A teenage hacker from Amman who served as a key figure inside ShinyHunters has reportedly been detained in Jordan and is walking FBI investigators through his devices — the second arrest in two weeks tied to the group’s brazen claim that it hacked the FBI itself.
Saif al-Din Khader — known online as Rey and ReyXBF — was reportedly detained by Jordanian authorities on or around September 29, 2026, according to a Reuters exclusive citing three sources familiar with the matter [1]. Two of those sources told Reuters he is now helping the FBI and international law enforcement locate his fellow ShinyHunters members. One source said he was walking investigators through his electronic devices and digital correspondence.
Reuters was unable to independently determine the circumstances of Khader’s detention or confirm his current whereabouts. The FBI declined to comment on any specific arrest or overseas activity, but told Reuters that it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice” [1]. Jordan’s government has not made any public statement on the matter.
Who Is Rey?
Khader is not a new name to researchers tracking English-language cybercrime groups. He was identified publicly in November 2025 by security journalist Brian Krebs, who traced the Rey alias to a teenager in Amman, Jordan through infostealer logs and direct Signal communications [2].
Before his connection to ShinyHunters became widely known, Khader was linked to the HellCat ransomware group that emerged in late 2024. In January 2025, he was one of four threat actors who claimed responsibility for a breach of Telefónica’s internal Jira ticketing system, where around 2.3GB of data was allegedly stolen. He later conducted an independent breach of Orange’s Romanian operations, leaking approximately 6.5GB of data in February 2025 while identifying himself as a HellCat member at the time [2].
Rey’s connection to ShinyHunters came through a group calling itself Scattered Lapsus$ Hunters — an alliance claiming to include former members of Lapsus$, Scattered Spider, and ShinyHunters. Rey was observed with administrative privileges in Telegram channels operated by this group. It claimed credit for the September 2025 cyberattack on Jaguar Land Rover, which reportedly cost the automaker more than $220 million after forcing production halts [2].
When Krebs spoke directly with Khader in November 2025, Khader claimed he had already been cooperating with law enforcement since at least June 2025. Krebs noted at the time he could not verify those claims.
The FBI Breach That Triggered the Crackdown
The current wave of arrests cannot be separated from what happened on the night of September 21–22, 2026. ShinyHunters publicly claimed it had breached the FBI’s jobs portal, obtaining data on current and former FBI employees, job applicants, and records from internal FBI services including what it described as medical and psychiatric information [2].
The group said it exploited a new, unspecified Oracle PeopleSoft zero-day to gain initial access, then moved laterally into FBI-managed AWS GovCloud systems. A Reuters analysis of a sample of the allegedly stolen data found it contained personally identifiable information on FBI employees and sensitive job-role details [1]. The FBI confirmed it was investigating unauthorized activity but has not confirmed the alleged zero-day, the lateral movement into AWS GovCloud, or the volume of data stolen.
This breach claim followed a documented, confirmed exploitation campaign. Between May and June 2026, ShinyHunters — tracked by Google’s Threat Intelligence Group as UNC6240 — exploited CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools, targeting academic institutions [3]. By September, researchers assessed that ShinyHunters had developed a URL-encoding technique to bypass web application firewall rules intended to mitigate CVE-2026-35273. Whether the FBI attack used this same flaw or a genuinely new PeopleSoft vulnerability has not been publicly established [4].
Two Arrests in Two Weeks
The detention of Khader is the second arrest linked to the post-FBI-breach crackdown. On September 15, Dutch authorities arrested a 24-year-old Amsterdam man identified by KrebsOnSecurity and DataBreaches.net as Pepijn van der Stap, previously known by the online alias “Umbreon” [5]. Van der Stap was convicted in 2023 for data theft and extortion and was on supervised release at the time of the September 2026 arrest. Dutch police confirmed the arrest publicly on September 28 but did not name the suspect or link him to any specific ShinyHunters attack.
There is a notable wrinkle in that case. According to KrebsOnSecurity, sources familiar with the investigation believe ShinyHunters may have deliberately used van der Stap’s former Umbreon identity — specifically the same Pokémon character imagery — in the FBI site defacement, possibly to frame him. The defacement prominently featured an Umbreon ASCII image, and the timing placed those actions after van der Stap’s arrest but before it became public. ShinyHunters denied any connection to van der Stap. A source cited by DataBreaches.net said the voice in a recorded audio clip associated with the Odido hack linked to ShinyHunters was not van der Stap’s [5]. Whether this amounts to deliberate framing, coincidence, or something else is not established.
What the Arrests Reveal About the Group
ShinyHunters does not operate the way the name might suggest — as a tight, hierarchical crew. By most accounts from researchers tracking the group, it functions more like a loose affiliation: a brand and a set of shared tools and infrastructure, with different actors cycling in and out and occasionally operating independently. Rey’s alleged administrative access and leadership role in the Scattered Lapsus$ Hunters offshoot suggests significant influence inside the network, but it is not clear that his cooperation alone will unravel the entire operation.
The fact that a new leak site appeared within days of his reported detention is telling. Either other members quickly moved to reconstitute operations, or the infrastructure was never as centralized as the crackdown might have assumed. Both are plausible.
The group’s stated motivation for targeting the FBI is also unusual. Unlike most cybercriminal extortion operations, ShinyHunters said it was not seeking money from the FBI. It demanded the bureau retract a May 2026 public service announcement describing the group’s tactics and its alleged links to a network called The Com — a loose collective associated with social engineering, SIM swapping, and physical violence. ShinyHunters disputed being connected to The Com and called the FBI’s characterization inaccurate [4]. Law enforcement has made no public concessions on that point.
What Remains Uncertain
Quite a bit is still unverified or unconfirmed:
- Jordan has not confirmed the detention. The Reuters report relies on three unnamed sources. The circumstances of the detention and Khader’s current location have not been officially disclosed.
- The FBI breach itself — the specific vulnerability exploited, the volume of data stolen, whether AWS GovCloud was actually accessed — remains unconfirmed by the FBI or Oracle.
- Whether van der Stap is genuinely connected to the current ShinyHunters operation, or was deliberately framed using his former alias, has not been resolved.
- How many people currently comprise the ShinyHunters operation, and how many remain at large, is not publicly known.
- Khader claimed he had been cooperating with law enforcement since at least June 2025. What that earlier cooperation produced, if anything, has not been reported.
What Defenders Should Watch
Arrests rarely stop a group’s techniques from spreading. The exploitation of CVE-2026-35273 is documented and confirmed — Google/Mandiant notified more than 100 organizations about renewed targeting of this vulnerability [3]. Any organization running Oracle PeopleSoft should treat patching this vulnerability as an immediate priority. WAF rules are not a sufficient substitute for the patch itself.
Beyond PeopleSoft, ShinyHunters has consistently exploited SaaS integrations, OAuth misconfigurations, and third-party access paths in Snowflake and Salesforce environments. None of that changes because two group members are in custody. The playbook is documented, and the techniques are available to affiliates and successor operations.
The FBI’s public messaging after the Dutch arrest was notably pointed. Cyber Division Assistant Director Brett Leatherman said: “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” That is the kind of statement law enforcement makes when they believe they have momentum and want remaining group members to break before they are identified. Whether additional members are cooperating or preparing to surrender is not yet public.
Sources & References
- Reuters — Exclusive: ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say (via KFGO, October 3, 2026)
- BleepingComputer — ShinyHunters hacker reportedly detained in Jordan, aiding FBI (Lawrence Abrams, October 3, 2026)
- SC World — ShinyHunters targets Oracle PeopleSoft in new campaign amid FBI attack claims
- The Hacker News — ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members (October 4, 2026)
- SecurityWeek — Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

Technical Discussion & Feedback
Leave a Comment (Authenticated Users)