cybercrime • BleepingComputer

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Aiding FBI

A suspected ShinyHunters extortion-group member known online as "Rey" and identified as Saif al-Din Khader has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members, according to Reuters. Sources say he was taken into custody early in the week (around 30 September–1 October 2026) and is walking investigators through his devices and digital communications.

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Aiding FBI

A suspected ShinyHunters extortion-group member known online as "Rey" and identified as Saif al-Din Khader has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members, according to Reuters. Sources say he was taken into custody early in the week (around 30 September–1 October 2026) and is walking investigators through his devices and digital communications. The story, amplified by BleepingComputer and others on 3 October, lands amid an FBI crackdown on the group after claimed breaches of bureau systems.

ShinyHunters has become one of the most visible names in SaaS and cloud data extortion. The group has been linked to Salesforce-environment attacks and third-party integration breaches affecting brands including Google and Cisco. The typical method is breaking into an integration partner, stealing authentication tokens, then exfiltrating customer data from connected cloud services — pure theft and leak-threats rather than classic file encryption. In May 2026 the group was tied to a major Instructure Canvas data-theft incident that caused platform outages; the company later said it reached an "agreement" to keep stolen data from being leaked.

In September 2026 ShinyHunters told BleepingComputer it breached FBI systems via an alleged Oracle PeopleSoft zero-day and moved laterally into FBI-managed AWS GovCloud, claiming 2–3 TB of stolen data including employee, applicant and medical information. BleepingComputer has not independently verified the zero-day, lateral movement or volume. The FBI confirmed it was investigating claims of unauthorised activity but did not confirm data theft. On 15 September Dutch police arrested a 24-year-old Amsterdam man — identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, alias "Umbreon" — in a ShinyHunters-related investigation. FBI Cyber Division Assistant Director Brett Leatherman then urged remaining members to turn themselves in.

Rey’s history stretches beyond the ShinyHunters label. He has been linked to HellCat ransomware and Jira breaches, including Telefónica (about 2.3 GB) and Orange Romania (about 6.5 GB). He appeared with administrative privileges in Telegram channels tied to "Scattered Lapsus$ Hunters," a constellation that in 2025–2026 claimed ties to Lapsus$, Scattered Spider and ShinyHunters and took credit for the Jaguar Land Rover attack that halted production for weeks at a cost exceeding $220 million. In November 2025 Brian Krebs reported that Rey was Saif Al-Din Khader after infostealer logs and Signal contact; Khader allegedly claimed he had been cooperating with law enforcement since June — claims Krebs could not verify.

On the reported detention day, disruption signs appeared: an affiliate who had contacted media about the FBI attack shut an account, the ShinyHunters leak site went offline, and the main representative stopped answering. By Thursday a new leak site was online again, suggesting others still run the extortion operation. Whether Rey’s cooperation yields more arrests, the message for Nordic CISOs is clear: SaaS token theft and third-party risk remain the operational main vector, and law enforcement disruption does not automatically end the campaigns.

How to protect yourself and your accounts

Audit which third-party apps and integrations hold OAuth or API access to Salesforce and other SaaS platforms; revoke unnecessary tokens. Require phishing-resistant MFA (multi-factor authentication) and monitor unusual data exports. If you receive extortion messages tied to ShinyHunters or Scattered Lapsus$ Hunters: document, report to police, do not pay as a default, and let legal and IR own communications. Individuals who suspect data leaked via an employer or school platform should change reused passwords and consider credit monitoring.

Sources & References

← All News Tools