Skip to main content
Emerging ThreatsMalware & Ransomware

FBI Gains Leverage with ShinyHunters Suspect's Detention

Person sits in detention with hands on table, face blurred.

"His cooperation is critical to ongoing efforts to arrest these hackers," a source told Reuters, summarizing why a detained suspect’s statements could matter to an ongoing international probe into the ShinyHunters extortion brand.

Saif al‑Din Khader — alias "Rey" or "ReyXBF" — reportedly detained in Jordan

Reuters, citing three people familiar with the matter, reported that a suspected member of the ShinyHunters group who uses the online name "Rey" and "ReyXBF" was taken into custody in Jordan on September 29, 2026. The report identifies him by name as Saif al‑Din Khader and says he is cooperating with the U.S. Federal Bureau of Investigation and other law enforcement to identify other members of the group.

Prior public reporting: roles in SLH/SLSH, Hellcat and BreachForums

Independent security journalist Brian Krebs named Khader in November 2025 as one of three administrators of Scattered LAPSUS$ Hunters — variously abbreviated SLH or SLSH — an assessed amalgam of Scattered Spider, LAPSUS$, and ShinyHunters. Krebs reported that Khader previously administered the data leak site for the Hellcat ransomware group that surfaced in late 2024, and that in 2024 he took over administration of the most recent incarnation of BreachForums. Khader told Krebs that he had been cooperating with law enforcement since at least June 2025.

Arrests, U.S. FBI messaging, and the claimed scale of ShinyHunters' activity

The detention of Khader follows another arrest linked to the broader ShinyHunters effort: independent reports identified a 24‑year‑old Amsterdam man arrested last week as Pepijn van der Stap, who has been described as a reformed hacker employed as an offensive security lead at the Dutch company Neo Security. A ShinyHunters spokesperson denied connections with van der Stap.

FBI director Kash Patel said after the Amsterdam arrest that "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest," and in a follow‑up post on X added, "FBI teams are working new leads RIGHT NOW. More arrests are on the table." Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement that since last year an alleged cybercriminal and co‑conspirators have breached more than 140 organizations and taken at least $70 million in extortion payments. Leatherman described the group as often targeting third‑party vendors in cloud‑based platforms and urged other members to speak out, saying "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left."

High‑profile operations: Cl0p site takeover, a Grav CMS flaw, and the FBI portal breach

In recent weeks ShinyHunters drew attention for several disruptive moves. The crew hijacked the darknet website of the cybercriminal group Cl0p by exploiting an unpatched flaw in Grav CMS, and they also carried out a breach of the FBI's "apply.fbijobs[.]gov" portal, stealing around three terabytes of sensitive data, according to the reporting. ShinyHunters has stated it is not seeking a monetary payoff in the FBI case but is applying pressure on the agency to amend what it calls false allegations and to challenge claims the FBI has made about the group's alleged connections with The Com.

The source material describes The Com as a loose‑knit collective notorious for social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, and physical violence; ShinyHunters has disputed agency claims tying it to that collective.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: the report underscores the continuing risk from unpatched third‑party components (the Grav CMS flaw) and the volume of data exfiltration (around three terabytes from the FBI portal), reinforcing the need to monitor vendor ecosystems and patch management for cloud‑facing software.
  • Policymakers and law enforcement partners: the reported Jordan detention and the Amsterdam arrest demonstrate cross‑border cooperation the FBI says it is leveraging to "obtain and execute more leads" and to press for additional arrests, per the director's and assistant director's comments.
  • Affected enterprises and procurement leaders: the FBI's assessment that more than 140 organizations were breached with at least $70 million in extortion payments highlights the financial and reputational stakes tied to third‑party vendors and cloud‑based platforms cited by the bureau.

Security researchers from Sekoia and Beazley Security framed ShinyHunters as a persistent brand that has evolved from progenitor extortion groups — TheDarkOverlord and GnosticPlayers — and emerged publicly around April or May 2020. Enzo Saez and Robert (Bobby) Venal wrote that the group's resilience flows from a near‑modular division of labor: social engineering for initial access, amplification and recruitment from adjacent actors, and monetization under a recognizable brand.

The immediate consequence of the reported detention in Jordan is not only the potential for names and networks to surface but also the law‑enforcement messaging that "more arrests are on the table." As Leatherman put it, arrests and seized infrastructure tend to change the choices available to those inside these networks — a dynamic that, according to the FBI, investigators are trying to accelerate.

Source: The Hacker News / Reuters summary