FBI announces "multiple" arrests but declines specifics
The FBI confirmed to The Register that investigators, working with law enforcement partners, have arrested “multiple” suspects connected to a September cyber incident allegedly involving the group ShinyHunters. The bureau framed the operation as ongoing and said it will “spare no resource” to bring responsible individuals to justice. Beyond that statement, the FBI declined to comment on the specific arrests when asked by the outlet.
Saif al‑Din Khader — "Rey" reportedly detained in Jordan
Reports say Saif al‑Din Khader, known by the alias Rey, was detained in Jordan on September 29 and has been held there, according to Reuters. The Register was told the FBI would not confirm details of that detention. Reuters has reported Khader is cooperating with the FBI to identify other members of the group. Khader himself confirmed his identity to security journalist Brian Krebs last year; Krebs described him as the “technical operator and public face” of Scattered LAPSUS$ Hunters.
Security researcher Kevin Beaumont reacted to the news with terse congratulations—“Rey got picked up finally”—and noted Rey was “one of the kids who got into JLR,” a reference to a separate, high‑impact intrusion tied to Scattered LAPSUS$ Hunters.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDutch National Police arrest and one alleged leader
Two weeks before Khader's reported detention, the Dutch National Police arrested a 24‑year‑old whom the FBI described as “one of the alleged leaders of ShinyHunters.” Dutch authorities did not name the suspect in their announcement. Krebs and other reports, cited by The Register, identify that person as Pepijn van der Stap—convicted in 2023 for hacking and extortion, who had been on supervised release following a three‑year prison term.
The Register also reports that van der Stap had worked as a software engineer at the Amsterdam‑based cybersecurity startup Hadrian and volunteered as a security researcher at the Dutch Institute for Vulnerability Disclosure (DIVD), details included in coverage of the arrest.
FBIJobs.gov intrusion and ShinyHunters' stated motives
In late September, the group claiming the ShinyHunters name hacked the FBIJobs.gov portal and asserted it had taken sensitive personal data for current, former and prospective FBI employees. A spokesperson for the group told The Register the action was “NOT financially motivated … We want the FBI to correct or retract their statements they made, which included substantial false allegations.”
In an exclusive interview with The Register the group’s spokesperson described the intrusion as “fundamentally a public relations and marketing initiative for our business,” framing the operation as attention‑seeking rather than profit‑driven.
Connections to Jaguar Land Rover and Scattered LAPSUS$ Hunters
The Register’s reporting links some actors associated with ShinyHunters to a prior and severe breach of Jaguar Land Rover (JLR) in late August 2025. That incident affected JLR’s IT systems, halted manufacturing operations, knocked dealer systems offline, caused suppliers to face canceled or delayed orders, and resulted in the theft of personal payroll data belonging to thousands of employees. The breach has been described in reports as one of the most costly cyberattacks in UK history and was attributed to Scattered LAPSUS$ Hunters; Krebs identified Khader as a prominent figure within that cluster.
What this means for the FBI, JLR employees, and security researchers
- For the FBI: the bureau has signaled an extended criminal investigation and publicly urged remaining members of the group to surrender or reach out—a message delivered in a video by Brett Leatherman, assistant director of the FBI’s Cyber Division: “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left ... I suggest you reach out first while the choice is still yours.” The FBI declined to answer whether it had seized any infrastructure or whether anyone had reached out in response to that plea.
- For JLR employees whose payroll data was taken in the August 2025 breach: the arrests and reported cooperation by detained individuals raise the possibility of stronger attribution and victim notification, but The Register’s reporting does not say whether stolen data has been recovered or which victims — if any — have been contacted directly by law enforcement.
- For security researchers and reporters: the case continues to produce named connections—individuals publicly linked to past intrusions, company affiliations, and volunteer roles—that will shape how technical and legal narratives unfold as investigators disclose more information.
The FBI’s public statements, the reported detentions in Jordan and the Netherlands, and the choice of language from both prosecutors and the group itself make clear this is an active, multi‑jurisdictional criminal inquiry. What remains to be revealed is whether detained suspects’ reported cooperation and any seized infrastructure will map to further arrests, recoveries, or clearer answers about motive and the full scope of the operations that disrupted JLR and targeted the FBIJobs.gov portal.




