Oct 04, 2026 · 8 min read
ShinyHunters Hacker 'Rey' Reportedly Held in Jordan, Aiding FBI
Reuters sources say Jordan detained Saif al-Din Khader, the teenager known as Rey, on September 29, 2026, and that he is helping the FBI find the rest of ShinyHunters. Neither Jordan nor the FBI has confirmed it, and a new leak site went up two days later.
Eleven days after ShinyHunters defaced the FBI's job application site, the teenager that sources have named as its new boss is reportedly in custody and talking. According to a Reuters report published October 3, Jordanian authorities detained Saif al-Din Khader, alias Rey, and two sources said "he is helping the FBI and global law enforcement locate the other hackers in the group."
It is the second reported ShinyHunters arrest in three weeks, and sources told KrebsOnSecurity that Rey tried to frame the first man arrested. For anyone whose records ShinyHunters leaked, neither arrest takes the data back.
Key Takeaways
- Reuters, citing three unnamed sources, reported on October 3, 2026 that Jordanian authorities detained Saif al-Din Khader, known as Rey, with two sources saying he was taken into custody on Tuesday, which was September 29.
- One source said Khader is "walking law enforcement through his electronic devices and digital communications" to help find his alleged accomplices, while the FBI declined to comment on any specific arrest abroad.
- KrebsOnSecurity identified Rey as Khader, a teenager from Amman, in November 2025 and described him as one of three administrators of the Scattered LAPSUS$ Hunters Telegram channel and a former admin of the Hellcat ransomware leak site.
- Dutch police arrested a 24 year old Amsterdam man, identified by KrebsOnSecurity as Pepijn van der Stap (Umbreon), on September 15, 2026 in a separate ShinyHunters investigation.
- A new ShinyHunters data leak site went online on Thursday, October 1, which BleepingComputer said suggests other members continue to run the extortion operation.
What Happened in Jordan?
Jordanian authorities detained Khader this week, according to three sources who spoke to Reuters, and two said it happened on Tuesday. The story ran on Saturday, October 3, which puts that Tuesday on September 29, 2026. Reuters "could not immediately determine the circumstances of Khader's detention or where he is being held."
One source said Khader is walking investigators through his devices and digital communications. "His cooperation is critical to ongoing efforts to arrest these hackers," a source told Reuters, as quoted by BleepingComputer.
None of this is officially confirmed. The FBI "declined to comment on any specific arrest or activity abroad," per Reuters, but said it has "already worked with partners to arrest multiple subjects." FBI Director Kash Patel posted on X on Wednesday: "FBI teams are working new leads RIGHT NOW. More arrests are on the table." We found no public statement from Jordanian authorities as of October 4.
Who Is Rey?
Rey is the handle of Saif al-Din Khader, a teenager from Amman, Jordan, whom KrebsOnSecurity named in November 2025 as the technical operator and public face of Scattered LAPSUS$ Hunters. In Meet Rey, the Admin of 'Scattered Lapsus$ Hunters', Brian Krebs reported that Khader told him he would turn 16 the following month, and listed three roles:
- One of three administrators of the Scattered LAPSUS$ Hunters Telegram channel
- The member who released ShinySp1d3r, a ransomware offering built from modified Hellcat code
- A former administrator of the data leak site for Hellcat, a ransomware group that surfaced in late 2024
Threat intelligence firm KELA got there first, tracing Rey through two infostealer infections of his own computer, in February 2024 (RedLine) and March 2024, to "a young individual named 'Saif'" in Amman. His crews break in with stolen credentials, and his own were stolen the same way.
Rey told Krebs in 2025, as quoted by BleepingComputer: "I have been talking to them since at least June. I haven't really done anything like breaching into a corp or extortion related since September." Krebs could not verify either claim.
Which Attacks Is Rey Linked To?
Rey is tied to at least five incidents since January 2025, but the links range from a victim's confirmation to unnamed sources. Check the basis column before treating any row as proven.
| When | Target | Basis for the link |
|---|---|---|
| January 9, 2025 | Telefónica's internal Jira ticketing server, about 2.3 GB scraped | Rey was one of four actors (with DNA, Grep and Pryx) who claimed it; Telefónica confirmed the breach to BleepingComputer |
| February 2025 | Orange Romania, about 6.5 GB leaked | Orange confirmed the attack after Rey leaked the data; Rey said he acted independently of Hellcat |
| March 2025 | Jaguar Land Rover: Jira issues, source code, employee information | Linked to Rey in BleepingComputer's reporting |
| September 2025 | Jaguar Land Rover production shutdown | Claimed by Scattered LAPSUS$ Hunters as a group, not by Rey personally |
| September 19 and 22, 2026 | Clop's leak site and the FBI jobs site | Unnamed sources told KrebsOnSecurity the shift to these attacks came after Rey took over ShinyHunters |
The bottom row matters most and is the weakest. Reuters' headline calls Khader a hacker "in FBI data theft," but its text describes him only as a suspected member of the group, and BleepingComputer does not say he took part in the FBI breach. We covered the Clop leak site hijack on September 19 and the FBI jobs site defacement three days later.
How Does the Amsterdam Arrest Fit In?
The Amsterdam arrest is the other half of a feud. On September 15, Dutch police arrested a 24 year old man, and the Politie's national investigations unit told The Hacker News: "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters."
KrebsOnSecurity and DataBreaches.net identified him as Pepijn van der Stap, the hacker known as Umbreon, who was sentenced to four years (one suspended) after a 2023 arrest for data theft and extortion and released in December 2025. ShinyHunters told Reuters he had "no association" with the group.
The FBI defacement carried an ASCII art rendition of the Pokémon Umbreon. Krebs's sources said "Rey had an ongoing beef with the Dutch hacker over control of the ShinyHunters brand and data, and that the inclusion of the oversized Umbreon Pokemon image in the FBI jobs site defacement was likely an attempt by Rey to pin the hack on the Dutchman." Note the dates: the September 15 arrest came a week before the September 22 defacement, although BleepingComputer's write up places it "following the FBI breach."
Most coverage skips the obvious problem. If those sources are right, the man now walking the FBI through his devices is accused of planting evidence against the man arrested first. Investigators will be weighing testimony from someone with a stake in the outcome.
Is ShinyHunters Finished?
No, ShinyHunters is still operating. Per BleepingComputer, an affiliate who had been talking to reporters shut down their messaging account on Tuesday, and the leak site went offline. Reuters said the site disappeared on Wednesday. "However, on Thursday, a new ShinyHunters data leak site went online, suggesting other members continue to run the extortion operation."
The tone did change. In its latest email to Reuters, the group said "we want no further escalation" with the FBI, after claiming on September 22 that it hacked the bureau in retaliation. After the Dutch arrest, FBI Cyber Division Assistant Director Brett Leatherman had pitched the remaining members directly: "The longer you stay in this, the more we learn about you."
Arrests have not ended this ecosystem before. LAPSUS$ came back after its 2022 arrests, and Rey's own 2025 claim that he had quit was followed, per Krebs's sources, by a takeover of ShinyHunters. A cooperating insider beats a seized server only if the crew cannot rebuild faster than investigators read his phone.
What This Means for Your Inbox
ShinyHunters runs on email. The FBI's September 2025 FLASH alert on UNC6040, the vishing cluster behind the Salesforce thefts, says "Some UNC6040 victims have subsequently received extortion emails allegedly from the ShinyHunters group," and that the demands arrived anywhere from days to months after the data was taken. A new leak site means those emails can keep coming, whoever is in custody.
For individuals, the risk is the data already out. Leaked addresses and support tickets give scammers believable detail, and we have tracked criminals reusing ShinyHunters dumps for a $2,000 sextortion email scam. An arrest headline also hands impersonators a pretext, so be wary of anyone citing the Jordan detention to ask you to verify your identity.
What Should ShinyHunters Victims Do Now?
Victims should treat the arrests as a reason to collect evidence, not a reason to relax. For security teams, the FBI's UNC6040 mitigations still apply:
- Train call center staff to recognize and report vishing, because UNC6040 callers pose as IT support closing an "auto-generated ticket."
- Require phishing resistant MFA and apply least privilege to user accounts and groups.
- Review every connected app and third party integration in Salesforce, then rotate API keys, credentials and tokens. A malicious connected app, the FBI warns, "bypasses many traditional defenses."
- Keep extortion emails intact, headers included, and report them to the FBI at IC3.
For people whose data appeared in a ShinyHunters leak:
- Change the password on the breached service and anywhere you reused it, then turn on two factor authentication.
- Distrust any email that quotes your order history, ticket text or address back to you. Contact the company through its own website or app.
- Do not pay sextortion or "delete your data" demands. ShinyHunters does not need your payment to keep a copy.
- Ignore anyone claiming to be the FBI who emails or calls asking for money or identity documents.
Looking Ahead
Watch for three signals: official confirmation from Jordan or the U.S. Justice Department, and whether Khader, a minor when Krebs interviewed him, is charged; what Rey's devices mean for the case against van der Stap; and whether the new leak site keeps posting victims. Until it stops, assume stolen ShinyHunters data is still in use. For how this crew usually gets in, our guide to ShinyHunters voice phishing walks through the phone call that starts most of these breaches.