NEWS

Alleged ShinyHunters Member Reportedly Detained in Jordan, Assisting FBI

Saif al-Din Khader, allegedly a top ShinyHunters figure, was detained in Jordan and is reportedly assisting the FBI after the group's FBI data-breach claims.

Dylan H.

News Desk

October 5, 2026
7 min read
Alleged ShinyHunters Member Reportedly Detained in Jordan, Assisting FBI

Alleged ShinyHunters Figure Detained in Jordan

A teenager identified as Saif al-Din Khader, who operates online under the alias "Rey," was reportedly detained by Jordanian authorities on September 29, 2026, according to three sources familiar with the matter who spoke to Reuters. Khader is said to be cooperating with the FBI and other international law enforcement agencies to help identify and locate remaining members of ShinyHunters, the extortion group he is alleged to have led or co-led.

The detention comes amid an active FBI investigation into a breach the group claims exposed sensitive personal data on nearly every FBI employee — a breach ShinyHunters says it carried out specifically in retaliation against the bureau. The FBI has not confirmed Khader's arrest, his current location, or whether extradition from Jordan is being pursued, and has declined to comment on specific individuals.


Details

AttributeValue
NameSaif al-Din Khader
Alias"Rey"
Alleged roleSenior ShinyHunters member/leader; also tied to Scattered Lapsus$ Hunters
Age/LocationTeenager (reported as 16), residing in Amman, Jordan
DetainedSeptember 29, 2026, by Jordanian authorities
StatusReportedly cooperating with the FBI
Identified byJournalist Brian Krebs, November 2025
Triggering incidentShinyHunters' claimed breach of FBIJobs.gov / FBI personnel data, late September 2026
FBI's broader tallyGroup allegedly tied to breaches of 140+ organizations and roughly $70 million in extortion payments
Related arrest24-year-old Amsterdam resident detained by Dutch authorities on September 15, 2026

What Happened

The FBI Breach and the Retaliation Motive

In late September 2026, ShinyHunters claimed it had breached systems tied to FBIJobs.gov, the bureau's employment portal, allegedly exploiting a vulnerability in Oracle PeopleSoft, the HR software used to process job applications. The group claimed to have stolen 2 to 3 terabytes of data covering current and former FBI employees, applicants, and Justice Department staff, including names, home addresses, phone numbers, dates of birth, Social Security numbers, FBI email addresses, employee ID numbers, and emergency contact information.

As proof, the group sent a sample of 5,000 records to several media outlets, including Reuters and the BBC, both of which reported the sample data appeared to be genuine. The FBI said only that it was "aware of claims regarding unauthorized activity affecting FBIJobs.gov and is investigating," and had not determined whether the point of entry was an FBI system or a third-party vendor supporting the job portal.

ShinyHunters framed the breach as retaliation. In May 2026, the FBI had issued a public service announcement describing the group as cybercriminals who use "real or exaggerated claims of access to sensitive or personal information to prompt payment from victims," often harassing victims and sometimes falsely claiming to hold compromising material. A follow-up IC3 advisory reiterated the warning, adding that ShinyHunters-linked actors have also engaged in swatting. The group reportedly told the FBI it was "offended" by the characterization and demanded the advisory be corrected or withdrawn within a week, insisting "this is not a ransom, coercion, or extortion."

The Detention

Jordanian authorities took Khader into custody on September 29, 2026. Reuters' sources said he is now helping the FBI and partner agencies identify other ShinyHunters members, though the precise terms of that cooperation, his custody location, and next legal steps remain undisclosed. It follows a separate arrest on September 15, 2026, when Dutch police detained a 24-year-old Amsterdam resident — reportedly Pepijn van der Stap, previously convicted in 2023 on related cybercrime charges — described as another ShinyHunters leader.

Background: ShinyHunters' 2025–2026 Campaign

ShinyHunters, active since 2020 and loosely affiliated with the "The Com" cybercrime community and the Scattered Lapsus$ Hunters collective (merging elements of ShinyHunters, Scattered Spider, and Lapsus$), spent much of the past year running a sustained extortion campaign against Salesforce-connected environments. Key milestones include:

  • November 2025 — Compromise of Gainsight-published Salesforce apps via stolen OAuth tokens, affecting 200+ customer instances.
  • March 2026 — A broader campaign against Salesforce Experience Cloud portals, with the group threatening to leak stolen data from hundreds of organizations starting March 14.
  • Cumulatively, the Salesforce-focused campaign is estimated to have touched over 1,000 organizations and claimed roughly 1.5 billion stolen records, including incidents at Carnival Cruise Line, ADT, Medtronic, and companies whose stolen Salesforce/Anodot tokens were reused against Snowflake, Rockstar Games, and Canvas.
  • Earlier high-profile claims attributed to the group include breaches at Ticketmaster, AT&T, McGraw Hill, and 7-Eleven.

The FBI has stated the group's members collectively are tied to breaches at more than 140 organizations and roughly $70 million in extortion proceeds — context that underscores why the bureau has prioritized identifying ShinyHunters' leadership, and why a cooperating insider like Khader could meaningfully accelerate that effort.


Impact Assessment

Impact AreaDescription
Law enforcement data exposureIf verified, the FBI breach would expose personal data of a sensitive federal workforce, with downsizing/safety implications for agents and their families
Investigative leverageKhader's cooperation could expose the identities, infrastructure, and operational history of other ShinyHunters/Scattered Lapsus$ Hunters members
Ongoing extortion riskVictims of the group's Salesforce-linked campaigns (1,000+ organizations claimed) remain exposed regardless of this detention, since the group operates with distributed membership
Attribution uncertaintyThe FBI has not confirmed Khader's arrest or the authenticity of the breach, leaving key facts — extradition status, breach scope, and identity verification — unresolved
Deterrence signalA second arrest in under three weeks (following the September 15 Amsterdam detention) signals active, coordinated international pressure on the group

Recommendations

For Organizations Using Salesforce/SaaS Connected Apps

  • Audit OAuth token grants on third-party connected apps (Gainsight, Drift, and similar) and revoke unused or overly broad scopes.
  • Treat any device-code phishing attempt targeting SaaS admin accounts as a high-priority alert — this remains ShinyHunters' primary initial-access technique.
  • Review vendor security advisories for Salesforce Experience Cloud and PeopleSoft-adjacent HR systems for patch guidance.
  • Do not engage or negotiate directly with extortion demands referencing ShinyHunters — the FBI and IC3 have repeatedly advised against payment, noting claims of access are sometimes exaggerated.
  • Monitor IC3 and FBI advisories for updates on this case, since Khader's cooperation may surface new indicators of compromise tied to past incidents.
  • Current and former federal employees (particularly FBI personnel) should treat unsolicited contact referencing personal details as a potential follow-on social-engineering or swatting attempt, consistent with the IC3 warning.

For Individuals Potentially Affected

  • Federal employees and applicants should monitor for identity-theft indicators (new credit inquiries, SSN misuse) given the claimed exposure of Social Security numbers and home addresses.
  • Report suspicious contact or threats referencing stolen personal data to the FBI's IC3 (ic3.gov) rather than responding directly.

Key Takeaways

  1. Saif al-Din Khader ("Rey"), a teenager from Amman alleged to be a senior ShinyHunters figure, was detained by Jordanian authorities on September 29, 2026, and is reportedly cooperating with the FBI.
  2. The detention follows ShinyHunters' claimed breach of FBIJobs.gov, allegedly exposing 2–3 TB of FBI/DOJ personnel data, which the group framed as retaliation for a May 2026 FBI advisory calling out its extortion tactics.
  3. The FBI has not confirmed Khader's arrest, custody location, or whether the breach itself is authentic — key facts remain unverified pending further disclosure.
  4. This is the second notable ShinyHunters-linked detention in under three weeks, following a September 15 arrest in Amsterdam.
  5. The FBI attributes 140+ organization breaches and roughly $70 million in extortion payments to the broader ShinyHunters/Scattered Lapsus$ Hunters ecosystem over the past year, centered on Salesforce-connected SaaS abuse.
  6. Organizations should continue hardening OAuth/SaaS integrations and refuse direct engagement with extortion demands, regardless of this arrest's outcome.

Sources