Skip to content

ShinyHunters Suspect Rey Detained in Jordan, Reportedly Helping FBI Track Down Group Members

ShinyHunters Suspect Rey Detained in Jordan, Reportedly Helping FBI Track Down Group Members

A teenage hacker from Amman who served as a key figure inside ShinyHunters has reportedly been detained in Jordan and is walking FBI investigators through his devices — the second arrest in two weeks tied to the group’s brazen claim that it hacked the FBI itself.

Conceptual diagram showing ShinyHunters at the center, linked by dashed lines to Rey (detained in Jordan) and Umbreon (arrested in Netherlands) on the left, and to HellCat and Scattered Lapsus$ Hunters on the right
Conceptual map of known actors linked to ShinyHunters based on reported investigations. Source: Generated by UnpanicTech.

Saif al-Din Khader — known online as Rey and ReyXBF — was reportedly detained by Jordanian authorities on or around September 29, 2026, according to a Reuters exclusive citing three sources familiar with the matter [1]. Two of those sources told Reuters he is now helping the FBI and international law enforcement locate his fellow ShinyHunters members. One source said he was walking investigators through his electronic devices and digital correspondence.

Reuters was unable to independently determine the circumstances of Khader’s detention or confirm his current whereabouts. The FBI declined to comment on any specific arrest or overseas activity, but told Reuters that it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice” [1]. Jordan’s government has not made any public statement on the matter.

Who Is Rey?

Khader is not a new name to researchers tracking English-language cybercrime groups. He was identified publicly in November 2025 by security journalist Brian Krebs, who traced the Rey alias to a teenager in Amman, Jordan through infostealer logs and direct Signal communications [2].

Before his connection to ShinyHunters became widely known, Khader was linked to the HellCat ransomware group that emerged in late 2024. In January 2025, he was one of four threat actors who claimed responsibility for a breach of Telefónica’s internal Jira ticketing system, where around 2.3GB of data was allegedly stolen. He later conducted an independent breach of Orange’s Romanian operations, leaking approximately 6.5GB of data in February 2025 while identifying himself as a HellCat member at the time [2].

Rey’s connection to ShinyHunters came through a group calling itself Scattered Lapsus$ Hunters — an alliance claiming to include former members of Lapsus$, Scattered Spider, and ShinyHunters. Rey was observed with administrative privileges in Telegram channels operated by this group. It claimed credit for the September 2025 cyberattack on Jaguar Land Rover, which reportedly cost the automaker more than $220 million after forcing production halts [2].

When Krebs spoke directly with Khader in November 2025, Khader claimed he had already been cooperating with law enforcement since at least June 2025. Krebs noted at the time he could not verify those claims.

The FBI Breach That Triggered the Crackdown

The current wave of arrests cannot be separated from what happened on the night of September 21–22, 2026. ShinyHunters publicly claimed it had breached the FBI’s jobs portal, obtaining data on current and former FBI employees, job applicants, and records from internal FBI services including what it described as medical and psychiatric information [2].

The group said it exploited a new, unspecified Oracle PeopleSoft zero-day to gain initial access, then moved laterally into FBI-managed AWS GovCloud systems. A Reuters analysis of a sample of the allegedly stolen data found it contained personally identifiable information on FBI employees and sensitive job-role details [1]. The FBI confirmed it was investigating unauthorized activity but has not confirmed the alleged zero-day, the lateral movement into AWS GovCloud, or the volume of data stolen.

This breach claim followed a documented, confirmed exploitation campaign. Between May and June 2026, ShinyHunters — tracked by Google’s Threat Intelligence Group as UNC6240 — exploited CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools, targeting academic institutions [3]. By September, researchers assessed that ShinyHunters had developed a URL-encoding technique to bypass web application firewall rules intended to mitigate CVE-2026-35273. Whether the FBI attack used this same flaw or a genuinely new PeopleSoft vulnerability has not been publicly established [4].

Diagram showing the ShinyHunters PeopleSoft attack chain: Recon, WAF bypass via URL encoding, RCE via CVE-2026-35273 or variant, web shell and tunneling kit deployment, then lateral movement and data theft. Includes defender action steps.
Conceptual illustration of the ShinyHunters PeopleSoft exploitation chain, based on Google/Mandiant UNC6240 reporting. The FBI breach attack chain has not been independently confirmed. Source: Generated by UnpanicTech.

Two Arrests in Two Weeks

The detention of Khader is the second arrest linked to the post-FBI-breach crackdown. On September 15, Dutch authorities arrested a 24-year-old Amsterdam man identified by KrebsOnSecurity and DataBreaches.net as Pepijn van der Stap, previously known by the online alias “Umbreon” [5]. Van der Stap was convicted in 2023 for data theft and extortion and was on supervised release at the time of the September 2026 arrest. Dutch police confirmed the arrest publicly on September 28 but did not name the suspect or link him to any specific ShinyHunters attack.

There is a notable wrinkle in that case. According to KrebsOnSecurity, sources familiar with the investigation believe ShinyHunters may have deliberately used van der Stap’s former Umbreon identity — specifically the same Pokémon character imagery — in the FBI site defacement, possibly to frame him. The defacement prominently featured an Umbreon ASCII image, and the timing placed those actions after van der Stap’s arrest but before it became public. ShinyHunters denied any connection to van der Stap. A source cited by DataBreaches.net said the voice in a recorded audio clip associated with the Odido hack linked to ShinyHunters was not van der Stap’s [5]. Whether this amounts to deliberate framing, coincidence, or something else is not established.

Timeline showing five key events from May 2026 through October 2026: the CVE-2026-35273 exploitation campaign, the Dutch arrest on September 15, the FBI breach claim on September 21-22, Dutch police confirmation on September 28, and Rey reported detained in Jordan September 29 through October 3
Key events in the ShinyHunters law enforcement crackdown, May through October 2026. Source: Generated by UnpanicTech.

What the Arrests Reveal About the Group

ShinyHunters does not operate the way the name might suggest — as a tight, hierarchical crew. By most accounts from researchers tracking the group, it functions more like a loose affiliation: a brand and a set of shared tools and infrastructure, with different actors cycling in and out and occasionally operating independently. Rey’s alleged administrative access and leadership role in the Scattered Lapsus$ Hunters offshoot suggests significant influence inside the network, but it is not clear that his cooperation alone will unravel the entire operation.

The fact that a new leak site appeared within days of his reported detention is telling. Either other members quickly moved to reconstitute operations, or the infrastructure was never as centralized as the crackdown might have assumed. Both are plausible.

The group’s stated motivation for targeting the FBI is also unusual. Unlike most cybercriminal extortion operations, ShinyHunters said it was not seeking money from the FBI. It demanded the bureau retract a May 2026 public service announcement describing the group’s tactics and its alleged links to a network called The Com — a loose collective associated with social engineering, SIM swapping, and physical violence. ShinyHunters disputed being connected to The Com and called the FBI’s characterization inaccurate [4]. Law enforcement has made no public concessions on that point.

Three boxes showing the international law enforcement response: Jordan (Rey detained, not officially confirmed), Netherlands (Umbreon arrested, confirmed by Dutch police), and United States FBI (coordinating investigation, multiple arrests confirmed). A quote from the FBI is shown at the bottom.
Overview of confirmed and reported law enforcement actions across three jurisdictions as of October 4, 2026. Source: Generated by UnpanicTech.

What Remains Uncertain

Quite a bit is still unverified or unconfirmed:

  • Jordan has not confirmed the detention. The Reuters report relies on three unnamed sources. The circumstances of the detention and Khader’s current location have not been officially disclosed.
  • The FBI breach itself — the specific vulnerability exploited, the volume of data stolen, whether AWS GovCloud was actually accessed — remains unconfirmed by the FBI or Oracle.
  • Whether van der Stap is genuinely connected to the current ShinyHunters operation, or was deliberately framed using his former alias, has not been resolved.
  • How many people currently comprise the ShinyHunters operation, and how many remain at large, is not publicly known.
  • Khader claimed he had been cooperating with law enforcement since at least June 2025. What that earlier cooperation produced, if anything, has not been reported.

What Defenders Should Watch

Arrests rarely stop a group’s techniques from spreading. The exploitation of CVE-2026-35273 is documented and confirmed — Google/Mandiant notified more than 100 organizations about renewed targeting of this vulnerability [3]. Any organization running Oracle PeopleSoft should treat patching this vulnerability as an immediate priority. WAF rules are not a sufficient substitute for the patch itself.

Beyond PeopleSoft, ShinyHunters has consistently exploited SaaS integrations, OAuth misconfigurations, and third-party access paths in Snowflake and Salesforce environments. None of that changes because two group members are in custody. The playbook is documented, and the techniques are available to affiliates and successor operations.

The FBI’s public messaging after the Dutch arrest was notably pointed. Cyber Division Assistant Director Brett Leatherman said: “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” That is the kind of statement law enforcement makes when they believe they have momentum and want remaining group members to break before they are identified. Whether additional members are cooperating or preparing to surrender is not yet public.

Sources & References

  1. Reuters — Exclusive: ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say (via KFGO, October 3, 2026)
  2. BleepingComputer — ShinyHunters hacker reportedly detained in Jordan, aiding FBI (Lawrence Abrams, October 3, 2026)
  3. SC World — ShinyHunters targets Oracle PeopleSoft in new campaign amid FBI attack claims
  4. The Hacker News — ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members (October 4, 2026)
  5. SecurityWeek — Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
NK

Naseem Khan (Technical Editor)

Cybersecurity Researcher & Technical Editor

UnpanicTech is supported by a dedicated team of cybersecurity specialists and writers. All research and articles are comprehensively reviewed and published by our Technical Editor, Naseem Khan, covering vulnerability analysis, defensive security, incident response, cloud security, and practical security engineering.

Technical Discussion & Feedback

Leave a Comment (Authenticated Users)