The FBI has confirmed that multiple suspects have been arrested in connection with a September cyber incident allegedly involving the ShinyHunters data-theft-and-extortion group.[2][12] In an emailed statement, the bureau said it is aggressively pursuing the case and will spare no resource in bringing those responsible to justice, while declining to name the individuals already in custody.[2]
One of the suspects is widely reported to be Saif al-Din Khader, a Jordanian national known online as Rey, who was detained by Jordanian authorities in late September and is said to be cooperating with FBI investigators.[3][4][13] Khader is alleged to be a member of ShinyHunters and a key figure in the group’s recent compromise of the FBIJobs.gov recruitment portal, where the gang claims to have stolen sensitive personal information on current, former, and prospective FBI employees.[2][3][9] ShinyHunters representatives have characterized that breach as a public-relations stunt rather than a financially motivated extortion attempt, framing it as a way to challenge the bureau’s public statements about the group.[2][9]
Security journalist Brian Krebs previously identified Rey as Khader and described him as the technical operator and public face of a closely related crew known as Scattered LAPSUS$ Hunters.[2] That crew has been linked to the late-August 2025 cyberattack on Jaguar Land Rover that disrupted manufacturing, knocked dealer systems offline, delayed supplier orders, and exposed payroll data for thousands of employees, in what has been described as one of the costliest corporate breaches in UK history.[2]
Khader’s detention came shortly after Dutch police arrested a 24-year-old Amsterdam man described by authorities as one of the alleged leaders of ShinyHunters in a separate but related investigation.[1][8][11] Though officials have not publicly named him, multiple reports identify the suspect as convicted hacker Pepijn van der Stap, who was profiled as a security professional before his past involvement in hacking and extortion came to light.[1][11][14] Van der Stap was arrested on September 15 in a dramatic raid on the offices of cybersecurity firm Neo Security, where he worked as an offensive security lead, while still on supervised release after serving three years of a four-year sentence for previous data-theft and extortion offenses.[1][8][14] Dutch media and Reuters also report that investigators are probing whether the suspect ordered or planned two murders, allegations his legal team has not commented on publicly.[11][15] ShinyHunters has rejected any link to van der Stap, with a representative telling reporters that he has no association with the group and criticizing Dutch police as incompetent.[14][15]
As arrests mounted, FBI Cyber Division assistant director Brett Leatherman issued an unusual video message warning remaining ShinyHunters members that arrests have a way of changing who is willing to talk and urging them to proactively reach out to the bureau.[2][9] Leatherman hinted that investigators are gaining visibility into the gang’s remaining infrastructure and personnel, saying that seized systems have a way of showing us who’s left and cautioning that the longer members stay involved, the more the FBI learns about them.[2][9] The bureau has not publicly confirmed whether it has seized any ShinyHunters servers or whether additional members have contacted investigators in response to the appeal.[2][9][12]
ShinyHunters has built a reputation over several years as a prolific data-theft and extortion operation responsible for intrusions at more than 140 organizations worldwide, including recent attacks on Dutch telecom provider Odido and other high-profile targets.[10][11] In the Odido case, the group claimed to have stolen terabytes of customer and corporate data, prompting regulatory scrutiny and a complex breach response by the carrier and Dutch authorities.[10][15] The group’s tactics typically focus on compromising web applications, cloud services, and employee accounts to quietly exfiltrate large data sets before issuing extortion demands or leaking troves online.[9][11]
For organizations previously targeted by ShinyHunters, the arrests do not immediately eliminate risk, as stolen data may already have been copied, sold, or posted to criminal marketplaces. Security teams at entities affected in incidents such as the FBIJobs portal breach and the Odido hack should continue to assume compromise of exposed personal and credential data, tighten access controls, and monitor closely for follow-on fraud or account takeover.[2][9][10] More broadly, the case underlines how even nominally reformed or dual-hatted security professionals can pose significant insider risk when proper vetting, oversight, and ethical boundaries are not enforced.
References
- Dutch ‘reformed hacker’ arrested in ShinyHunters investigation, police and ex-boss say
- FBI confirms ‘multiple’ arrests related to ShinyHunters hack
- Suspected ShinyHunters hacker detained in Jordan …
- Alleged ShinyHunters Leader Arrested in Jordan
- Dutch Police Arrest Convicted Hacker in ShinyHunters …
- ShinyHunters Defiant After FBI Calls on Members to Come …
- Dutch authorities arrest suspected ShinyHunters member in Odido hack probe
- techcrunch.com › 2026/09/29 › dutch-police-arrestDutch police arrest ShinyHunters hacker accused of planning …
- FBI Confirms Multiple Arrests in ShinyHunters Investigation
- Exclusive-ShinyHunters hacker in FBI data theft detained …
- Dutch police arrest security professional in ShinyHunters investigation
- ShinyHunters suspect also investigated for alleged murder orders, Dutch media report
