NEWS

ShinyHunters Suspect 'Rey' Reportedly Detained in Jordan, Helping FBI Identify Group Members

Suspected ShinyHunters member Saif al-Din Khader ('Rey') was detained in Jordan and is reportedly helping the FBI identify other group members, sources say.

Dylan H.

News Desk

October 4, 2026
8 min read
ShinyHunters Suspect 'Rey' Reportedly Detained in Jordan, Helping FBI Identify Group Members

Suspected ShinyHunters Hacker "Rey" Detained in Jordan, Reportedly Cooperating With FBI

A suspected member of the ShinyHunters digital extortion collective, who operates under the online alias "Rey" (and also "Hikki-Chan"), has reportedly been detained by authorities in Jordan. According to Reuters, citing three people familiar with the matter, the suspect is Saif al-Din Khader, and two of the sources said he was taken into custody on Tuesday. Two sources also told Reuters that Khader is now cooperating with the FBI and international law enforcement partners, reportedly walking investigators through his electronic devices and digital communications to help identify and locate alleged co-conspirators. Reuters said it could not independently determine the exact circumstances of the detention or Khader's current whereabouts, and that attempts to reach him and his family over the preceding week and a half were unsuccessful.

The development comes roughly two weeks after ShinyHunters claimed responsibility for defacing the FBI's recruitment site, apply.fbijobs.gov, and asserted it had stolen personal data on nearly every FBI employee and applicant. The FBI has not confirmed the Jordan detention specifically, but said it "continues to aggressively investigate" the incident and has "already worked with international partners to arrest multiple" suspects tied to the group.


Incident Details

AttributeValue
Suspect alias"Rey" / "Hikki-Chan"
Alleged real identitySaif al-Din Khader
Location of detentionAmman area, Jordan
Reported detention dateTuesday (week of September 28, 2026), per two sources
Detaining authorityJordanian authorities
Cooperating agencyFBI, with international law enforcement partners
Group affiliationShinyHunters / Scattered Lapsus$ Hunters (SLSH) alliance
First publicly identifiedNovember 2025, by journalist Brian Krebs
Related incidentSeptember 2026 defacement and claimed data theft at apply.fbijobs.gov
Reporting outletReuters (first reported), syndicated by The Hacker News, BleepingComputer, and others

Background: Who Is ShinyHunters and "Rey"

ShinyHunters is a financially motivated data-extortion group that has operated since roughly 2020 and, over the past year, has folded into a broader, loosely affiliated collective researchers track as Scattered Lapsus$ Hunters (SLSH) — an alliance drawing members from Scattered Spider, Lapsus$, and ShinyHunters proper. The alliance surfaced publicly in 2025 and has since claimed responsibility for a long string of high-profile breaches, including the Allianz Life incident (2.8 million records), the Salesloft/Drift OAuth token compromise (more than 700 downstream organizations, including Cloudflare, Zscaler, and Palo Alto Networks), the Gainsight and Klue supply-chain OAuth breaches, and direct intrusions at Google, Adidas, Air France, ADT, Zara, 7-Eleven, Carnival Corporation, Panera Bread, Pitney Bowes, and Grubhub, among others.

The alias "Rey" was first publicly tied to Khader in November 2025, when security journalist Brian Krebs identified him as a teenager from Amman, Jordan, allegedly involved with the SLSH alliance. Khader reportedly spoke with Krebs over Signal at the time and claimed he was stepping back from data theft and extortion. He had previously been doxed by the threat-intelligence firm Kela. Rey has separately been linked to the March 2025 breach of Jaguar Land Rover, which leaked Jira issues, source code, employee records, and development logs, and to the group's follow-on September 2025 attack on JLR that forced a multi-week production halt estimated to have cost the automaker more than $220 million.

What Happened: The FBI Jobs Portal Breach

In September 2026, ShinyHunters defaced the FBI's job-applicant site, taking apply.fbijobs.gov and its Special Agent Applicant Portal offline and replacing the page with a message styled after a law-enforcement seizure notice. The group claimed to have exploited a previously unknown vulnerability in Oracle PeopleSoft, the human-resources platform underpinning the portal, and alleged it had exfiltrated personally identifiable and health information on both current and former FBI employees, plus all applicant data. As proof, the group supplied journalists with a sample of roughly 5,000 purported employee records containing names, home addresses, phone numbers, Social Security numbers, dates of birth, duty assignments, and family and emergency-contact details.

The FBI has said attackers did not penetrate its core investigative network or any classified systems, but an internal bureau message acknowledged that exposed data included names, home addresses, cell numbers, FBI email addresses, employee ID numbers, and emergency-contact PII, including Social Security numbers. Reporting has also indicated the exposure extended to thousands of local law-enforcement officials who worked on FBI task forces. Reuters said it was able to partially verify information in at least ten sampled records, though that check alone did not confirm the data originated from compromised FBI systems — meaning some elements of the group's claims remain independently unverified.

FBI Cooperation and Investigation Status

Per Reuters' sourcing, Khader is actively assisting investigators by reviewing his own devices and chat logs with law enforcement to help identify other alleged members of the group. The FBI has declined to confirm the Jordan detention by name but issued a statement saying it continues to investigate the incident "allegedly involving ShinyHunters" and has already coordinated with international partners to arrest multiple suspects connected to the group's broader campaign. No formal charges against Khader have been publicly disclosed as of this writing, and it remains unclear whether he will face prosecution in Jordan, extradition proceedings, or a cooperation arrangement with U.S. authorities.


Impact Assessment

Impact AreaDescription
Law enforcement momentumFirst confirmed-by-sourcing detention tied directly to the FBI jobs-portal breach; signals active, multi-country pursuit of SLSH-affiliated actors
Group operational securityCooperation from an identified member could expose infrastructure, Telegram handles, and real identities of co-conspirators, pressuring the broader alliance
FBI personnel riskRegardless of the arrest, previously exfiltrated PII on employees, applicants, and task-force officers remains exposed and exploitable for phishing, swatting, or doxing
Ongoing SLSH campaignsThe alliance's Salesforce Experience Cloud and OAuth supply-chain campaigns against enterprise victims continue independent of this one detention
Attribution confidenceReuters' sourcing is strong (three independent sources) but unconfirmed on the record by Jordanian or FBI officials; some details may shift as reporting develops

Recommendations

For Organizations Previously Linked to ShinyHunters/SLSH Campaigns

  • Treat this detention as a potential trigger for data dumps or retaliatory leaks; monitor extortion and leak sites closely in the coming weeks.
  • Re-verify that OAuth tokens and third-party integrations tied to prior ShinyHunters campaigns (Salesloft/Drift, Gainsight, Klue, Salesforce Experience Cloud guest-user profiles) remain revoked and rotated.
  • Review Salesforce org-wide sharing rules and guest-user permissions against the AuraInspector-style scanning techniques the group has used.

For Security Teams

  • Update threat-intel watchlists and YARA/Sigma rules with any newly surfaced ShinyHunters/SLSH infrastructure or handles that may emerge from Khader's cooperation.
  • Flag spikes in vishing (voice phishing) attempts targeting help desks and SSO administrators — a long-standing SLSH initial-access technique.
  • Brief executive teams on the group's documented escalation to physical threats, DDoS, and swatting as extortion leverage; ensure physical-security and HR are looped into incident response planning.

For FBI Employees, Applicants, and Affected Individuals

  • Assume personal data submitted via FBIJobs.gov (names, addresses, phone numbers, Social Security numbers, family/emergency-contact details) may be compromised and act accordingly.
  • Enroll in identity-theft monitoring and place fraud alerts or credit freezes with major credit bureaus if eligible for agency-provided protection services.
  • Be alert to targeted phishing, impersonation, or swatting attempts referencing personal or family details that would not otherwise be public.

Key Takeaways

  1. Saif al-Din Khader, allegedly "Rey" of ShinyHunters, was reportedly detained in Jordan this week and is cooperating with the FBI to identify other group members, per three Reuters sources.
  2. Rey's identity has been semi-public since November 2025, when journalist Brian Krebs named him as a Jordan-based teenager tied to the Scattered Lapsus$ Hunters alliance.
  3. The detention follows ShinyHunters' September 2026 defacement and claimed mass data theft from the FBI's job-applicant portal, exploiting a zero-day in Oracle PeopleSoft.
  4. The FBI says attackers did not reach classified systems or its core investigative network, but exposed PII — including Social Security numbers — on employees, applicants, and task-force officers tied to the bureau.
  5. ShinyHunters/SLSH remains an active, prolific threat actor with a broader 2025-2026 track record spanning Salesforce Experience Cloud exploitation, OAuth supply-chain compromises, and extortion of dozens of global enterprises.
  6. Organizations previously touched by SLSH-linked campaigns should treat this arrest as a possible trigger for retaliatory leaks and revisit token rotation and third-party integration hygiene now.

Sources