VMTech
Discuss a project →

Jordan reportedly detains suspected ShinyHunters member Rey

Jordan reportedly detains suspected ShinyHunters member Rey

Jordanian authorities have reportedly detained Saif al-Din Khader, a suspected member of the ShinyHunters digital extortion group known online as Rey and ReyXBF. Reuters, citing three people familiar with the matter, reported that Khader was taken into custody on 29 September 2026 and is cooperating with the U.S. Federal Bureau of Investigation to identify other group members.

The reported detention follows the arrest of a 24-year-old man in Amsterdam over alleged involvement in ShinyHunters' malicious cyber operations. FBI Director Kash Patel said investigators were pursuing further leads from that arrest and that more arrests were possible.

Investigation focuses on a fluid cybercrime network

Rey has been linked publicly to several cybercrime operations. In November 2025, independent security journalist Brian Krebs identified him as one of three administrators of Scattered LAPSUS$ Hunters, also called SLH or SLSH, an alleged amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.

Krebs also reported that Rey had administered the data-leak site for the ransomware group Hellcat after it emerged in late 2024, and later ran the most recent incarnation of BreachForums. Khader told Krebs that he had been cooperating with law enforcement since at least June 2025.

FBI Cyber Division assistant director Brett Leatherman said that the cybercriminal and co-conspirators allegedly breached more than 140 organizations and collected at least $70 million in extortion payments. He said the actors often target third-party vendors in cloud-based platforms, steal sensitive data, and threaten victims with publication.

Recent activity and operational resilience

ShinyHunters has recently drawn attention for hijacking the darknet site of Cl0p through an unpatched Grav CMS flaw and for compromising the FBI's apply.fbijobs[.]gov portal, from which it claimed to have taken about three terabytes of sensitive data. The group said it was not seeking payment in the FBI incident, instead demanding changes to what it described as false allegations and disputing links to The Com.

Research from Sekoia and Beazley Security traces the brand's lineage to TheDarkOverlord and GnosticPlayers, groups associated with data theft and extortion. The ShinyHunters name surfaced publicly around April or May 2020. The researchers characterized it as a brand and business model that has persisted through arrests, indictments, and forum seizures rather than as a single fixed group.

They attributed that persistence to a division of labour: social engineers obtain initial access, adjacent actors amplify and recruit, and monetisation takes place under a recognisable name. For businesses, the reported arrests reinforce the need to limit vendor access, monitor cloud-based data movement, and prepare incident response plans for extortion following data theft.

#cybersecurity#databreach#extortion#threatintel
Open analytics
On the site 0 views
min read 3 04.10.2026
Instagram

Jordan reportedly detains suspected ShinyHunters member Rey

Open the post on Instagram ↗