Suspected ShinyHunters Hacker "Rey" Detained in Jordan, Reportedly Cooperating With FBI
A suspected member of the ShinyHunters digital extortion collective, who operates under the online alias "Rey" (and also "Hikki-Chan"), has reportedly been detained by authorities in Jordan. According to Reuters, citing three people familiar with the matter, the suspect is Saif al-Din Khader, and two of the sources said he was taken into custody on Tuesday. Two sources also told Reuters that Khader is now cooperating with the FBI and international law enforcement partners, reportedly walking investigators through his electronic devices and digital communications to help identify and locate alleged co-conspirators. Reuters said it could not independently determine the exact circumstances of the detention or Khader's current whereabouts, and that attempts to reach him and his family over the preceding week and a half were unsuccessful.
The development comes roughly two weeks after ShinyHunters claimed responsibility for defacing the FBI's recruitment site, apply.fbijobs.gov, and asserted it had stolen personal data on nearly every FBI employee and applicant. The FBI has not confirmed the Jordan detention specifically, but said it "continues to aggressively investigate" the incident and has "already worked with international partners to arrest multiple" suspects tied to the group.
Incident Details
| Attribute | Value |
|---|---|
| Suspect alias | "Rey" / "Hikki-Chan" |
| Alleged real identity | Saif al-Din Khader |
| Location of detention | Amman area, Jordan |
| Reported detention date | Tuesday (week of September 28, 2026), per two sources |
| Detaining authority | Jordanian authorities |
| Cooperating agency | FBI, with international law enforcement partners |
| Group affiliation | ShinyHunters / Scattered Lapsus$ Hunters (SLSH) alliance |
| First publicly identified | November 2025, by journalist Brian Krebs |
| Related incident | September 2026 defacement and claimed data theft at apply.fbijobs.gov |
| Reporting outlet | Reuters (first reported), syndicated by The Hacker News, BleepingComputer, and others |
Background: Who Is ShinyHunters and "Rey"
ShinyHunters is a financially motivated data-extortion group that has operated since roughly 2020 and, over the past year, has folded into a broader, loosely affiliated collective researchers track as Scattered Lapsus$ Hunters (SLSH) — an alliance drawing members from Scattered Spider, Lapsus$, and ShinyHunters proper. The alliance surfaced publicly in 2025 and has since claimed responsibility for a long string of high-profile breaches, including the Allianz Life incident (2.8 million records), the Salesloft/Drift OAuth token compromise (more than 700 downstream organizations, including Cloudflare, Zscaler, and Palo Alto Networks), the Gainsight and Klue supply-chain OAuth breaches, and direct intrusions at Google, Adidas, Air France, ADT, Zara, 7-Eleven, Carnival Corporation, Panera Bread, Pitney Bowes, and Grubhub, among others.
The alias "Rey" was first publicly tied to Khader in November 2025, when security journalist Brian Krebs identified him as a teenager from Amman, Jordan, allegedly involved with the SLSH alliance. Khader reportedly spoke with Krebs over Signal at the time and claimed he was stepping back from data theft and extortion. He had previously been doxed by the threat-intelligence firm Kela. Rey has separately been linked to the March 2025 breach of Jaguar Land Rover, which leaked Jira issues, source code, employee records, and development logs, and to the group's follow-on September 2025 attack on JLR that forced a multi-week production halt estimated to have cost the automaker more than $220 million.
What Happened: The FBI Jobs Portal Breach
In September 2026, ShinyHunters defaced the FBI's job-applicant site, taking apply.fbijobs.gov and its Special Agent Applicant Portal offline and replacing the page with a message styled after a law-enforcement seizure notice. The group claimed to have exploited a previously unknown vulnerability in Oracle PeopleSoft, the human-resources platform underpinning the portal, and alleged it had exfiltrated personally identifiable and health information on both current and former FBI employees, plus all applicant data. As proof, the group supplied journalists with a sample of roughly 5,000 purported employee records containing names, home addresses, phone numbers, Social Security numbers, dates of birth, duty assignments, and family and emergency-contact details.
The FBI has said attackers did not penetrate its core investigative network or any classified systems, but an internal bureau message acknowledged that exposed data included names, home addresses, cell numbers, FBI email addresses, employee ID numbers, and emergency-contact PII, including Social Security numbers. Reporting has also indicated the exposure extended to thousands of local law-enforcement officials who worked on FBI task forces. Reuters said it was able to partially verify information in at least ten sampled records, though that check alone did not confirm the data originated from compromised FBI systems — meaning some elements of the group's claims remain independently unverified.
FBI Cooperation and Investigation Status
Per Reuters' sourcing, Khader is actively assisting investigators by reviewing his own devices and chat logs with law enforcement to help identify other alleged members of the group. The FBI has declined to confirm the Jordan detention by name but issued a statement saying it continues to investigate the incident "allegedly involving ShinyHunters" and has already coordinated with international partners to arrest multiple suspects connected to the group's broader campaign. No formal charges against Khader have been publicly disclosed as of this writing, and it remains unclear whether he will face prosecution in Jordan, extradition proceedings, or a cooperation arrangement with U.S. authorities.
Impact Assessment
| Impact Area | Description |
|---|---|
| Law enforcement momentum | First confirmed-by-sourcing detention tied directly to the FBI jobs-portal breach; signals active, multi-country pursuit of SLSH-affiliated actors |
| Group operational security | Cooperation from an identified member could expose infrastructure, Telegram handles, and real identities of co-conspirators, pressuring the broader alliance |
| FBI personnel risk | Regardless of the arrest, previously exfiltrated PII on employees, applicants, and task-force officers remains exposed and exploitable for phishing, swatting, or doxing |
| Ongoing SLSH campaigns | The alliance's Salesforce Experience Cloud and OAuth supply-chain campaigns against enterprise victims continue independent of this one detention |
| Attribution confidence | Reuters' sourcing is strong (three independent sources) but unconfirmed on the record by Jordanian or FBI officials; some details may shift as reporting develops |
Recommendations
For Organizations Previously Linked to ShinyHunters/SLSH Campaigns
- Treat this detention as a potential trigger for data dumps or retaliatory leaks; monitor extortion and leak sites closely in the coming weeks.
- Re-verify that OAuth tokens and third-party integrations tied to prior ShinyHunters campaigns (Salesloft/Drift, Gainsight, Klue, Salesforce Experience Cloud guest-user profiles) remain revoked and rotated.
- Review Salesforce org-wide sharing rules and guest-user permissions against the AuraInspector-style scanning techniques the group has used.
For Security Teams
- Update threat-intel watchlists and YARA/Sigma rules with any newly surfaced ShinyHunters/SLSH infrastructure or handles that may emerge from Khader's cooperation.
- Flag spikes in vishing (voice phishing) attempts targeting help desks and SSO administrators — a long-standing SLSH initial-access technique.
- Brief executive teams on the group's documented escalation to physical threats, DDoS, and swatting as extortion leverage; ensure physical-security and HR are looped into incident response planning.
For FBI Employees, Applicants, and Affected Individuals
- Assume personal data submitted via FBIJobs.gov (names, addresses, phone numbers, Social Security numbers, family/emergency-contact details) may be compromised and act accordingly.
- Enroll in identity-theft monitoring and place fraud alerts or credit freezes with major credit bureaus if eligible for agency-provided protection services.
- Be alert to targeted phishing, impersonation, or swatting attempts referencing personal or family details that would not otherwise be public.
Key Takeaways
- Saif al-Din Khader, allegedly "Rey" of ShinyHunters, was reportedly detained in Jordan this week and is cooperating with the FBI to identify other group members, per three Reuters sources.
- Rey's identity has been semi-public since November 2025, when journalist Brian Krebs named him as a Jordan-based teenager tied to the Scattered Lapsus$ Hunters alliance.
- The detention follows ShinyHunters' September 2026 defacement and claimed mass data theft from the FBI's job-applicant portal, exploiting a zero-day in Oracle PeopleSoft.
- The FBI says attackers did not reach classified systems or its core investigative network, but exposed PII — including Social Security numbers — on employees, applicants, and task-force officers tied to the bureau.
- ShinyHunters/SLSH remains an active, prolific threat actor with a broader 2025-2026 track record spanning Salesforce Experience Cloud exploitation, OAuth supply-chain compromises, and extortion of dozens of global enterprises.
- Organizations previously touched by SLSH-linked campaigns should treat this arrest as a possible trigger for retaliatory leaks and revisit token rotation and third-party integration hygiene now.
Sources
- ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members — The Hacker News
- Exclusive-ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say — Reuters (syndicated)
- ShinyHunters hacker reportedly detained in Jordan, aiding FBI — BleepingComputer
- ShinyHunters hacker "Rey," allegedly involved in FBI data theft, detained in Jordan — DataBreaches.Net