Alleged ShinyHunters Figure Detained in Jordan
A teenager identified as Saif al-Din Khader, who operates online under the alias "Rey," was reportedly detained by Jordanian authorities on September 29, 2026, according to three sources familiar with the matter who spoke to Reuters. Khader is said to be cooperating with the FBI and other international law enforcement agencies to help identify and locate remaining members of ShinyHunters, the extortion group he is alleged to have led or co-led.
The detention comes amid an active FBI investigation into a breach the group claims exposed sensitive personal data on nearly every FBI employee — a breach ShinyHunters says it carried out specifically in retaliation against the bureau. The FBI has not confirmed Khader's arrest, his current location, or whether extradition from Jordan is being pursued, and has declined to comment on specific individuals.
Details
| Attribute | Value |
|---|---|
| Name | Saif al-Din Khader |
| Alias | "Rey" |
| Alleged role | Senior ShinyHunters member/leader; also tied to Scattered Lapsus$ Hunters |
| Age/Location | Teenager (reported as 16), residing in Amman, Jordan |
| Detained | September 29, 2026, by Jordanian authorities |
| Status | Reportedly cooperating with the FBI |
| Identified by | Journalist Brian Krebs, November 2025 |
| Triggering incident | ShinyHunters' claimed breach of FBIJobs.gov / FBI personnel data, late September 2026 |
| FBI's broader tally | Group allegedly tied to breaches of 140+ organizations and roughly $70 million in extortion payments |
| Related arrest | 24-year-old Amsterdam resident detained by Dutch authorities on September 15, 2026 |
What Happened
The FBI Breach and the Retaliation Motive
In late September 2026, ShinyHunters claimed it had breached systems tied to FBIJobs.gov, the bureau's employment portal, allegedly exploiting a vulnerability in Oracle PeopleSoft, the HR software used to process job applications. The group claimed to have stolen 2 to 3 terabytes of data covering current and former FBI employees, applicants, and Justice Department staff, including names, home addresses, phone numbers, dates of birth, Social Security numbers, FBI email addresses, employee ID numbers, and emergency contact information.
As proof, the group sent a sample of 5,000 records to several media outlets, including Reuters and the BBC, both of which reported the sample data appeared to be genuine. The FBI said only that it was "aware of claims regarding unauthorized activity affecting FBIJobs.gov and is investigating," and had not determined whether the point of entry was an FBI system or a third-party vendor supporting the job portal.
ShinyHunters framed the breach as retaliation. In May 2026, the FBI had issued a public service announcement describing the group as cybercriminals who use "real or exaggerated claims of access to sensitive or personal information to prompt payment from victims," often harassing victims and sometimes falsely claiming to hold compromising material. A follow-up IC3 advisory reiterated the warning, adding that ShinyHunters-linked actors have also engaged in swatting. The group reportedly told the FBI it was "offended" by the characterization and demanded the advisory be corrected or withdrawn within a week, insisting "this is not a ransom, coercion, or extortion."
The Detention
Jordanian authorities took Khader into custody on September 29, 2026. Reuters' sources said he is now helping the FBI and partner agencies identify other ShinyHunters members, though the precise terms of that cooperation, his custody location, and next legal steps remain undisclosed. It follows a separate arrest on September 15, 2026, when Dutch police detained a 24-year-old Amsterdam resident — reportedly Pepijn van der Stap, previously convicted in 2023 on related cybercrime charges — described as another ShinyHunters leader.
Background: ShinyHunters' 2025–2026 Campaign
ShinyHunters, active since 2020 and loosely affiliated with the "The Com" cybercrime community and the Scattered Lapsus$ Hunters collective (merging elements of ShinyHunters, Scattered Spider, and Lapsus$), spent much of the past year running a sustained extortion campaign against Salesforce-connected environments. Key milestones include:
- November 2025 — Compromise of Gainsight-published Salesforce apps via stolen OAuth tokens, affecting 200+ customer instances.
- March 2026 — A broader campaign against Salesforce Experience Cloud portals, with the group threatening to leak stolen data from hundreds of organizations starting March 14.
- Cumulatively, the Salesforce-focused campaign is estimated to have touched over 1,000 organizations and claimed roughly 1.5 billion stolen records, including incidents at Carnival Cruise Line, ADT, Medtronic, and companies whose stolen Salesforce/Anodot tokens were reused against Snowflake, Rockstar Games, and Canvas.
- Earlier high-profile claims attributed to the group include breaches at Ticketmaster, AT&T, McGraw Hill, and 7-Eleven.
The FBI has stated the group's members collectively are tied to breaches at more than 140 organizations and roughly $70 million in extortion proceeds — context that underscores why the bureau has prioritized identifying ShinyHunters' leadership, and why a cooperating insider like Khader could meaningfully accelerate that effort.
Impact Assessment
| Impact Area | Description |
|---|---|
| Law enforcement data exposure | If verified, the FBI breach would expose personal data of a sensitive federal workforce, with downsizing/safety implications for agents and their families |
| Investigative leverage | Khader's cooperation could expose the identities, infrastructure, and operational history of other ShinyHunters/Scattered Lapsus$ Hunters members |
| Ongoing extortion risk | Victims of the group's Salesforce-linked campaigns (1,000+ organizations claimed) remain exposed regardless of this detention, since the group operates with distributed membership |
| Attribution uncertainty | The FBI has not confirmed Khader's arrest or the authenticity of the breach, leaving key facts — extradition status, breach scope, and identity verification — unresolved |
| Deterrence signal | A second arrest in under three weeks (following the September 15 Amsterdam detention) signals active, coordinated international pressure on the group |
Recommendations
For Organizations Using Salesforce/SaaS Connected Apps
- Audit OAuth token grants on third-party connected apps (Gainsight, Drift, and similar) and revoke unused or overly broad scopes.
- Treat any device-code phishing attempt targeting SaaS admin accounts as a high-priority alert — this remains ShinyHunters' primary initial-access technique.
- Review vendor security advisories for Salesforce Experience Cloud and PeopleSoft-adjacent HR systems for patch guidance.
For Security and Legal Teams
- Do not engage or negotiate directly with extortion demands referencing ShinyHunters — the FBI and IC3 have repeatedly advised against payment, noting claims of access are sometimes exaggerated.
- Monitor IC3 and FBI advisories for updates on this case, since Khader's cooperation may surface new indicators of compromise tied to past incidents.
- Current and former federal employees (particularly FBI personnel) should treat unsolicited contact referencing personal details as a potential follow-on social-engineering or swatting attempt, consistent with the IC3 warning.
For Individuals Potentially Affected
- Federal employees and applicants should monitor for identity-theft indicators (new credit inquiries, SSN misuse) given the claimed exposure of Social Security numbers and home addresses.
- Report suspicious contact or threats referencing stolen personal data to the FBI's IC3 (ic3.gov) rather than responding directly.
Key Takeaways
- Saif al-Din Khader ("Rey"), a teenager from Amman alleged to be a senior ShinyHunters figure, was detained by Jordanian authorities on September 29, 2026, and is reportedly cooperating with the FBI.
- The detention follows ShinyHunters' claimed breach of FBIJobs.gov, allegedly exposing 2–3 TB of FBI/DOJ personnel data, which the group framed as retaliation for a May 2026 FBI advisory calling out its extortion tactics.
- The FBI has not confirmed Khader's arrest, custody location, or whether the breach itself is authentic — key facts remain unverified pending further disclosure.
- This is the second notable ShinyHunters-linked detention in under three weeks, following a September 15 arrest in Amsterdam.
- The FBI attributes 140+ organization breaches and roughly $70 million in extortion payments to the broader ShinyHunters/Scattered Lapsus$ Hunters ecosystem over the past year, centered on Salesforce-connected SaaS abuse.
- Organizations should continue hardening OAuth/SaaS integrations and refuse direct engagement with extortion demands, regardless of this arrest's outcome.
Sources
- The Record — Alleged ShinyHunters member detained in Jordan, assisting law enforcement
- SecurityWeek — Alleged ShinyHunters Leader Arrested in Jordan
- CBS News — Suspected ShinyHunters hacker detained in Jordan, cooperating with FBI, sources say
- CBS News — Cybercriminal group claims it stole FBI personnel and applicant data