A suspected member of the ShinyHunters hacking group, known online as "Rey," has reportedly been detained in Jordan and is cooperating with the FBI to identify and locate other members of the extortion group. The individual has been identified as Saif al-Din Khader, who was reportedly taken into custody on Tuesday. Sources indicate that Khader is assisting the FBI and international law enforcement by providing access to his electronic devices and digital communications.
This reported detention follows an FBI crackdown on ShinyHunters, which intensified after the group claimed a cyberattack on the bureau in September. ShinyHunters alleged they breached FBI systems using an Oracle PeopleSoft zero-day vulnerability, subsequently moving laterally into FBI-managed AWS GovCloud systems. The attackers claimed to have stolen between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, medical and psychiatric records, and internal service data. The FBI confirmed it was investigating claims of unauthorized activity but did not verify any data theft.
Prior to Khader's reported detention, Dutch police arrested a 24-year-old Amsterdam man, identified as Pepijn van der Stap (online alias "Umbreon"), on September 15 in connection with the ShinyHunters investigation. Following this arrest, the FBI publicly urged other ShinyHunters members to surrender, emphasizing that investigators were actively identifying those involved.
On the same day Khader was reportedly detained, signs of disruption emerged within ShinyHunters' operations. An alleged affiliate, who had previously communicated with media about the FBI attack and a recent Clop ransomware data breach, abruptly closed their online messaging account. Subsequently, the ShinyHunters data leak site went offline, and the group's primary representative ceased responding to media inquiries. While a new ShinyHunters data leak site appeared online on Thursday, suggesting continued operations by other members, it remains unclear if these disruptions are directly linked to Khader's detention.
Khader, under the alias "Rey," has been associated with numerous data theft and extortion incidents over the past two years. In January 2025, Rey was among four individuals who claimed responsibility for a breach of Telefónica's internal Jira ticketing system, allegedly stealing approximately 2.3GB of documents and other data. Rey was also linked to the HellCat ransomware operation and a broader series of attacks targeting Jira servers globally. In February 2025, Orange confirmed a cyberattack on its Romanian operations after Rey leaked approximately 6.5GB of stolen data, claiming to have acted independently despite being a HellCat member.
Rey was later associated with the ShinyHunters group and held administrative privileges in Telegram channels operated by "Scattered Lapsus$ Hunters." This group, which emerged in 2025, claimed to comprise former members of Lapsus$, Scattered Spider, and ShinyHunters. Scattered Lapsus$ Hunters took responsibility for a September 2025 cyberattack on Jaguar Land Rover, which caused production halts and over $220 million in losses. Rey was also linked to an earlier March 2025 breach of Jaguar Land Rover, where gigabytes of data, including Jira issues, source code, and employee information, were leaked.
In November 2025, security journalist Brian Krebs identified Rey as Saif Al-Din Khader after analyzing infostealer logs and directly communicating with Khader. Khader reportedly claimed at the time that he was distancing himself from Scattered Lapsus$ Hunters and had been cooperating with law enforcement since at least June, stating he had not engaged in corporate breaches or extortion since September. These claims could not be independently verified.
The ShinyHunters group has a history of large-scale data theft and extortion campaigns, frequently targeting Salesforce and other cloud SaaS environments. Their operations have been linked to breaches at Google, Cisco, and PornHub, often involving the compromise of third-party integration companies and the use of stolen authentication tokens to access connected SaaS environments. The group was also behind a May data-theft attack on Instructure Canvas, which led to significant platform outages and an eventual "agreement" with the threat actors to prevent data leakage. Numerous arrests have been made in connection with ShinyHunters' activities, including those related to Snowflake data-theft attacks, PowerSchool breaches, and the operation of the Breached v2 hacking forum.






