ShinyHunters suspect detained in Jordan as FBI expands cybercrime crackdown
Authorities in Jordan detained Saif al-Din Khader, a suspected ShinyHunters administrator, who is now cooperating with the FBI to identify other group members.
Jordanian authorities have detained Saif al-Din Khader, a suspected high-ranking member of the ShinyHunters cybercrime collective, marking a significant escalation in international efforts to dismantle the group. Khader, known online as Rey or ReyXBF, was taken into custody on September 29, 2026, and is reportedly assisting the U.S. Federal Bureau of Investigation (FBI) in identifying and locating other operatives within the network.
What happened
The detention of Khader follows a series of rapid developments targeting the ShinyHunters infrastructure and leadership. According to reports citing three individuals familiar with the matter, Khader’s cooperation is considered critical to ongoing investigations. This move comes just one week after the arrest of Pepijn van der Stap, a 24-year-old offensive security lead at the Dutch firm Neo Security, who independent reports identified as an alleged leader within the group. While a ShinyHunters spokesperson denied any connection to van der Stap, FBI Director Kash Patel confirmed that teams are actively pursuing new leads generated from these arrests.
Khader is not a new name in cybersecurity circles. In November 2025, journalist Brian Krebs identified him as one of three administrators of Scattered LAPSUS$ Hunters (SLH), a coalition merging tactics from Scattered Spider, LAPSUS$, and ShinyHunters. Khader had previously administered data leak sites for the Hellcat ransomware group and the latest iteration of BreachForums. He reportedly told Krebs he had been cooperating with law enforcement since June 2025, suggesting his recent detention may formalize an existing informal arrangement.
The ShinyHunters group has recently drawn intense scrutiny for high-profile breaches, including the hijacking of the Cl0p darknet website via an unpatched Grav CMS flaw and the theft of approximately three terabytes of data from the FBI’s job application portal. The group claims these actions were not for monetary gain but to pressure the FBI to retract allegations linking them to The Com, a violent cybercrime collective involved in kidnapping and physical harm.
How it works
ShinyHunters operates less like a traditional hierarchical criminal organization and more like a modular business model. Researchers from Sekoia and Beazley Security describe the group as a brand that has outlived its original founders, evolving from a small crew on RaidForums in 2020 into a self-renewing entity. Its resilience stems from a division of labor where different actors handle specific tasks: social engineers gain initial access, adjacent actors amplify the breach, and others handle monetization through extortion.
This modular structure allows the group to absorb arrests and infrastructure seizures without collapsing. When one cell is compromised, others continue operating under the shared brand. The group primarily targets third-party vendors in cloud-based platforms, exploiting weak links in the supply chain to steal sensitive data. They then extort victims by threatening to publish the stolen information, a tactic that has allegedly generated at least $70 million in payments from over 140 organizations since last year.
Key details
- Saif al-Din Khader (alias Rey/ReyXBF) was detained in Jordan on September 29, 2026.
- Khader is cooperating with the FBI to identify other ShinyHunters members.
- Pepijn van der Stap, a Dutch security professional, was arrested last week for alleged involvement.
- ShinyHunters breached the FBI’s job portal, stealing around three terabytes of data.
- The group has allegedly breached over 140 organizations and extracted $70 million in extortion.
- Researchers describe ShinyHunters as a modular brand rather than a fixed group of individuals.
Why it matters
For software developers and security leads, the ShinyHunters case highlights the persistent risk posed by supply chain vulnerabilities. The group’s focus on third-party vendors in cloud platforms means that even robust internal security can be undermined by weaker partners. Understanding that threat actors operate as modular brands helps teams recognize that arresting individual leaders does not immediately eliminate the threat; the underlying business model and technical methods remain active and adaptable.
Furthermore, the sheer volume of data stolen from government and private sectors underscores the importance of data minimization and encryption. With three terabytes taken from a single federal portal, the potential for identity theft and corporate espionage remains high. Teams must assume that breaches are inevitable and focus on reducing the blast radius of any single compromise, particularly in cloud environments where access controls can be complex and prone to misconfiguration.
What you can do
- Audit third-party vendor access to ensure strict least-privilege principles are enforced.
- Review and patch content management systems and cloud platforms for known vulnerabilities like those in Grav CMS.
- Implement multi-factor authentication across all external-facing portals and vendor connections.
- Monitor for leaked credentials and data exposures on darknet forums and breach sites.
- Conduct regular tabletop exercises simulating supply chain compromises to test incident response plans.
- Encrypt sensitive data at rest and in transit to mitigate the impact of potential exfiltration.



