ShinyHunters’ “Rey” Detained in Jordan: What His Cooperation Means for the FBI Probe

Illustration of detained hacker handing over drives to law enforcement

A suspected member of the ShinyHunters group who uses the online alias “Rey” has reportedly been detained in Jordan and is cooperating with U.S. law enforcement. Identified in reporting as Saif al‑Din Khader (also known online as ReyXBF), he was allegedly taken into custody on September 29, 2026. Sources say his cooperation is already assisting the FBI and other agencies as they pursue leads to identify and apprehend additional individuals linked to the long‑running data theft and extortion operation known as ShinyHunters.

Who Rey Is and Why His Detention Matters

Rey is a known figure in cybercrime reporting: past investigations have associated him with administrator roles on multiple criminal forums and leak sites, and he has been linked to groups that evolved from earlier extortion-focused crews. Independent reporting previously placed him among administrators of a hybrid collective sometimes referred to as Scattered LAPSUS$ Hunters, and noted his involvement in managing data leak infrastructure for other ransomware and extortion actors. Because of those operational ties, law enforcement officials say his cooperation could provide critical visibility into how the ShinyHunters brand operates and who is involved across its modular network.

Recent Arrests and Ongoing Investigations

The detention follows other enforcement activity in recent weeks, including the arrest of a 24‑year‑old man in Amsterdam identified by independent reports as Pepijn van der Stap. Authorities say these actions are producing leads that FBI teams are actively following; public comments from FBI leadership have indicated that investigators expect more arrests as seized infrastructure and new cooperation change the investigatory landscape. The combined effect of arrests and infrastructure seizures often prompts insiders to come forward, which can rapidly expand the list of identifiable actors and reveal operational details.

Tactics, Notable Operations, and Allegations

ShinyHunters and affiliated actors have been accused of breaching hundreds of organizations, exploiting third‑party vendors and cloud platforms to steal data, and demanding extortion payments. Law enforcement statements cited allegations that the collective has compromised over 140 organizations and extracted tens of millions of dollars in extortion proceeds. Recent high‑profile incidents attributed to the group include the hijacking of a rival cybercrime site and an exploitation of an unpatched Grav CMS vulnerability, as well as a reported intrusion into an FBI jobs portal that yielded approximately three terabytes of sensitive data. ShinyHunters has at times framed its actions as a response to perceived misrepresentations by authorities, but prosecutors and investigators emphasize the commercialized and harmful nature of the activity.

What Law Enforcement Is Saying

FBI leadership has portrayed the investigations as active and intensifying. Public remarks by senior FBI officials described the arrests as opening pathways to new leads and urged other participants to cooperate before options narrow. The bureau’s cyber division has highlighted patterns in targeting—particularly the exploitation of vendor relationships and cloud services—as repeatable tactics that increase victim exposure. Statements from law enforcement underscore that dismantling such groups often requires international cooperation, forensic analysis of seized infrastructure, and testimonies or technical information from detained insiders.

Understanding ShinyHunters’ Resilience and Structure

Security researchers tracking the group’s evolution describe ShinyHunters less as a single, monolithic organization and more as a brand and business model that persists by absorbing new members and redistributing tasks across a loose network. That modular structure—where initial access, amplification, recruitment, and monetization can be performed by different actors under a shared banner—helps explain the group’s longevity despite arrests and forum seizures. Analysts point to earlier progenitor groups that specialized in database theft and extortion, and they note how marketplace dynamics and reusable identities enable the brand to reconstitute itself after law‑enforcement disruptions.

What Organizations Should Take Away

For security teams, the developments reinforce two persistent lessons: prioritize supply‑chain and vendor security (because third‑party compromise is a recurring vector), and assume that stolen data may circulate for years even after a primary intrusion is disrupted. Rapid patching of known vulnerabilities, segmented access controls for vendor connections, and robust incident response playbooks remain essential. The unfolding investigation also highlights the value of threat intelligence sharing—public-private coordination can accelerate attribution and containment when cross‑border criminal networks are involved.

Looking Ahead

If reports about Rey’s cooperation are accurate, investigators may gain technical leads and human intelligence that accelerate prosecutions and additional arrests. However, experts caution that brand‑style groups with modular operations are likely to persist in some form: removing a few actors rarely eliminates the underlying incentives or the pool of skilled contributors. Law enforcement pressure, combined with improved organizational defenses and intelligence sharing, can narrow the avenues for profitable extortion and reduce long‑term harm—but the broader challenge of resilient, distributed cybercrime groups will endure.

Leave a Reply

Your email address will not be published. Required fields are marked *