NEWS

ShinyHunters Hacker Reportedly Detained in Jordan, Aiding FBI

ShinyHunters member "Rey" was reportedly detained in Jordan on Oct. 1 and is cooperating with the FBI to identify other members of the group.

Dylan H.

News Desk

October 3, 2026
8 min read
ShinyHunters Hacker Reportedly Detained in Jordan, Aiding FBI

ShinyHunters Suspect "Rey" Detained in Jordan, Reportedly Cooperating With FBI

A suspected member of the ShinyHunters data-extortion group known online as "Rey" — identified by prior reporting as Saif al-Din Khader — was reportedly detained in Jordan on Tuesday, October 1, 2026, according to Reuters, which cited three sources familiar with the matter. Two of those sources said Khader is now cooperating with the FBI, walking investigators through his devices and digital communications to help identify and locate other alleged members of the group. The detention is the latest development in a monthslong international law-enforcement push against ShinyHunters, which followed the September 15, 2026 arrest of an alleged ShinyHunters leader in Amsterdam and comes weeks after the group publicly claimed to have breached FBI systems and stolen data on current, former, and prospective agency employees.

The FBI has not confirmed a specific arrest abroad but told reporters it is continuing to investigate the alleged FBI breach and has already worked with international partners to take multiple suspects into custody. The exact circumstances of Khader's detention — including which agency currently holds him and whether extradition is being discussed — have not been officially disclosed.


Incident Details

AttributeValue
SuspectSaif al-Din Khader, alias "Rey" / "Hikki-Chan"
Reported detention dateOctober 1, 2026
LocationAmman, Jordan
Reporting agenciesJordanian authorities; FBI involvement reported
StatusReportedly cooperating with FBI against alleged co-conspirators
GroupShinyHunters, part of the "Scattered Lapsus$ Hunters" alliance
Prior public identificationNamed by journalist Brian Krebs in November 2025
Related arrestPepijn van der Stap ("Umbreon"), Amsterdam, September 15, 2026
First reported byReuters (three sources familiar with the matter)

Who Is "Rey"?

"Rey," also using the alias "Hikki-Chan," was publicly doxed by the threat-intelligence firm Kela and later profiled in depth by independent journalist Brian Krebs in November 2025, who identified him as a teenager based in Amman, Jordan, with alleged ties to the Scattered Lapsus$ Hunters alliance — a loose online collective drawing members from ShinyHunters, Scattered Spider, and Lapsus$. At the time, Khader reportedly spoke with Krebs over Signal and claimed he was stepping away from data theft and extortion, telling the reporter he had been cooperating with the FBI since June 2025. That claim of cooperation has resurfaced now that his detention has become public, though it remains unclear whether his 2025 contact with investigators continued uninterrupted or whether this week's detention represents a formal legal escalation.

Rey has been linked by researchers and prior reporting to a string of high-profile intrusions, including the Telefónica Jira breach (January 2025, roughly 2.3GB of data), the Orange Romania breach (February 2025, roughly 6.5GB), and breaches affecting Jaguar Land Rover in both March and September 2025.

How the Detention Reportedly Happened

Reuters' sources did not detail the operational specifics of how Jordanian authorities located or took Khader into custody, and neither Jordanian officials nor the FBI have issued a public statement confirming the detention. The lack of an official announcement is notable given how aggressively ShinyHunters-linked arrests have otherwise been publicized — the Netherlands arrest two weeks earlier was confirmed on the record by Dutch police within days. Analysts tracking the case note this pattern — quiet detention, sourced reporting, no formal charges disclosed yet — is consistent with an active cooperating-witness arrangement, where authorities have an incentive to avoid tipping off remaining group members before further arrests are made.

What Cooperation With the FBI Involves

According to Reuters' sourcing, Khader's cooperation centers on two things: granting investigators access to his devices and chat logs, and helping identify and locate other individuals operating under the ShinyHunters and Scattered Lapsus$ Hunters umbrella. One source described his cooperation as "critical to ongoing efforts to arrest these hackers." Because much of ShinyHunters' membership operates pseudonymously across Telegram and other encrypted channels, an insider with direct knowledge of handles, infrastructure, and chat history would represent a significant intelligence gain for investigators who have spent well over a year chasing a loosely affiliated, high-turnover group.


Why ShinyHunters Matters

ShinyHunters has become one of the most prolific extortion operations tracked by CosmicBytez Labs over the past year, with a breach and extortion cadence that has touched dozens of organizations across retail, telecom, healthcare, automotive, and — most recently — federal law enforcement itself.

Impact AreaDescription
Breach scaleLinked to breaches at 140+ organizations and an estimated $70 million-plus in extortion payments since 2025, per Dutch police statements tied to the related Amsterdam arrest
Federal exposureGroup claimed in September 2026 to have exploited an Oracle PeopleSoft flaw to steal 2-3TB of FBI data, including employee and applicant records and alleged medical/psychiatric files
Extortion escalationSeparately claimed to have breached the Clop ransomware gang's own leak site and threatened to extort Clop, an unusual extortion-of-an-extortionist move
Named prior victimsSalesforce customer environments, Google, Cisco, Pornhub, Instructure Canvas, Ticketmaster, Telefónica, Orange Romania, Jaguar Land Rover, and numerous Snowflake customers
Attribution difficultyPseudonymous, loosely affiliated membership (Scattered Lapsus$ Hunters) makes the group resilient to single arrests — underscoring why insider cooperation matters

This detention follows the September 15 arrest of a 24-year-old Amsterdam man identified by press reporting as Pepijn van der Stap, held on suspicion of participating in a criminal organization tied to ShinyHunters. Taken together, the two cases suggest the FBI and allied agencies are pursuing a multi-front strategy: arresting suspected organizers while simultaneously flipping lower-tier or disillusioned members into cooperating witnesses.


Recommendations

For Organizations Previously Named by ShinyHunters

  • Treat any ShinyHunters claim of data theft as credible until proven otherwise — the group has a documented track record of following through on extortion threats with actual data dumps
  • Review third-party and SaaS-platform access logs (Salesforce, Oracle, Snowflake-connected environments) for anomalous bulk data pulls matching the group's known TTPs
  • Preserve logs and forensic artifacts now — active law-enforcement cooperation from a detained member raises the likelihood of follow-on subpoenas or evidence requests tied to historical intrusions

For Security Teams

  • Monitor for secondary extortion attempts; insider cooperation inside ShinyHunters may prompt remaining members to accelerate monetization of already-stolen data before further arrests disrupt operations
  • Continue hardening against the group's known initial-access patterns — social engineering of help-desk and IT staff, abuse of SaaS OAuth tokens, and exploitation of unpatched enterprise application flaws (e.g., the alleged Oracle PeopleSoft issue used against the FBI)
  • Track CISA, FBI, and Europol advisories for updated indicators as cooperating-witness intelligence potentially surfaces new infrastructure or affiliate identities

For Individuals Potentially Affected

  • Anyone who received a notification tied to a confirmed ShinyHunters-linked breach (Ticketmaster, Pornhub, Telefónica, Jaguar Land Rover, and others) should assume personal data remains at risk of resale or secondary extortion regardless of this arrest
  • Enable credit monitoring or fraud alerts where offered, and remain alert to phishing that references breached personal details with added urgency or legitimacy

Key Takeaways

  1. A suspect using the alias "Rey" — reportedly Saif al-Din Khader — was detained in Jordan on October 1, 2026, and is reportedly cooperating with the FBI.
  2. Cooperation reportedly includes providing access to devices/communications and helping identify other ShinyHunters and Scattered Lapsus$ Hunters members.
  3. The detention follows the September 15, 2026 arrest of an alleged ShinyHunters leader in Amsterdam, suggesting a coordinated, multi-country enforcement push.
  4. ShinyHunters claimed in September 2026 to have breached the FBI itself via an alleged Oracle PeopleSoft flaw, stealing 2-3TB of employee and applicant data.
  5. Neither Jordanian authorities nor the FBI have officially confirmed the detention, which investigators may be deliberately keeping low-profile while pursuing additional suspects.
  6. Organizations and individuals previously named in ShinyHunters breaches should not assume this arrest reduces their risk — stolen data already circulating remains exploitable regardless of ongoing prosecutions.

Sources