Reported Detention of “Rey” Adds Pressure to the ShinyHunters Network
Saif al-Din Khader 'Rey' reportedly detained in Jordan aiding FBI ShinyHunters probe amid unverified FBI hack claims and leak-site disruption.
Illustrative image generated with AI
Sources say Saif al-Din Khader was taken into custody in Jordan
Jordanian authorities reportedly detained Saif al-Din Khader, known online as “Rey,” during the week of a report examining law-enforcement activity against ShinyHunters.
Two sources cited by Reuters said the detention occurred on Tuesday. They described Khader as a suspected member of ShinyHunters, an extortion group associated with international data-theft campaigns.
Sources familiar with the arrest also told Reuters that Khader was assisting the FBI and other international law-enforcement agencies. The reported objective is to identify and locate additional alleged participants in the group.
One source said Khader was explaining information found on his electronic devices and helping investigators understand his digital communications. These remain attributed accounts: neither the detention nor the reported cooperation was independently confirmed by BleepingComputer, which published its report on October 3, 2026, at 03:09 PM.
The report places the action in Jordan within a wider FBI effort to identify ShinyHunters participants after the group claimed it had compromised bureau systems. It does not establish how investigators located Khader or what evidence may have resulted from his reported assistance.
ShinyHunters-linked services went quiet, but causation is unproven
Changes affecting ShinyHunters communications appeared on Tuesday, the same day Khader was reportedly taken into custody.
An alleged affiliate closed an online messaging account previously used to communicate with BleepingComputer and other media outlets. That account had discussed both the claimed attack on the FBI and a recent Clop ransomware data breach.
The ShinyHunters data-leak site subsequently became unavailable. The group’s principal media contact also stopped responding to BleepingComputer and Reuters. BleepingComputer said it separately contacted ShinyHunters about the reported detention but received no answer before publication.
The timing alone does not connect these developments. The available reporting does not show that law enforcement seized the unavailable infrastructure, that Khader operated the closed account, or that his reported cooperation caused the disruption.
A replacement ShinyHunters data-leak site appeared on Thursday. The report interpreted its return as an indication that other members may still be carrying out extortion activity.
The evidence therefore supports only a narrow assessment: parts of the group’s public-facing operation were disrupted around the reported detention, but ShinyHunters was not shown to have ceased operating. The relationship between the two events remains unclear.
The alleged FBI intrusion has not been independently verified
In September, ShinyHunters told BleepingComputer that it had entered FBI systems by exploiting an alleged Oracle PeopleSoft zero-day vulnerability. The group claimed it then moved laterally into FBI-managed AWS GovCloud systems.
ShinyHunters also asserted that it stole between 2 TB and 3 TB of information. According to the group, the material concerned current and former FBI employees, job applicants, medical and psychiatric information, and records associated with internal services.
Those are threat-actor claims rather than independently established findings.
BleepingComputer said it had not verified the alleged zero-day, the reported lateral movement, or the claimed amount of data. The FBI confirmed that it was investigating reports of unauthorized activity but did not confirm that information had been exfiltrated.
The figure of between 2 TB and 3 TB is consequently an unverified storage estimate. It is not a count of affected individuals or compromised records. The cited reporting provides no independently confirmed total for either category.
No CVE identifier, affected Oracle PeopleSoft version, indicator of compromise, detection query, patch instruction, or workaround was provided. The report therefore cannot be used to establish that a particular PeopleSoft release contains a confirmed vulnerability.
The same limitation applies to AWS GovCloud. ShinyHunters claimed it reached FBI-managed systems there, but the available material does not independently demonstrate that the cloud environment was compromised or that an AWS product flaw was involved.
Separate enforcement action had already targeted an alleged member
The reported detention in Jordan follows another law-enforcement action connected to the ShinyHunters investigation.
On September 15, Dutch authorities took a 24-year-old man from Amsterdam into custody as part of their inquiry into the group. The passage reporting that action does not specify the year. KrebsOnSecurity and DataBreaches identified the suspect as Pepijn van der Stap, who previously used the online alias “Umbreon.”
After that arrest, the FBI publicly called on other ShinyHunters participants to surrender. The bureau said investigators were continuing to identify people associated with the operation.
FBI Cyber Division Assistant Director Brett Leatherman said “last week” that arrests could change who was willing to cooperate, while seized infrastructure could help investigators determine who remained active. The report does not provide a calendar date for that statement.
BleepingComputer’s main ShinyHunters contact continued communicating with the publication after van der Stap’s arrest. According to the report, this indicated that van der Stap was not controlling the specific messaging account used for those conversations.
Other arrests have been associated with the ShinyHunters name over the years. The cited examples involve suspects connected to Snowflake data-theft attacks, PowerSchool breaches, and operation of the Breached v2 hacking forum. The report supplies no additional dates or case details for those actions.
Earlier reporting associated Rey with HellCat and Scattered Lapsus$ Hunters
Rey has previously been linked to several data-theft and extortion cases, although the supporting evidence and confirmation level differ among the incidents.
In January 2025, Rey was one of four threat actors who claimed responsibility for compromising Telefónica’s internal Jira ticketing system. The attackers allegedly obtained approximately 2.3 GB of documents, tickets, and other data. Earlier BleepingComputer reporting associated Rey and two of the other actors with the then-new HellCat ransomware operation.
Rey was later connected to a broader series of attacks targeting Jira servers at organizations around the world.
In February 2025, Orange confirmed a cyberattack affecting its Romanian operations after Rey leaked approximately 6.5 GB of data. Rey told BleepingComputer that he belonged to HellCat but had conducted the Orange intrusion independently.
He was subsequently linked to ShinyHunters and observed with administrative privileges in Telegram channels operated by Scattered Lapsus$ Hunters. First seen in 2025, that group claimed to include former members of Lapsus$, Scattered Spider, and ShinyHunters.
Scattered Lapsus$ Hunters claimed responsibility for the September 2025 cyberattack on Jaguar Land Rover. The incident forced the automaker to stop production for weeks and ultimately cost it more than $220 million, according to the report.
Rey was also linked to a March 2025 breach of Jaguar Land Rover. Data leaked in connection with that incident included Jira issues, source code, employee information, and development logs.
In November 2025, security journalist Brian Krebs identified Rey as Saif al-Din Khader. Krebs said the identification was based on information from infostealer logs and direct Signal communications with Khader.
Khader reportedly told Krebs that he was distancing himself from Scattered Lapsus$ Hunters, had cooperated with law enforcement since at least June, and had not conducted corporate intrusions or extortion-related activity since September. Krebs said he could not verify those claims.
Defenders have context, but no incident-specific remediation
The detention report concerns an enforcement operation rather than a technical disclosure. It offers no validated evidence that organizations can use to select a PeopleSoft patch, determine whether a particular version is exposed, or search conclusively for activity associated with the alleged FBI intrusion.
ShinyHunters’ wider operating pattern still provides defensive context. The group has focused on Salesforce and other cloud software-as-a-service environments, with campaigns linked to breaches involving Google, Cisco, and PornHub.
The report says the group commonly targets third-party integration providers and uses stolen authentication tokens to reach connected SaaS environments and extract customer data. That pattern is separate from the unverified allegation involving Oracle PeopleSoft and AWS GovCloud.
BleepingComputer also attributed a major Instructure Canvas data-theft attack in May to ShinyHunters, although the relevant passage does not specify the year. The attack caused significant platform outages. Instructure later reached what the report described as an “agreement” intended to prevent publication of the stolen data.
None of these earlier incidents validates the group’s claims about the FBI. Without affected-version details, technical indicators, or vendor guidance, defenders cannot derive an incident-specific patch or reliable detection procedure from the report alone.
For now, the confirmed scope is limited. Reuters sources reported Khader’s detention and cooperation, while ShinyHunters-linked communications and infrastructure experienced disruption around the same time. Whether those developments will materially reduce the group’s activity has not been established.
Sources
This article is an original reworking based on the sources below.




