Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Remains of Bulgaria’s Czar Samuel return ‘home’ after 1,000 years | History News

    October 3, 2026

    Surfshark Promo Codes: 87% Off | October 2026

    October 3, 2026

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Remains of Bulgaria’s Czar Samuel return ‘home’ after 1,000 years | History News
    • Surfshark Promo Codes: 87% Off | October 2026
    • ShinyHunters hacker reportedly detained in Jordan, aiding FBI
    • Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea
    • Vitamin C linked to fewer deaths in blood disorder trial
    • Trump ramps up pressure on US Republicans to end US clock switching | Donald Trump News
    • Conservatives pledge to scrap £100,000 childcare ‘cliff edge’
    • Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 3, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A suspected ShinyHunters hacking group member known online as “Rey” has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group.

    According to Reuters, Jordanian authorities detained Rey, identified as Saif al-Din Khader, this week, with two sources saying he was taken into custody on Tuesday.

    Two sources familiar with the arrest told Reuters that Khader is now helping the FBI and international law enforcement agencies locate other group members.

    One source said Khader is walking law enforcement through his electronic devices and digital communications to help identify and locate his alleged co-conspirators.

    “His cooperation is critical to ongoing efforts to arrest these hackers,” a source told Reuters.

    The reported detention comes amid an FBI crackdown on ShinyHunters following the group’s cyberattack on the bureau.

    In September, ShinyHunters told BleepingComputer that it breached FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability before spreading laterally into FBI-managed AWS GovCloud systems.

    The threat actors claimed they stole between 2TB and 3TB of data, including information belonging to current and former FBI employees, job applicants, medical and psychiatric information, and records from internal services.

    BleepingComputer has not independently verified the alleged zero-day, lateral movement, or volume of stolen data. The FBI previously confirmed that it was investigating claims of unauthorized activity but did not confirm that data had been stolen.

    Following the FBI breach, the Dutch police arrested a 24-year-old Amsterdam man on September 15 as part of an investigation into ShinyHunters.

    The suspect was identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, who previously used the online alias “Umbreon.”

    After the arrest, the FBI publicly warned other ShinyHunters members to turn themselves in, saying investigators were still identifying those involved with the group.

    “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” FBI Cyber Division Assistant Director Brett Leatherman said last week.

    “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”

    The main ShinyHunters representative continued communicating with BleepingComputer after van der Stap’s arrest, indicating he was not the person operating that messaging account.

    On Tuesday, the same day Khader was reportedly detained, signs of disruption began appearing within the ShinyHunters operation.

    An alleged ShinyHunters affiliate who had previously contacted BleepingComputer and other media about the FBI attack and a recent Clop ransomware gang data breach abruptly shut down their online messaging account.

    Later, the ShinyHunters data leak site went offline, and the group’s main representative also stopped responding to questions from the media, including BleepingComputer and Reuters.

    It is unclear whether the sudden silence and shutdown of ShinyHunters-linked infrastructure are connected to Khader’s reported detention.

    However, on Thursday, a new ShinyHunters data leak site went online, suggesting other members continue to run the extortion operation.

    BleepingComputer contacted ShinyHunters about Rey’s reported detention but has not received a response.

    The ShinyHunters gang has long been a thorn in the side of law enforcement, performing massive data theft attacks and extortion campaigns against organizations worldwide.

    In recent years, the extortion gang has focused on Salesforce and other cloud SaaS environments, with campaigns linked to breaches at Google, Cisco, and PornHub.

    The extortion gang commonly breaches third-party integration companies and uses stolen authentication tokens to access connected SaaS environments and steal customer data.

    The extortion gang was also behind a massive data-theft attack on Instructure Canvas in May that caused significant platform outages. The company eventually reached an “agreement” with the threat actors to prevent the data stolen in a recent breach from being leaked online.

    Over the years, numerous arrests have been linked to the ShinyHunters name, including suspects connected to the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.

    Who is Rey?

    The threat actor known as Rey has been linked to numerous data theft and extortion attacks over the past two years.

    In January 2025, Rey was one of four threat actors who claimed responsibility for a breach of Telefónica’s internal Jira ticketing system, where approximately 2.3GB of documents, tickets, and other data were allegedly stolen.

    BleepingComputer previously reported that Rey and two of the other attackers were members of the then-new HellCat ransomware operation.

    The threat actor was later linked to a wider series of attacks targeting Jira servers at organizations worldwide.

    In February 2025, Orange confirmed that its Romanian operations suffered a cyberattack after Rey leaked approximately 6.5GB of stolen data. Rey told BleepingComputer at the time that he was a member of HellCat but had conducted the Orange breach independently.

    Rey was later linked to the ShinyHunters extortion group and was seen with administrative privileges in Telegram channels operated by “Scattered Lapsus$ Hunters.”

    Scattered Lapsus$ Hunters was first seen in 2025 and claimed to consist of former members of the Lapsus$, Scattered Spider, and ShinyHunters cybercrime groups.

    The group claimed responsibility for the September 2025 cyberattack on Jaguar Land Rover that forced the automaker to halt production for weeks and ultimately cost the company more than $220 million.

    Rey was also linked to an ealier March 2025 breach of Jaguar Land Rover, with the threat actor leaking gigabytes of data, including Jira issues, source code, employee information, and development logs.

    Rey leaking jaguar data

    In November 2025, security journalist Brian Krebs reported that Rey was Saif Al-Din Khader after analyzing information obtained from infostealer logs and speaking directly with Khader over Signal.

    Krebs reported that Khader said he was trying to distance himself from Scattered Lapsus$ Hunters and claimed he had been cooperating with law enforcement since at least June.

    “I’m already cooperating with law enforcement,” Khader allegedly told Krebs. “In fact, I have been talking to them since at least June. I have told them nearly everything. I haven’t really done anything like breaching into a corp or extortion related since September.”

    Krebs said he could not verify those claims.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Aiding detained FBI Hacker Jordan reportedly ShinyHunters
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

    Fortra Patches Critical Vulnerabilities in BoKS

    Danish university DTU breach exposes data of up to 200,000 people

    doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Remains of Bulgaria’s Czar Samuel return ‘home’ after 1,000 years | History News

    October 3, 2026

    Surfshark Promo Codes: 87% Off | October 2026

    October 3, 2026

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    October 3, 2026

    Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea

    October 3, 2026
    Latest Posts

    Google’s top hacker hunter explains why hacking groups get codenames

    August 8, 2026

    Nicola Sturgeon ‘has not spoken to’ estranged husband, Peter Murrell, since he was jailed | Nicola Sturgeon

    August 8, 2026

    Amid Abuse Claims Against Max Miller, This Democrat Thinks He Can Win His Seat

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Remains of Bulgaria’s Czar Samuel return ‘home’ after 1,000 years | History News

    October 3, 2026

    Surfshark Promo Codes: 87% Off | October 2026

    October 3, 2026

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.