"His cooperation is critical to ongoing efforts to arrest these hackers," a source told Reuters — a terse assessment that, if accurate, places a detained Jordanian suspect at the center of an international effort to dismantle the ShinyHunters extortion operation.
Saif al‑Din Khader (known online as "Rey"): detained in Jordan
Reuters reported that Jordanian authorities detained a suspected ShinyHunters member this week. Two sources named the detainee as Saif al‑Din Khader and said he is known online as "Rey." The sources told Reuters the detention occurred on Tuesday.
Brian Krebs previously reported in November 2025 that Rey was Saif Al‑Din Khader after analyzing infostealer logs and speaking with Khader over Signal; Krebs also reported Khader saying he had been cooperating with law enforcement since at least June, a claim Krebs said he could not verify.
Cooperation with the FBI and international law enforcement
Two sources familiar with the arrest told Reuters that Khader is now assisting the FBI and international partners. One source said Khader was "walking law enforcement through his electronic devices and digital communications" to help identify and locate alleged co‑conspirators. BleepingComputer reported that it contacted ShinyHunters about Rey's reported detention but received no response.
The detention and reported cooperation come amid an FBI enforcement push after ShinyHunters told BleepingComputer in September that it had breached FBI systems. The threat actors claimed they exploited an alleged Oracle PeopleSoft zero‑day vulnerability, spread laterally into FBI‑managed AWS GovCloud systems, and stole between 2TB and 3TB of data, including information related to current and former FBI employees, job applicants, medical and psychiatric records, and internal services. BleepingComputer has not independently verified the zero‑day, lateral movement, or volume of stolen data, and the FBI said it was investigating claims of unauthorized activity without confirming data theft.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadOperational disruptions within ShinyHunters and a new leak site
On the same Tuesday that Reuters reported Khader's detention, BleepingComputer observed signs of disruption in ShinyHunters activity. An alleged ShinyHunters affiliate who had previously communicated with media abruptly shut down their online messaging account. The group's data leak site went offline and the main representative stopped responding to media inquiries from BleepingComputer and Reuters.
Those outages were not definitively tied to the reported detention. Nevertheless, by Thursday a new ShinyHunters data leak site went online, indicating that elements of the extortion operation remain active.
Context: prior arrests and the FBI's public warning
The Reuters and BleepingComputer reporting places this detention against a recent law‑enforcement timeline. On September 15, Dutch police arrested a 24‑year‑old Amsterdam man identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, who had used the alias "Umbreon," in an investigation tied to ShinyHunters.
After that arrest the FBI publicly warned other ShinyHunters members to turn themselves in. FBI Cyber Division Assistant Director Brett Leatherman said, "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left," and added, "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
Rey's alleged track record and ShinyHunters' methods
The individual known as Rey has been linked in reporting to numerous breaches and extortion campaigns over the past two years. Reported incidents tied to Rey include a January 2025 claim of responsibility for a Telefónica Jira breach involving roughly 2.3GB of material, a February 2025 leak of about 6.5GB from Orange's Romanian operations, and involvement in a series of attacks targeting Jira servers globally. Reporting by BleepingComputer linked Rey to HellCat ransomware activity and to Telegram channels operated by "Scattered Lapsus$ Hunters," a group that claimed the September 2025 Jaguar Land Rover attack which halted production and was said to have cost the company more than $220 million.
ShinyHunters more broadly has focused on cloud SaaS environments such as Salesforce, and has been connected in reporting to breaches at Google, Cisco, and PornHub. The gang is reported to commonly target third‑party integration companies and use stolen authentication tokens to access connected SaaS environments and steal customer data. In May, ShinyHunters were linked to a large data‑theft attack on Instructure Canvas that caused platform outages; the company later reached an "agreement" with the threat actors to prevent the data from being leaked online. Over time, multiple arrests have been associated with operations using the ShinyHunters name, including cases tied to Snowflake data theft, PowerSchool breaches, and the Breached v2 forum.
What this means for technologists, law enforcement, and affected organizations
- Technologists and security teams: expect forensic reviews of seized devices and communications to reveal account takeovers and token‑based lateral access patterns consistent with reported ShinyHunters methods; guards against token misuse and third‑party integration risks will remain central to incident response.
- Law enforcement and investigators: the reported cooperation from a detained suspect could accelerate identification of co‑conspirators and infrastructure, building on the Dutch arrest and public warnings already issued by the FBI.
- Affected enterprises and victims: disruptions in ShinyHunters communications and a temporarily offline leak site show one set of operational effects, but the appearance of a new leak site underscores that data‑exposure risks persist until extortion actors are comprehensively disrupted.
Whether a detained and cooperating suspect produces rapid arrests or only incremental leads, the sequence of a Dutch arrest, FBI public warnings, reported detention in Jordan, and continued leak activity paints a picture of a global, multi‑agency effort in motion — one in which seized devices, intercepted communications, and the choice of a suspect to cooperate may determine how much of the ShinyHunters network law enforcement can map and dismantle.
Source: BleepingComputer — "ShinyHunters hacker reportedly detained in Jordan, aiding FBI"




