Skip to main content
Threat IntelligenceEmerging Threats

FBI Arrests Multiple Suspects Linked to ShinyHunters Hack

Law enforcement officers escort handcuffed individuals in a formal government setting.
“The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice,” an FBI spokesperson told The Register.

FBI announces "multiple" arrests but declines specifics

The FBI confirmed to The Register that investigators, working with law enforcement partners, have arrested “multiple” suspects connected to a September cyber incident allegedly involving the group ShinyHunters. The bureau framed the operation as ongoing and said it will “spare no resource” to bring responsible individuals to justice. Beyond that statement, the FBI declined to comment on the specific arrests when asked by the outlet.

Saif al‑Din Khader — "Rey" reportedly detained in Jordan

Reports say Saif al‑Din Khader, known by the alias Rey, was detained in Jordan on September 29 and has been held there, according to Reuters. The Register was told the FBI would not confirm details of that detention. Reuters has reported Khader is cooperating with the FBI to identify other members of the group. Khader himself confirmed his identity to security journalist Brian Krebs last year; Krebs described him as the “technical operator and public face” of Scattered LAPSUS$ Hunters.

Security researcher Kevin Beaumont reacted to the news with terse congratulations—“Rey got picked up finally”—and noted Rey was “one of the kids who got into JLR,” a reference to a separate, high‑impact intrusion tied to Scattered LAPSUS$ Hunters.

Dutch National Police arrest and one alleged leader

Two weeks before Khader's reported detention, the Dutch National Police arrested a 24‑year‑old whom the FBI described as “one of the alleged leaders of ShinyHunters.” Dutch authorities did not name the suspect in their announcement. Krebs and other reports, cited by The Register, identify that person as Pepijn van der Stap—convicted in 2023 for hacking and extortion, who had been on supervised release following a three‑year prison term.

The Register also reports that van der Stap had worked as a software engineer at the Amsterdam‑based cybersecurity startup Hadrian and volunteered as a security researcher at the Dutch Institute for Vulnerability Disclosure (DIVD), details included in coverage of the arrest.

FBIJobs.gov intrusion and ShinyHunters' stated motives

In late September, the group claiming the ShinyHunters name hacked the FBIJobs.gov portal and asserted it had taken sensitive personal data for current, former and prospective FBI employees. A spokesperson for the group told The Register the action was “NOT financially motivated … We want the FBI to correct or retract their statements they made, which included substantial false allegations.”

In an exclusive interview with The Register the group’s spokesperson described the intrusion as “fundamentally a public relations and marketing initiative for our business,” framing the operation as attention‑seeking rather than profit‑driven.

Connections to Jaguar Land Rover and Scattered LAPSUS$ Hunters

The Register’s reporting links some actors associated with ShinyHunters to a prior and severe breach of Jaguar Land Rover (JLR) in late August 2025. That incident affected JLR’s IT systems, halted manufacturing operations, knocked dealer systems offline, caused suppliers to face canceled or delayed orders, and resulted in the theft of personal payroll data belonging to thousands of employees. The breach has been described in reports as one of the most costly cyberattacks in UK history and was attributed to Scattered LAPSUS$ Hunters; Krebs identified Khader as a prominent figure within that cluster.

What this means for the FBI, JLR employees, and security researchers

  • For the FBI: the bureau has signaled an extended criminal investigation and publicly urged remaining members of the group to surrender or reach out—a message delivered in a video by Brett Leatherman, assistant director of the FBI’s Cyber Division: “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left ... I suggest you reach out first while the choice is still yours.” The FBI declined to answer whether it had seized any infrastructure or whether anyone had reached out in response to that plea.
  • For JLR employees whose payroll data was taken in the August 2025 breach: the arrests and reported cooperation by detained individuals raise the possibility of stronger attribution and victim notification, but The Register’s reporting does not say whether stolen data has been recovered or which victims — if any — have been contacted directly by law enforcement.
  • For security researchers and reporters: the case continues to produce named connections—individuals publicly linked to past intrusions, company affiliations, and volunteer roles—that will shape how technical and legal narratives unfold as investigators disclose more information.

The FBI’s public statements, the reported detentions in Jordan and the Netherlands, and the choice of language from both prosecutors and the group itself make clear this is an active, multi‑jurisdictional criminal inquiry. What remains to be revealed is whether detained suspects’ reported cooperation and any seized infrastructure will map to further arrests, recoveries, or clearer answers about motive and the full scope of the operations that disrupted JLR and targeted the FBIJobs.gov portal.

Original article