A suspected member of the ShinyHunters extortion group, operating under the alias “Rey,” has reportedly been detained by authorities in Jordan and is now cooperating with the FBI, according to Reuters reporting cited by The Hacker News and BleepingComputer.
The suspect, identified as Saif al-Din Khader, was reportedly taken into custody on September 29, 2026 (BleepingComputer’s sources place the date on a Tuesday that week). Sources familiar with the matter say Khader is walking law enforcement through his electronic devices and digital communications to help identify and locate alleged co-conspirators. One source described his cooperation as “critical to ongoing efforts to arrest these hackers.”
Part of a Broader FBI Crackdown
The reported detention follows an escalating FBI campaign against ShinyHunters after the group claimed responsibility for breaching FBI systems in September. ShinyHunters told BleepingComputer it exploited an alleged Oracle PeopleSoft zero-day to gain initial access, then moved laterally into FBI-managed AWS GovCloud infrastructure, claiming to have exfiltrated between 2TB and 3TB of data, including records on current and former employees, job applicants, and medical/psychiatric information. The FBI confirmed it was investigating unauthorized activity but has not verified the scope of any theft, and BleepingComputer notes it could not independently confirm the zero-day, lateral movement, or data volume claims.
The alleged FBI breach triggered a wider law enforcement push. Dutch police arrested a 24-year-old Amsterdam man, identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap (alias “Umbreon”), on September 15 in connection with the group. FBI Cyber Division Assistant Director Brett Leatherman publicly urged remaining ShinyHunters members to come forward, warning that “arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left.”
Signs of Disruption, But Operation Continues
On the same day Khader was reportedly detained, an alleged ShinyHunters affiliate who had previously spoken to media shut down their messaging account, the group’s data leak site went offline, and its main representative stopped responding to press inquiries. It remains unclear whether these events are connected to Khader’s detention. A new ShinyHunters leak site surfaced days later, suggesting other members continue operating the extortion scheme.
ShinyHunters has been linked to breaches at Google, Cisco, PornHub, and Instructure Canvas, typically compromising third-party SaaS integrations to steal authentication tokens and access connected cloud environments. Numerous arrests tied to the ShinyHunters name have occurred over the years, including suspects connected to the 2024 Snowflake data-theft campaign.
