Jordanian Authorities have detained a suspected member of the ShinyHunters hacker group known online as “Rey” in Amman, following cyberattacks that hit government databases and company networks [1]. Three people familiar with the matter confirmed to Reuters that local security forces took Saif Khader, formally identified as Saif al-Din Khader, into custody on Tuesday, September 29, 2026 [2]. Investigators say Khader is now cooperating with the Federal Bureau of Investigation to help locate his alleged co-conspirators, walking agents through his electronic devices and private messaging accounts [1].
Detaining a Suspected ShinyHunters Hacker Group Member in Amman
Two sources familiar with the detention said Khader is walking federal agents through his computers, phones, and digital chat logs to identify other actors in the ShinyHunters hacker group. One source told Reuters that “his cooperation is critical to ongoing efforts to arrest these hackers.” Investigators gained access to private channels that law enforcement couldn’t monitor from the outside [1].
Saif Khader’s name isn’t new to cybersecurity researchers who track underground extortion rings. Journalist Brian Krebs identified Rey as an Amman teenager in November 2025 after examining infostealer malware logs and speaking directly with him on Signal, where Khader claimed he was trying to leave cybercrime behind [3]. In those conversations, Khader insisted that he had been in contact with law enforcement since June 2025, claiming: “I have told them nearly everything. I haven’t really done anything like breaching into a corp or extortion related since September”. Krebs couldn’t verify those claims at the time. Recent activity tied Rey to manager accounts on Telegram under the moniker Scattered Lapsus$ Hunters. That group claimed a September 2025 intrusion into automaker Jaguar Land Rover that halted production for weeks and cost the British Jaguar maker over $220 million in recovery expenses [1].

FBI Data Theft Claims and the PeopleSoft Vulnerability
The detention in Amman follows a public confrontation between the Federal Bureau and the ShinyHunters hacker group over an intrusion into recruitment systems. In September 2026, the hackers breached the bureau’s jobs portal at apply.fbijobs.gov, displaying a fake seizure banner and forcing the agency to take its Special Agent Applicant Portal offline during the inquiry [2]. Threat actors claimed they breached Oracle Systems software by exploiting CVE-2026-35273 before moving into government cloud instances managed on Amazon Web Services [3].
Security analysts at Google Threat Intelligence Group and Mandiant Threat Intelligence track the cluster as UNC6240, noting that attackers first used the PeopleSoft zero-day flaw against universities before altering the exploit to bypass web application firewalls in broader government intrusions [3]. The hackers claimed they extracted between 2TB and 3TB of records, yet neither Oracle Corporation nor United States Federal officials confirmed that intrusion path [1]. It’s still unclear whether the hackers penetrated central networks or simply scraped applicant portals that sat on public servers. Federal investigators need to compare server logs, cloud access records, and outgoing data transfers to verify what was taken [2].
Washington Federal officials distributed a staff memo warning people to assume every employee record was exposed, even though independent analysts couldn’t confirm the total volume of stolen files [3]. ShinyHunters provided Cyber Security News press with a sample of 5,000 staff profiles that included names, birth dates, phone numbers, home addresses, and Social Security numbers. Reuters verified details for ten people by checking credit records, but that test didn’t prove the full database came from compromised bureau storage [2].

What Is the Extent of the Stolen Personnel Files?
The documents shared by the ransom gang contained medical and mental health records, which heightened privacy concerns across Washington. Files reportedly included evaluations from FBI MedLink, an applicant screening tool that tracks fitness health checks, prescription histories, and psychiatric reviews. One document described an applicant who took daily aspirin and suffered from dust and cat allergies, while another noted a candidate who experienced depression during high school. An additional file contained an electrocardiogram scan from a pre-employment medical review, illustrating the personal nature of the records shared with press [4].
Security specialists likened the incident to the 2015 breach at the US Office of Personnel Management, where foreign state hackers breached vetting archives for millions of government workers [6]. Even if attackers don’t retain permanent access, stolen staff files create lasting risks of identity fraud, spear-phishing, and harassment directed at agents and their families [2]. Why would an extortion syndicate target federal personnel if it didn’t plan to sell the records on the dark web? [4]
ShinyHunters argued that the confrontation was simply a promotional stunt. In a statement sent to press, the group said it never planned to publish or sell the sensitive personnel data, describing its one-week ultimatum as a “marketing campaign” rather than an extortion threat. The hackers had demanded that the bureau remove an advisory published in May 2026 that characterized them as a cybercrime syndicate. That advisory stayed online. The bureau refused to negotiate [4].

Law Enforcement Pressure Mounts on ShinyHunters Group
The detention of Khader arrived two weeks after Dutch National Police arrested Pepijn van der Stap, an alleged 24-year-old hacker known online as “Umbreon,” during an armed raid in Amsterdam on September 15, 2026. Van der Stap served as offensive security lead at Neo Security, where investigators searched company offices on the day of the arrest [5]. Rotterdam District Court judges ordered van der Stap held for a further 90 days, while police also investigated suspected solicitation of two killings abroad based on evidence found on his computer [4].
Federal Bureau Director Kash Patel praised the Dutch operation on social media, saying investigators were pursuing fresh leads and warning that more arrests stayed on the table [6]. Assistant Director Brett Leatherman of the Cyber Division issued a direct challenge to the gang: “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left”. Officials say the ShinyHunters hacker group breached over 140 organizations and collected at least $70 million in extortion ransoms since 2025, mirroring earlier arrests of GTA Online hackers linked to ShinyHunters in European jurisdictions. Neo Security founder Benjamin Korper confirmed that police searched their Amsterdam office during the operation [5].
ShinyHunters built a long record of cloud compromises by stealing authentication tokens and targeting single sign-on credentials. In May 2026, the group struck Instructure Canvas, an educational platform, claiming it stole 3.65TB of data affecting nearly 9,000 schools and roughly 275 million users before reaching an agreement with the company to withhold the leak [3]. The group also accessed Snowflake accounts at Rockstar Games through vendor Anodot, and previous attacks struck Telefónica Jira servers, Orange Romania, Cisco Systems, and PornHub [1].

Fresh Leaks and Disruption Inside ShinyHunters
Signs of strain inside the group surfaced the same day Jordanian Authorities detained Khader in Amman Police custody. An affiliate account that communicated with press about the FBI incident and a separate Clop ransomware dispute went silent on Tuesday [1]. By Wednesday, the group’s dark web leak site went dark, though operators claimed the outage stemmed from distributed denial-of-service attacks rather than police action [4]. Reporter Lawrence Abrams of BleepingComputer observed that ShinyHunters representatives stopped answering messages from press, showing that the detention rattled the group’s communications [1].
Despite the disruptions, other members continue running extortion channels. A replacement leak site surfaced on Thursday, posting new breach listings for Reilly Automotive and medical firm DexCom on October 1 before removing them on October 3 [3]. In the two months prior to that update, the gang listed 15 victims in healthcare and technology, including Logitech Streamlabs Brand, Metabase Corporation, Lumenis Ltd, and RingCentral [4]. The ongoing listings confirm that detaining a single member doesn’t immediately shut down a distributed cybercrime network. Security analysts at Hacker Posts noted that extortion infrastructure often survives individual arrests [7].
Security experts caution that companies shouldn’t wait for criminal indictments before revoking exposed credentials. Security teams must rotate API keys, reset single sign-on authenticators, and assume stolen cloud tokens stay dangerous even while suspects talk to police [7]. International cyber investigations take months of cross-border coordination to turn seized hard drives and chat logs into formal charges [8]. For now, investigators are watching to see how far Khader’s statements lead them into the ShinyHunters hacker group and its remaining circle [1].
- ONLINE NEWS Abrams, L. (2026, October 3). ShinyHunters hacker reportedly detained in Jordan, aiding FBI. BleepingComputer. [Article Link]
- ONLINE NEWS Baran, G. (2026, October 3). ShinyHunters member detained in Jordan, reportedly helping FBI identify fellow hackers. Cyber Security News. [Article Link]
- ONLINE NEWS Waqas. (2026, October 3). ShinyHunters suspect “Rey” detained in Jordan, reportedly helping FBI. Hackread. [Article Link]
- ONLINE NEWS Oki, O. B. (2026, October 3). ShinyHunters hacker detained in Jordan cooperating with FBI. Kahawatungu. [Article Link]
- ONLINE NEWS Alund, N. N. (2026, September 29). Member of ShinyHunters hacking group arrested, officials say. USA TODAY. [Article Link]
- ONLINE NEWS The Straits Times. (2026, October 3). ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say. The Straits Times. [Article Link]
- ONLINE NEWS Hacker Posts Desk. (2026, October 3). ShinyHunters member ‘Rey’ detained in Jordan, aiding FBI. Hacker Posts. [Article Link]
- ONLINE NEWS UNDERCODE NEWS. (2026, October 3). Suspected ShinyHunters hacker Rey reportedly detained in Jordan, now cooperating with the FBI to identify other members. UNDERCODE NEWS. [Article Link]