ShinyHunters hacker reportedly detained in Jordan, aiding FBI

A major blow has been dealt to the notorious ShinyHunters hacking group, with a key member reportedly detained in Jordan and cooperating with the FBI to help locate other members of the extortion gang. The news comes as part of an ongoing crackdown on ShinyHunters following their high-profile cyberattack on the Federal Bureau of Investigation (FBI) in September.

According to sources familiar with the arrest, Saif al-Din Khader, known online as “Rey”, was taken into custody by Jordanian authorities this week. Khader is now working with law enforcement agencies, including the FBI, to identify and locate other alleged co-conspirators within ShinyHunters. By walking investigators through his electronic devices and digital communications, Khader’s cooperation is seen as crucial in ongoing efforts to bring down the extortion gang.

ShinyHunters made headlines earlier this year when they claimed to have breached FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability. They then spread laterally into FBI-managed Amazon Web Services (AWS) GovCloud systems, allegedly stealing between 2TB and 3TB of sensitive data, including information belonging to current and former FBI employees, medical records, and internal services. While the FBI has confirmed it is investigating claims of unauthorized activity, it has not confirmed the volume of stolen data.

The news of Khader’s detention comes as part of a broader crackdown on ShinyHunters. In September, Dutch police arrested 24-year-old Pepijn van der Stap, who was linked to the group and used the online alias “Umbreon”. Following this arrest, the FBI publicly warned other ShinyHunters members to turn themselves in, stating that investigators were still identifying those involved with the group.

The ShinyHunters gang has been a thorn in the side of law enforcement for years, performing massive data theft attacks and extortion campaigns against organizations worldwide. They have targeted cloud-based services, including Salesforce, Google, Cisco, and PornHub, by breaching third-party integration companies and using stolen authentication tokens to access connected environments and steal customer data.

The detention of Khader is seen as a significant development in the ongoing effort to dismantle ShinyHunters. While it remains unclear whether his reported detention has led to the shutdown of ShinyHunters-linked infrastructure, signs of disruption have begun to appear within the operation. A new ShinyHunters data leak site went online on Thursday, suggesting that other members continue to run the extortion operation.

As we’ve seen with previous high-profile hacking groups, arrests and disruptions can often bring about a sense of uncertainty and chaos among remaining members. It’s essential for organizations to remain vigilant in protecting themselves against these types of attacks, particularly when it comes to cloud-based services. By staying informed about emerging threats and best practices in cybersecurity, you can help safeguard your organization from the impact of these malicious operations.


Source: Bleeping Computer — 2026-10-03