ShinyHunters suspect held in Jordan
A reported detention in Jordan and a week of digital silence are testing the extortion group's resilience.
A suspected member of the ShinyHunters extortion crew is reportedly in Jordanian custody, and according to sources cited by Reuters, he is now helping U.S. investigators trace the people he allegedly worked alongside. The development lands in the middle of an FBI push against a group that has spent years carrying out mass data theft and extortion campaigns against organizations worldwide.
The suspected operator, known online as "Rey" and identified as Saif al-Din Khader, was reportedly taken into custody on Tuesday. Reuters reported that two sources familiar with the arrest said Khader is now working with the FBI and international law enforcement agencies to locate other members of the group.
One of those sources told Reuters that Khader is walking investigators through his electronic devices and digital communications to help identify and locate his alleged co-conspirators. The outlet quoted a source describing the value of that assistance:
"His cooperation is critical to ongoing efforts to arrest these hackers."
— a source who spoke to Reuters
A reported detention in Jordan
The reported arrest was first surfaced by Reuters, which attributed the account to two sources. Those sources said Khader was detained this week, with Tuesday given as the day he was taken into custody. Reuters reported that he is now cooperating with the FBI and international law enforcement agencies as they try to locate other members of the group.
One source said Khader is walking law enforcement through his electronic devices and digital communications to help identify and locate his alleged co-conspirators. The outlet did not name the sources who provided the account, and BleepingComputer has not independently confirmed the reported detention.
The reported detention lands in the middle of an FBI crackdown on ShinyHunters following the group's cyberattack on the bureau. In September, ShinyHunters told BleepingComputer that it breached FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability before spreading laterally into FBI-managed AWS GovCloud systems. The threat actors claimed they stole between 2TB and 3TB of data, including information belonging to current and former FBI employees, job applicants, medical and psychiatric information, and records from internal services.
BleepingComputer has not independently verified the alleged zero-day, lateral movement, or volume of stolen data. The FBI previously confirmed that it was investigating claims of unauthorized activity but did not confirm that data had been stolen.
The FBI breach that preceded the arrest
The FBI breach claim and the reported detention in Jordan are tied together by timing. The bureau had already confirmed it was investigating claims of unauthorized activity before the Jordanian arrest was reported, though it stopped short of confirming that data had been stolen. According to BleepingComputer's earlier reporting, the group claimed to have moved from an alleged Oracle PeopleSoft zero-day into FBI-managed AWS GovCloud systems.
The reported volume of data at stake — 2TB to 3TB — and the categories the group said it took, including job applicants and medical and psychiatric information, put the incident among the more sensitive claims tied to the ShinyHunters name. None of those technical details have been independently verified by BleepingComputer.
The public FBI response to the wider crackdown has been unusually direct. After the Dutch arrest of a 24-year-old Amsterdam man in September, the bureau publicly warned other ShinyHunters members to turn themselves in, saying investigators were still identifying those involved with the group.
FBI Cyber Division Assistant Director Brett Leatherman said last week:
"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left."
"The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
— Brett Leatherman, FBI Cyber Division Assistant Director
An Amsterdam arrest weeks earlier
The Jordanian detention is not the first arrest tied to the group in recent months. Following the FBI breach, Dutch police arrested a 24-year-old Amsterdam man on September 15 as part of an investigation into ShinyHunters. The suspect was identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, who previously used the online alias "Umbreon."
Even after that arrest, the main ShinyHunters representative continued communicating with BleepingComputer, indicating that van der Stap was not the person operating that messaging account. The distinction matters because it shows how the group distributes operational roles across multiple people, and it complicates any assumption that a single arrest can shut down the extortion business.
The FBI has not publicly linked the Amsterdam suspect and the Jordanian suspect beyond the timing of the two investigations. BleepingComputer reported that the FBI publicly warned other ShinyHunters members to turn themselves in after the Dutch arrest, saying investigators were still identifying those involved with the group.
Signs of disruption within the operation
On Tuesday — the same day Khader was reportedly detained — signs of disruption began appearing within the ShinyHunters operation. An alleged ShinyHunters affiliate who had previously contacted BleepingComputer and other media about the FBI attack and a recent Clop ransomware gang data breach abruptly shut down their online messaging account.
Later, the ShinyHunters data leak site went offline, and the group's main representative also stopped responding to questions from the media, including BleepingComputer and Reuters. It is unclear whether the sudden silence and shutdown of ShinyHunters-linked infrastructure are connected to Khader's reported detention. BleepingComputer contacted ShinyHunters about Rey's reported detention but has not received a response.
However, on Thursday, a new ShinyHunters data leak site went online, suggesting other members continue to run the extortion operation. That detail complicates any reading of the week's disruption as a shutdown. Even as one affiliate account went dark and the original leak site disappeared, a replacement came up within days.
What ShinyHunters has done
The ShinyHunters gang has long been a thorn in the side of law enforcement, running massive data theft attacks and extortion campaigns against organizations worldwide. In recent years, the extortion gang has focused on Salesforce and other cloud SaaS environments, with campaigns linked to breaches at Google, Cisco, and PornHub.
The group commonly breaches third-party integration companies and uses stolen authentication tokens to access connected SaaS environments and steal customer data. That pattern — targeting an integrator rather than the primary victim — recurs across the group's recent activity.
The extortion gang was also behind a massive data-theft attack on Instructure Canvas in May that caused significant platform outages. The company eventually reached an "agreement" with the threat actors to prevent the data stolen in a recent breach from being leaked online. Over the years, numerous arrests have been linked to the ShinyHunters name, including suspects connected to the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.
Rey's trail of attacks
The threat actor known as Rey has been linked to numerous data theft and extortion attacks over the past two years, giving investigators a long trail to work with if they are now debriefing him. In January 2025, Rey was one of four threat actors who claimed responsibility for a breach of Telefónica's internal Jira ticketing system, where approximately 2.3GB of documents, tickets, and other data were allegedly stolen.
BleepingComputer previously reported that Rey and two of the other attackers were members of the then-new HellCat ransomware operation. The threat actor was later linked to a wider series of attacks targeting Jira servers at organizations worldwide. In February 2025, Orange confirmed that its Romanian operations suffered a cyberattack after Rey leaked approximately 6.5GB of stolen data. Rey told BleepingComputer at the time that he was a member of HellCat but had conducted the Orange breach independently.
Rey was later linked to the ShinyHunters extortion group and was seen with administrative privileges in Telegram channels operated by "Scattered Lapsus$ Hunters." Scattered Lapsus$ Hunters was first seen in 2025 and claimed to consist of former members of the Lapsus$, Scattered Spider, and ShinyHunters cybercrime groups. The group claimed responsibility for the September 2025 cyberattack on Jaguar Land Rover that forced the automaker to halt production for weeks and ultimately cost the company more than $220 million.
Rey was also linked to an earlier March 2025 breach of Jaguar Land Rover, with the threat actor leaking gigabytes of data, including Jira issues, source code, employee information, and development logs.
The reported identification and his response
In November 2025, security journalist Brian Krebs of KrebsOnSecurity reported that Rey was Saif Al-Din Khader after analyzing information obtained from infostealer logs and speaking directly with Khader over Signal. Krebs reported that Khader said he was trying to distance himself from Scattered Lapsus$ Hunters and claimed he had been cooperating with law enforcement since at least June.
Krebs quoted Khader as saying:
"I'm already cooperating with law enforcement."
"In fact, I have been talking to them since at least June. I have told them nearly everything. I haven't really done anything like breaching into a corp or extortion related since September."
— Saif Al-Din Khader, in messages to security journalist Brian Krebs
Krebs said he could not verify those claims. The distinction between Khader's own account and the claims Krebs could confirm is worth keeping in view as the Jordanian detention is reported. The Reuters account, too, rests on two sources rather than on a public charging document or an official confirmation from Jordanian or U.S. authorities.
What the week signals
For organizations that deal with third-party SaaS integrations, the week's events offer a mixed picture. On one hand, the reported detention of a suspected operator and the apparent takedown of a working leak site suggest that pressure on the group is affecting its operations. On the other, the emergence of a new leak site on Thursday suggests the extortion business itself has not stopped.
The pattern that recurs across ShinyHunters campaigns — breaching an integration company to reach the customers behind it — is the part most directly relevant to defenders. Stolen authentication tokens and third-party access paths remain the group's preferred route into SaaS environments, and that route does not depend on any single operator staying out of custody.
For the FBI and its international partners, the reported cooperation of a suspect who spent two years at the center of multiple extortion operations could yield information about the group's structure, its members, and its methods. Whether that cooperation produces further arrests is not yet established, and the bureau has not confirmed the detention publicly.
The silence from the group's main representative after Tuesday also complicates the picture. BleepingComputer contacted ShinyHunters about Rey's reported detention but has not received a response. It remains unclear whether that silence is temporary, tied to the reported detention, or simply a change in how the remaining members communicate.
Sources
- BleepingComputer Original source
Continue Reading
DTU breach exposes 200k user records
Hackers accessed the Technical University of Denmark's identity system using compromised credentials, potentially exposing data of up to 200,000 people.
Warlock Hits SharePoint, Then Strikes
Symantec says the China-linked group behind Warlock ransomware disabled defenses on dozens of hosts within hours of exploiting SharePoint flaws.
Frontline Education breach hits school staff
Edtech vendor Frontline Education says attackers exploited a third-party software flaw to access employee data including Social Security numbers.