Press play to start listening
A suspected key member of ShinyHunters known online as “Rey” has been detained in Jordan and is reportedly cooperating with the FBI, days after the hacking group claimed one of its most sensitive breaches yet: the theft of personnel information belonging to FBI employees.
Jordanian authorities detained Saif al-Din Khader this week, according to three people familiar with the case who spoke to Reuters. Two sources said authorities took him into custody Tuesday, and he is now helping the FBI and other law enforcement agencies identify and locate other hackers connected to the group.
The exact circumstances of Khader’s detention and his current location have not been disclosed. The FBI declined to confirm a specific arrest abroad, but said it is continuing to investigate the recent incident allegedly involving ShinyHunters and has already worked with international partners to arrest multiple suspects.
Who Is Rey?
Khader’s alleged identity has been public for almost a year. In November 2025, cybersecurity journalist Brian Krebs identified Rey as a teenager from Amman, Jordan, allegedly involved with Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider and LAPSUS$. Khader reportedly spoke with Krebs over Signal and claimed at the time that he was leaving data theft and extortion behind.

Hackread.com reported on the identification at the time, noting that Rey disputed some of the claims linking him to the group. More recent reporting, however, placed him much closer to ShinyHunters’ operations. Sources cited by Krebs last month described Rey as having taken control of the ShinyHunters brand amid an internal dispute involving Dutch hacker Pepijn van der Stap, also known as Umbreon.
Rey had also been publicly taunting the FBI and rival cybercrime groups. According to Krebs’ report, shortly after the FBI breach became public, an account linked to him posted material referencing the attack and the group’s conflict with Clop. The account was deleted after Krebs contacted Khader’s father seeking another interview.
FBI Breach Put ShinyHunters Under Intense Pressure
The detention follows ShinyHunters’ September attack on the FBI Jobs portal. The group claimed it entered through apply.fbijobs.gov, defaced the site and obtained between 2TB and 3TB of information after accessing other systems.
The FBI confirmed that it was investigating unauthorized activity affecting the jobs portal but has not publicly confirmed the full volume or contents of the data reportedly obtained.
The contents appear particularly sensitive. Reuters reviewed samples containing personally identifiable information, job roles and psychiatric and medical information belonging to FBI personnel. An internal FBI memo reportedly instructed staff to assume every employee may have been exposed.
ShinyHunters claimed it used an Oracle PeopleSoft vulnerability for the attack. Google Threat Intelligence Group and Mandiant separately documented ShinyHunters, tracked as UNC6240, mass-exploiting CVE-2026-35273 against PeopleSoft systems.
The flaw was first exploited as a zero-day mainly against universities before the hackers modified their exploit to bypass WAF rules and expanded attacks into government, healthcare, technology, transportation and other sectors.
Hackread.com later obtained a statement from ShinyHunters saying it had never intended to publish or sell the FBI data. The group described its one-week demand for the FBI to correct statements about its activities as a “marketing campaign,” not an extortion deadline.
From Canvas and Rockstar to Large SaaS Data Theft
The FBI incident followed an aggressive year for ShinyHunters. In May, the group targeted Instructure’s Canvas learning platform, claiming it stole 3.65TB of information connected to nearly 9,000 institutions and roughly 275 million users.
Instructure confirmed exposed information included names, email addresses, student IDs and internal Canvas messages, although the hackers’ larger figures were not independently verified.
The group then defaced Canvas login portals used by hundreds of schools and universities, disrupting access during exams and assignment periods. Instructure later announced that it had reached an agreement with the attackers intended to prevent publication of the stolen information.
Rockstar Games was another target. ShinyHunters claimed in April that it gained access to Rockstar’s Snowflake environment through credentials or tokens exposed following a third-party incident involving Anodot.
Rockstar subsequently confirmed that a limited amount of non-material company information had been accessed through a third-party breach, while saying players and its operations were unaffected.
Google has also documented a much larger ShinyHunters-branded campaign involving voice phishing, fake credential pages and theft from cloud services including Salesforce.
The operations targeted corporate SSO credentials and MFA codes before extracting data from SaaS platforms and using it for extortion. Google tracks several related clusters separately because membership and partnerships within the ShinyHunters infrastructure can change and impersonation is also a concern.
Second Major Detention in Weeks
Khader’s detention follows the September arrest in the Netherlands of Pepijn van der Stap, a previously convicted hacker suspected by Dutch investigators of playing a role in ShinyHunters. The FBI described Van der Stap as one of the group’s alleged leaders, although ShinyHunters denied to Hackread.com that he had any association with them.
The FBI says ShinyHunters and its alleged co-conspirators have breached more than 140 organisations since last year and collected at least $70 million in extortion payments. After the Dutch arrest, FBI Cyber Division Assistant Director Brett Leatherman publicly warned remaining members that arrests and seized infrastructure were providing investigators with new information.
Events this week suggest investigators were already closing in. Reuters lost contact with ShinyHunters through an account previously used by the group on Tuesday. Its dark web site disappeared Wednesday, shortly after the deadline in its dispute with the FBI expired. The operators later attributed the outage to sabotage by rivals and an unrelated disruption.
The latest reporting goes further. Two sources told Reuters that Khader is walking investigators through his electronic devices and communications to help identify other members. One source described his cooperation as important to continuing arrest efforts.
For a group whose membership has often been difficult to define, access to a suspected operator’s devices and communications could give investigators information that public aliases and leak sites cannot. What Khader has provided, whether he faces charges, and whether Jordan intends to extradite him have not been disclosed.

