A suspected member of the ShinyHunters cyber extortion group has allegedly been detained in Jordan and is cooperating with U.S. authorities, according to Reuters, which cited three people familiar with the matter.
The suspect, known online as “Rey” and “ReyXBF,” has been identified as Saif al-Din Khader. Sources said he was taken into custody on September 29, 2026, and is now working with the FBI and other law enforcement agencies to help identify additional members of the hacking group. One source described his cooperation as critical to ongoing efforts to arrest other suspected hackers.
Khader has previously been linked to several major cybercrime communities. In a November 2025 report, security journalist Brian Krebs identified Rey as one of three administrators of Scattered LAPSUS$ Hunters, a group believed to bring together members associated with Scattered Spider, LAPSUS$, and ShinyHunters.
Krebs also reported that Rey had previously administered the data leak site associated with the Hellcat ransomware group and later took control of the latest version of BreachForums in 2024. Khader had also said that he had been cooperating with law enforcement since at least June 2025.
The reported detention comes shortly after Dutch authorities arrested a 24-year-old Amsterdam man over alleged involvement in ShinyHunters-related cyber operations. His identity was not officially disclosed, although independent reporting identified him as Pepijn van der Stap, a former hacker who had worked as an offensive security lead at Dutch cybersecurity company Neo Security. A ShinyHunters spokesperson later denied any connection to van der Stap.
Following the arrest, FBI Director Kash Patel said FBI teams were working with international partners to pursue additional leads. In a subsequent statement, Patel said more arrests remained possible as investigators continued to follow information obtained from the case.
ShinyHunters has also attracted attention in recent weeks after allegedly taking control of the dark-web site operated by rival cybercriminal group Cl0p. The attackers reportedly exploited an unpatched vulnerability in Grav CMS to gain access. The group has also claimed responsibility for breaching the FBI’s apply.fbijobs.gov portal and stealing roughly three terabytes of sensitive information.
The group has said it is not seeking a financial ransom from the FBI. Instead, it claims the operation was intended to pressure the agency over what ShinyHunters described as false allegations and statements concerning its alleged connections to The Com, a loosely organized cybercrime network associated with social engineering, phishing, SIM swapping, extortion and other criminal activity.
FBI Cyber Division Assistant Director Brett Leatherman has said that ShinyHunters and its alleged associates have breached more than 140 organizations since last year and obtained at least $70 million through extortion payments. He said the group frequently targets third-party vendors operating cloud-based platforms, stealing sensitive information and threatening victims with publication.
Leatherman also urged other suspected members of the group to cooperate with investigators, warning that arrests and the seizure of criminal infrastructure could expose additional individuals involved in the operations.
Researchers from Sekoia and Beazley Security recently traced ShinyHunters’ origins to earlier cybercriminal groups including TheDarkOverlord and GnosticPlayers, which were involved in data theft, extortion and leak operations. The ShinyHunters name first emerged publicly around April or May 2020.
The researchers said that, over the years, ShinyHunters has evolved from a relatively small group trading stolen databases into a broader cybercrime brand and business model that has continued despite arrests, indictments and the shutdown of criminal forums.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
They described the group’s resilience as being driven less by a single leader and more by a modular structure involving different actors responsible for initial access, social engineering, recruitment and monetization under the ShinyHunters name.
ShinyHunters Suspect Allegedly Detained in Jordan, Cooperating With FBI



