← All posts

Security

A Second ShinyHunters Figure Is in Custody, and This One Is Walking the FBI Through His Own Devices. The Group's Channels Went Dark the Same Day

Reuters reports that Saif al-Din Khader — the hacker known as "Rey" — was detained in Jordan on Tuesday and is helping the FBI identify the rest of ShinyHunters. The detention rests on anonymous sources, but the group's communication channel went unreachable the same day and its leak site was gone by Wednesday.

MAI
The flag of the United States Federal Bureau of Investigation: the FBI seal centred on a dark blue field, with the bureau's name in gold lettering.

Reuters reported on Saturday that Saif al-Din Khader — the hacker who used the handle "Rey" — was detained in Jordan on Tuesday and is now helping the FBI and international law enforcement identify the rest of ShinyHunters. Three people familiar with the matter described the detention to Reuters; two of them said Khader is cooperating, walking investigators through his own devices and digital correspondence. The FBI declined to comment on the detention. Jordanian officials did not respond to Reuters.

That is the second ShinyHunters figure taken into custody in a fortnight. The first, Pepijn van der Stap, was arrested in Amsterdam on 15 September and the case made public on 29 September. The difference between the two detentions is the entire story. An arrest subtracts one person from a loose confederation that has fractured and rebranded before. A cooperating insider walking through his own message history subtracts the assumption everyone else was working under.

What is established, and what rests on anonymous sources

Khader detained in Jordan on TuesdayThree people familiar, via Reuters; no official confirmation
Cooperating with the FBI, reviewing his own devicesTwo of those sources, via Reuters
ShinyHunters channel unreachable from Tuesday; leak site gone by WednesdayObservable
Khader identified as "Rey," admin of the Scattered Lapsus$ Hunters channelReported by Kela and Krebs on Security since November 2025
Multiple arrests already made in the FBI data theft investigationStated by the FBI
Contents of the stolen FBI personnel dataReviewed by Reuters

The weakest link in that table is the first row, and it is the one carrying the headline. No agency in either country has put its name to the detention. That is worth keeping in view.

The group took down its own megaphone

The corroboration that does not depend on anonymous sources is behavioural. ShinyHunters' communication channel became unreachable beginning Tuesday — the day Reuters' sources place Khader in custody — and its dark web leak site had disappeared by Wednesday.

Four days earlier, the group was running the opposite play. It told anyone listening that its confrontation with the FBI was a "marketing campaign," declined to publish the bulk of what it claimed to hold, and conspicuously did not say the data had been deleted. A crew in that posture does not quietly switch off its own publicity apparatus. It does so when it stops knowing who is reading.

That is the mechanism the FBI described in its 28 September video, when Assistant Director Brett Leatherman spoke past the press to the people still inside the group. Custody changes who is willing to talk; the uncertainty about who already has is what does the work. Within four days of that video, the channel was dark.

He has claimed to be cooperating before

The complication is that Khader has been here already. Krebs on Security identified him in November 2025 as the administrator of the Scattered Lapsus$ Hunters channel, a former administrator of Hellcat's leak site, and a serial BreachForums operator, writing from Amman. Asked about his position then, he said:

I'm already cooperating with law enforcement. In fact, I have been talking to them since at least June.

He also said he had contacted Europol and stepped back from breaches and extortion. Neither claim held. The ShinySp1d3r ransomware-as-a-service offering shipped late in 2025, and the group ran its campaigns through 2026, up to and including the Oracle PeopleSoft exploitation that reached the FBI's own careers portal. Krebs reported him as turning 16 in December 2025.

Cooperation asserted to a journalist and cooperation conducted in custody, with investigators holding the devices, are not the same instrument. But the earlier claim is the reason to be careful about how much today's reporting proves. "Cooperating" has meant very little coming from this particular source.

The Bureau is not behaving like an agency closing a case

The FBI's statement is procedural and forward-leaning at once: it "continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects." Director Kash Patel went further on X, writing that FBI teams are working new leads right now and that more arrests are on the table.

What none of this undoes

The data is still out. Reuters reviewed the material ShinyHunters claimed from the FBI's job-application system and found extensive personally identifiable information on FBI employees, sensitive job-role detail, and psychiatric and medical information. Nobody recalls a dataset. Every person in those records remains exposed regardless of how many people end up in custody.

Nor does any of this change the defensive arithmetic for everyone else. The vulnerability the group rode into the FBI's systems, CVE-2026-35273 in Oracle PeopleSoft, has had a patch since 10 June, and Google Threat Intelligence was still notifying fresh victims a week ago. Two detentions in Europe and the Middle East do not patch a server in a university data centre.

What they do change is the group's internal economics. ShinyHunters has always recruited publicly and operated on trust between people who have never met. The cheapest way to end that is not to arrest everyone. It is to make one of them useful.

Sources: Reuters via U.S. News: Exclusive — ShinyHunters Hacker in FBI Data Theft Detained in Jordan, Cooperating With Bureau, Sources Say · Reuters via KFGO: ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say · DataBreaches.Net: ShinyHunters hacker "Rey," allegedly involved in FBI data theft, detained in Jordan · The New Arab: ShinyHunters hacker detained in Jordan, 'cooperating with FBI' · Krebs on Security: Meet Rey, the Admin of 'Scattered Lapsus$ Hunters' · FBI: FBI Announces ShinyHunters Arrest · Google Threat Intelligence: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Keep reading