ShinyHunters suspect Rey held in Jordan, aiding FBI

Jordan has detained alleged ShinyHunters member Saif al-Din Khader, known online as “Rey,” who is reportedly cooperating with the FBI to identify other members of the digital extortion group linked to a recent U.S. law-enforcement data theft claim.[1][3][4][5][6][10][13] The arrest marks a significant development in the investigation into ShinyHunters, which has claimed responsibility for stealing personnel information on FBI employees in one of its highest-profile operations to date.[1][2][5][11]

Khader was taken into custody by Jordanian authorities on September 29, according to three people familiar with the matter cited by Reuters, with sources saying he is now assisting U.S. and international law enforcement in locating other ShinyHunters operatives.[1][3][5][6][10][11] Jordan later confirmed the arrest of a suspect tied to ShinyHunters after reports that the group had targeted FBI systems, while declining to elaborate on his current status or possible extradition proceedings.[2][10] The FBI has acknowledged the ongoing investigation into the alleged breach but has declined to confirm any specific overseas arrest, underscoring the sensitivity of the case and the multi-country nature of the inquiry.[5][6][12]

Rey is not a new name to investigators and researchers tracking ShinyHunters and related crews.[3][8][11] In 2025, independent journalist Brian Krebs reported that Khader, using the handle Rey or ReyXBF, was a key member of “Scattered LAPSUS$ Hunters,” an umbrella-style hacking community assessed to blend tactics and personnel from Scattered Spider, LAPSUS$, and ShinyHunters.[1][4][8][11] That loose collective has been linked by researchers to English-speaking cybercrime groups that specialize in account takeover, data theft, and aggressive extortion demands against large organizations.[1][8][11]

ShinyHunters itself has built a reputation as a prolific data-theft and extortion outfit, breaching corporate systems, stealing large troves of sensitive information, and then advertising the data on underground markets and leak sites.[1][4][5][13] Most recently, the group claimed it had compromised systems tied to FBI employment records and obtained personnel information for FBI staff, a boast that elevated the case from typical corporate breach to a national-security concern.[1][5][6][11] While authorities have not publicly verified the full scope of the FBI-related intrusion, multiple arrests tied to ShinyHunters activity in recent years suggest law enforcement pressure on the group has been mounting even before Khader’s reported detention.[1][5][6]

Threat-intelligence trackers say ShinyHunters-linked activity has increasingly focused on exploiting high-severity software flaws in enterprise environments as part of broader campaigns.[14][15] Google-owned Mandiant has warned that a cluster it tracks as UNC6240, linked to ShinyHunters, has been mass exploiting CVE-2026-35273, a CVSS 9.8 unauthenticated remote-code-execution vulnerability in Oracle PeopleSoft that can give attackers sweeping control over targeted systems.[15] Separate reporting has associated ShinyHunters with attacks or attempted exploitation involving Oracle E-Business Suite under CVE-2025-61882, Cisco Unified Communications under CVE-2026-20045, and credential-stuffing and OAuth abuse against Snowflake environments, illustrating how the group and its affiliates blend vulnerability exploitation with stolen or weak credentials to gain initial access.[14]

For defenders, Khader’s reported cooperation may eventually yield valuable insight into ShinyHunters’ internal structure, tooling, and preferred attack paths, but the broader risk landscape the group operates in will remain even if one suspected key member is off the field.[1][5][6] Organizations running Oracle PeopleSoft, Oracle E-Business Suite, Cisco Unified Communications, or Snowflake should treat the ShinyHunters-linked campaigns as a reminder to patch known high-impact vulnerabilities such as CVE-2026-35273 and related flaws promptly, validate that exposed services are not reachable from the internet, and ensure multi-factor authentication is enforced on administrative and remote-access accounts.[14][15] Combined with tighter monitoring of data access and exfiltration patterns, those measures can help reduce the window of opportunity for extortion-focused actors like ShinyHunters, regardless of how the investigation into Rey ultimately unfolds.[1][14][15]

References

  1. ShinyHunters hacker in FBI data theft detained in Jordan …
  2. Jordan says suspected ShinyHunters hacker arrested after FBI data theft claim
  3. ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
  4. ShinyHunters hacker reportedly detained in Jordan, aiding FBI
  5. ShinyHunters Hacker “Rey” Arrested in Jordan, Reportedly …
  6. ShinyHunters Hacker Helping FBI
  7. The Hacker News | #1 Trusted Source for Cybersecurity News
  8. ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau: Reuters
  9. Key ShinyHunters Suspect Detained in Jordan, Reportedly Cooperating With FBI After FBI Data Theft
  10. FBI-hacker ShinyHunters in de kraag gevat
  11. Latest ShinyHunters news – BleepingComputer
  12. Shinyhunters
  13. ShinyHunters (Threat actor) – ZeroHour

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply