ShinyHunters Hacker Detained in Jordan, Cooperating with FBI
A key suspect in the ShinyHunters extortion group has been detained in Jordan and is assisting the FBI. The arrest could lead to broader disruption of the cybercriminal network.
TL;DR
- Suspected ShinyHunters member 'Rey' (Saif al-Din Khader) was detained in Jordan on September 29, 2026.
- Rey is reportedly cooperating with the FBI to identify other members of the digital extortion group.
- ShinyHunters is known for breaching companies and extorting them for large payments.
- The arrest may help U.S. authorities dismantle the group's operations.
- This development highlights ongoing international collaboration in combating cybercrime.
Authorities in Jordan have reportedly taken into custody a suspected member of the notorious ShinyHunters hacking group. Identified online as 'Rey,' the individual, whose real name is Saif al-Din Khader, was arrested on September 29, 2026.
According to sources cited by Reuters, Rey is now cooperating with the U.S. Federal Bureau of Investigation (FBI), providing information that could help identify and locate additional members of the group. This development marks a significant step in international efforts to dismantle one of the more active digital extortion groups targeting businesses worldwide.
ShinyHunters has gained attention for infiltrating corporate systems, stealing sensitive data, and demanding ransom payments to avoid public exposure. The group’s methods have impacted numerous organizations across various industries, making this arrest particularly impactful for cybersecurity professionals monitoring threat actor activities.
Who Is Rey and What Role Did He Play?
- Rey, also known as Saif al-Din Khader, was a core figure within the ShinyHunters cybercriminal collective.
- He is believed to have played a key role in several high-profile breaches carried out by the group.
- His cooperation with law enforcement suggests he had access to internal communications and operational details.
- Intelligence gathered from him may expose infrastructure used by the group, such as servers and communication channels.
Implications for Cybersecurity Teams
- Organizations should monitor for any indicators of compromise linked to ShinyHunters activity disclosed through this investigation.
- Security teams can expect updated threat intelligence based on Rey’s cooperation, including new TTPs (tactics, techniques, and procedures).
- This case underscores the importance of tracking third-party vendor risks and insider threats.
- Businesses should review their incident response plans and ensure they are prepared for potential fallout from related breaches.
- Law enforcement collaboration like this demonstrates how global partnerships enhance cyber defense capabilities.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.