

While the FBI confirmed it was investigating unauthorized activity without verifying the volume of stolen data, the bureau launched an aggressive response. On September 15, Dutch police arrested 24-year-old Pepijn van der Stap in Amsterdam under the alias "Umbreon." Following that arrest, FBI Cyber Division Assistant Director Brett Leatherman issued a direct warning to remaining members: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you."

Digital illustration of interconnected cloud network infrastructure and data flow
Illustration: ShinyHunters targeted cloud integrations and corporate SaaS environments across multiple global industries.AI-generated illustration

Who Is 'Rey' and What Is His Cybercrime Record?

Khader, reported to still be a teenager, has compiled a extensive record across several high-profile extortion operations. Detailed by The Hacker News, independent security journalist Brian Krebs previously identified Khader in November 2025 as an administrator for the HellCat ransomware group's leak site, as well as an administrator for a recent incarnation of BreachForums.

In January 2025, Khader was among the threat actors who claimed responsibility for breaching Telefónica's internal Jira ticketing system, stealing roughly 2.3GB of documents. The following month, Orange confirmed a cyberattack on its Romanian operations after Khader leaked 6.5GB of internal data. Khader was also linked to attacks on Schneider Electric and a March 2025 intrusion at Jaguar Land Rover, where source code, employee data, and Jira issues were exfiltrated.

Khader later operated with administrative privileges in "Scattered Lapsus$ Hunters" (SLSH)—a coalition formed from members of Scattered Spider, LAPSUS$, and ShinyHunters. That collective claimed the September 2025 attack on Jaguar Land Rover that halted vehicle production for weeks and inflicted over $220 million in losses. Khader claimed to Krebs in late 2025 that he had been in contact with authorities since June 2025.

Operational Impact on the ShinyHunters Syndicate

Signs of disruption within the ShinyHunters network emerged immediately around the time of Khader's detention on Tuesday. A key affiliate messaging account went offline, the primary representative ceased answering media inquiries, and the group's darknet data leak portal temporarily disappeared. However, a new leak site emerged shortly after, indicating that remaining affiliates are attempting to maintain extortion activities.

According to analysis from cybersecurity firms Sekoia and Beazley Security, ShinyHunters originated in 2020 out of progenitor groups TheDarkOverlord and GnosticPlayers. Over six years, the outfit transitioned from trading stolen databases on RaidForums to targeting cloud software-as-a-service (SaaS) environments, including Salesforce and Instructure Canvas, by compromising third-party integrations and stealing authentication tokens.

FBI Assistant Director Leatherman noted that the group and its affiliates have breached more than 140 organizations and collected at least $70 million in extortion payments. FBI Director Kash Patel confirmed that federal agents are actively pursuing additional targets based on leads from recent arrests, stating that further apprehensions remain on the table.

Frequently asked questions

Who is the suspect known as Rey in the ShinyHunters investigation?

Rey is the online moniker used by Saif al-Din Khader, a suspected cybercriminal who has served as an administrator across HellCat ransomware, BreachForums, and Scattered Lapsus$ Hunters.

Why was Saif al-Din Khader detained in Jordan?

Jordanian authorities took Khader into custody in connection with an international law enforcement crackdown on the ShinyHunters extortion group, where he is now assisting the FBI with identifying co-conspirators.

What major breaches have been linked to ShinyHunters and Rey?

Attacks linked to the group and Khader include breaches at Telefónica, Orange Romania, Jaguar Land Rover, Instructure Canvas, and the FBI's job recruitment portal.

Sources

  1. ShinyHunters hacker reportedly detained in Jordan, aiding FBIBleepingComputer · Oct 3, 2026
  2. ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersThe Hacker News · Oct 4, 2026
  3. Suspected ShinyHunters hacker detained in Jordan, cooperating with FBI, sources sayCBS News · Oct 4, 2026
  4. Hacker Linked to ShinyHunters FBI Hack Detained in JordanPCMag · Oct 4, 2026

How this story was made: the newsroom picked it up from Techmeme and Reddit, gathered the full text of the sources above, and drafted it with AI assistance. Every factual claim was then checked against those sources before publishing (18 claims checked). Illustrations marked as AI-generated are not photographs. Spotted an error? Tell us.

#ShinyHunters #Cybersecurity #FBI #Data Breach #Ransomware

Published October 5, 2026 at 00:35 UTC