← Back to news
The Hacker News4 Oct 2026 · 2 min read

Report: Alleged ShinyHunters Figure Detained in Jordan as U.S. Investigation Expands

A person alleged to be associated with the ShinyHunters cyber-extortion ecosystem has reportedly been detained in Jordan and is assisting U.S. investigators, according to a Reuters report citing sourc...

A person alleged to be associated with the ShinyHunters cyber-extortion ecosystem has reportedly been detained in Jordan and is assisting U.S. investigators, according to a Reuters report citing sources familiar with the matter.

The individual, identified by the report as Saif al-Din Khader and known online as “Rey” or “ReyXBF,” was reportedly taken into custody on September 29. Sources said he has been providing information to the FBI and other law-enforcement agencies that could help identify additional participants in the group. Authorities have not publicly confirmed the reported detention or detailed any charges.

Rey has previously been linked by security researchers and journalists to several prominent cybercrime communities. Reporting in late 2025 described him as an administrator connected to Scattered LAPSUS$ Hunters, an apparent overlap of actors associated with the Scattered Spider, LAPSUS$, and ShinyHunters names. He was also reportedly involved with a Hellcat data-leak site and a later version of the BreachForums platform.

Broader investigation

The reported development follows the recent arrest in Amsterdam of a 24-year-old man in a separate investigation tied to alleged ShinyHunters activity. The FBI has said it is pursuing further leads with international partners, while a spokesperson using the ShinyHunters name denied a connection to the arrested Dutch man.

In recent activity attributed to the group, attackers claimed responsibility for compromising a Cl0p-associated dark-web site through an alleged Grav CMS vulnerability. They also claimed to have accessed an FBI recruitment portal and stolen roughly 3 TB of data, though the scope and attribution of those claims have not been independently verified.

FBI Cyber Division Assistant Director Brett Leatherman said investigators believe the suspects and co-conspirators breached more than 140 organizations and received at least $70 million through extortion. He said the actors frequently seek access through cloud-service providers and threaten to publish stolen data.

A durable criminal brand

Researchers at Sekoia and Beazley Security have characterized ShinyHunters as a flexible brand rather than a fixed organization. Their analysis traces its emergence to 2020 and argues that its longevity has depended on specialized collaborators handling social engineering, access, data theft, publicity, and extortion.

The latest reports illustrate how arrests, seized infrastructure, and cooperation from detained suspects can reshape investigations into loosely connected cybercrime networks.

Share this article:TwitterLinkedIn