Back to Feed
Threat IntelligenceOct 4, 2026

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

ShinyHunters suspect 'Rey' detained in Jordan, cooperating with FBI.

Summary

A suspected member of the ShinyHunters group, known as 'Rey' (Saif al-Din Khader), has been detained in Jordan and is reportedly cooperating with the FBI. Rey, also linked to other cybercrime groups like Scattered LAPSUS$ Hunters and Hellcat, has allegedly been involved in breaching over 140 organizations and extorting millions. This development follows the recent arrest of another individual in Amsterdam and is part of ongoing efforts to dismantle the ShinyHunters network.

Full text

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members Ravie LakshmananOct 04, 2026Cybercrime / Data Breach A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and law enforcement to identify other members of the group. "His cooperation is critical to ongoing efforts to arrest these hackers," a source told the news agency. Rey, who also went by the online alias ReyXBF, is not an unknown face. In a report published in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of Scattered LAPSUS$ Hunters (SLH or SLSH), a group that's assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters. "Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024," Krebs noted at the time. "Also in 2024, Rey would take over as administrator of the most recent incarnation of BreachForums." Khader also told Krebs that he had been cooperating with law enforcement since at least June 2025. The development is the latest action in the ShinyHunters saga, which also saw the arrest of a 24-year-old Amsterdam man last week for their involvement in the threat actor's malicious cyber operations. Although his identity has not been disclosed, independent reports revealed that it was Pepijn van der Stap, a reformed hacker who has been employed as an offensive security lead at the Dutch company Neo Security. A ShinyHunters spokesperson subsequently denied having any connections with van der Stap. Following the arrest, FBI director Kash Patel said, "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest." In a follow-up X post, Patel said, "FBI teams are working new leads RIGHT NOW. More arrests are on the table." In recent weeks, the prolific hacking crew has come under the spotlight for hijacking the darknet website of a fellow cybercriminal outfit, Cl0p, by exploiting an unpatched flaw in Grav CMS and its hack of the FBI's "apply.fbijobs[.]gov" portal, stealing around three terabytes of sensitive data. ShinyHunters insisted that it's not seeking a monetary payoff in the FBI case, but rather apply pressure on the FBI to amend what it said were false allegations about the group and challenge claims made by the agency about its connections with The Com, a loose-knit cybercrime collective notorious for social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, and physical violence. "Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement. "They often target third-party vendors in cloud-based platforms, stealing sensitive data and extort victims with threats to publish it." Leatherman, who described van der Stap as an alleged leader of the group, also urged other members to speak out and said that they can no longer hide behind perceived international anonymity and evade detection. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left. The longer you stay in this, the more we learn about you," Leatherman added. "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours." In a deep-dive report tracing ShinyHunters' origins and their tactical evolution, cybersecurity companies Sekoia and Beazley Security said its lineage goes back to two progenitor hacking groups, TheDarkOverlord and GnosticPlayers, that specialized in extortion and data leak operations. The ShinyHunters brand emerged publicly around April or May 2020. "Six years on, ShinyHunters is less a group than a brand and business model that has outlived its founders," researchers Enzo Saez and Robert (Bobby) Venal said. "What began in 2020 as a small crew trading stolen databases on RaidForums has become a persistent, self-renewing group that has absorbed indictments, arrests, and forum seizures without ever going quiet for long." "That resilience is the real story. It doesn't come from any single leader or cell, but from a division of labor that has become almost modular: initial access from social engineers, amplification and recruitment from adjacent actors, and monetization under a shared, recognizable brand." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cybercrime, data breach, ransomware ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header

Indicators of Compromise

  • domain — apply.fbijobs[.]gov
  • malware — LAPSUS$
  • malware — Hellcat
  • malware — Cl0p

Entities

ShinyHunters (threat_actor)Scattered Spider (threat_actor)LAPSUS$ (threat_actor)Hellcat (threat_actor)The Com (threat_actor)Cl0p (threat_actor)