ShinyHunters Operator "Rey" Has Been Detained in Jordan Since September 29 — and Is Reportedly Helping the FBI Identify Other Members

ShinyHunters Operator "Rey" Has Been Detained in Jordan Since September 29 — and Is Reportedly Helping the FBI Identify Other Members

ShinyHunters Operator "Rey" Has Been Detained in Jordan Since September 29 — and Is Reportedly Helping the FBI Identify Other Members

A suspected ShinyHunters operator known online as "Rey" has been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group, Reuters reported, citing three people familiar with the matter. Rey, identified as Saif al-Din Khader (also seen under the alias ReyXBF), was taken into custody on September 29, and sources say he is now walking law enforcement through his electronic devices and digital communications to identify alleged co-conspirators. "His cooperation is critical to ongoing efforts to arrest these hackers," a source told the agency.

The detention is the most personal blow yet to a group under visible strain. Krebs reported in November 2025 that Rey was one of three administrators of Scattered LAPSUS$ Hunters — an assessed amalgamation of Scattered Spider, LAPSUS$ and ShinyHunters — and previously ran the data leak site for the Hellcat ransomware group and the latest incarnation of BreachForums. Dutch police separately arrested a 24-year-old Amsterdam man in mid-September — identified by Krebs and DataBreaches as Pepijn van der Stap, a "reformed" hacker working as an offensive security lead — whom the FBI's Brett Leatherman described as an alleged leader of the group; ShinyHunters denied the connection. Khader told Krebs he had been cooperating with law enforcement since at least June 2025.

The pressure campaign follows the group's hijack of rival gang Cl0p's darknet site via an unpatched Grav CMS flaw and its breach of the FBI's apply.fbijobs.gov portal — ShinyHunters claims 2TB to 3TB of sensitive data after entering through an alleged Oracle PeopleSoft zero-day and moving laterally into FBI-managed AWS GovCloud, a method and volume BleepingComputer has not independently verified. The FBI says the group and its co-conspirators have breached more than 140 organizations and taken at least $70 million in extortion payments since last year, largely by targeting third-party vendors on cloud platforms. FBI director Kash Patel: "FBI teams are working new leads RIGHT NOW. More arrests are on the table."

The operation showed visible disruption the same day Khader was reportedly detained: an affiliate's messaging account went dark, the group's data leak site went offline, and its main representative stopped responding to media questions. By October 1 a new leak site was back online — a reminder, as Sekoia and Beazley Security researchers put it, that ShinyHunters is "less a group than a brand and business model" that absorbs arrests without going quiet. We have tracked this arc from the FBI-breach claim through the PeopleSoft WAF-bypass campaign; the arrests are the third act, not the finale.

What Should You Do?

  1. If ShinyHunters or SLH extorted your organization, preserve all evidence and expect law-enforcement contact — a cooperating insider may surface cases investigators did not know about.
  2. Rotate credentials exposed through third-party vendor breaches. The group's documented monetization model starts with vendor access to cloud platforms, and stolen tokens do not expire just because arrests are on the news.
  3. Re-review third-party access to your cloud estates — who can reset, who can read, which dormant admin paths exist — the hardening that blunts this entire extortion economy.
  4. Do not write the group off. The leak site was back within days of the detention, and prior coverage suggests the brand outlives its members.

The WAF Angle

ShinyHunters' core playbook is social engineering and third-party cloud abuse, not novel web exploitation — no WAF rule stops a help-desk impersonation. But the group's affiliates have shown they will probe whatever edge is exposed: the UNC6240 arm ran Oracle PeopleSoft campaigns with a URL-encoding trick that walked past naive WAF rules, a reminder that internet-facing administrative portals — HR systems included — deserve the same WAF scrutiny as customer applications. The practical edge takeaway is monitoring for credential abuse: impossible-travel logins, session-token reuse, and anomalous API reads from third-party vendor accounts are the observable artifacts of this group's operations, and they are all detectable at the edge long before a leak site posts your name.

Sources