A Major Blow to ShinyHunters: Suspected Hacker Detained in Jordan, Cooperating with FBI
In a significant development, authorities in Jordan have detained a suspected member of the notorious ShinyHunters hacking group, who is now cooperating with the Federal Bureau of Investigation (FBI) and international law enforcement agencies. The individual, identified as Saif al-Din Khader, also known online as “Rey,” was taken into custody on Tuesday and is providing crucial information to help locate other members of the extortion gang.
The reported detention comes amid an ongoing FBI crackdown on ShinyHunters following a brazen cyberattack on the bureau in September. The group claimed to have breached FBI systems using a zero-day vulnerability in Oracle PeopleSoft, before spreading laterally into FBI-managed AWS GovCloud systems and stealing between 2TB and 3TB of sensitive data.
The stolen data includes personal information belonging to current and former FBI employees, job applicants, medical records, and internal service records. The breach highlights the group’s sophisticated tactics and capabilities in targeting high-profile organizations worldwide. ShinyHunters has been linked to numerous extortion campaigns, including massive data theft attacks on Salesforce, Google, Cisco, and PornHub.
The detention of Khader is a significant blow to the group, which has long evaded law enforcement efforts. According to sources familiar with the investigation, Khader’s cooperation is crucial in identifying and locating other ShinyHunters members. His electronic devices and digital communications are being examined by law enforcement agencies to gather more information on the group’s operations.
The FBI’s crackdown on ShinyHunters has been ongoing since September, with a public warning issued last week urging other group members to turn themselves in. The warning highlighted that investigators were still identifying those involved with the group and emphasized that arrests have a way of changing who is willing to talk.
While it remains unclear whether the reported detention led to the sudden shutdown of ShinyHunters-linked infrastructure, including their data leak site, the development marks a significant setback for the extortion gang. As law enforcement agencies continue to close in on the group, organizations worldwide must remain vigilant against potential attacks and take proactive measures to protect themselves from similar threats.
For individuals and businesses, this incident serves as a reminder of the importance of robust cybersecurity measures and staying informed about emerging threats. By understanding the tactics employed by ShinyHunters and other groups, you can better prepare yourself for potential cyberattacks and minimize the risk of falling victim to their schemes.
Source: Bleeping Computer — 2026-10-03