A suspected member of the ShinyHunters digital extortion group, who goes by the web alias “Rey,” has been allegedly detained by authorities in Jordan, Reuters reported, citing three folks acquainted with the matter.
Rey, whose actual title is Saif al-Din Khader, is alleged to have been introduced into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and regulation enforcement to determine different members of the group.
“His cooperation is important to ongoing efforts to arrest these hackers,” a supply instructed the information company.
Rey, who additionally glided by the web alias ReyXBF, will not be an unknown face. In a report printed in November 2025, unbiased safety journalist Brian Krebs labeled him as one of many three directors of Scattered LAPSUS$ Hunters (SLH or SLSH), a bunch that is assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.
“Beforehand, Rey was an administrator of the info leak web site for Hellcat, a ransomware group that surfaced in late 2024,” Krebs famous on the time. “Additionally in 2024, Rey would take over as administrator of the newest incarnation of BreachForums.” Khader additionally instructed Krebs that he had been cooperating with regulation enforcement since a minimum of June 2025.
The event is the most recent motion within the ShinyHunters saga, which additionally noticed the arrest of a 24-year-old Amsterdam man final week for his or her involvement within the menace actor’s malicious cyber operations.
Though his id has not been disclosed, unbiased experiences revealed that it was Pepijn van der Stap, a reformed hacker who has been employed as an offensive safety lead on the Dutch firm Neo Safety. A ShinyHunters spokesperson subsequently denied having any connections with van der Stap.
Following the arrest, FBI director Kash Patel mentioned, “FBI groups are actively working with companions to acquire and execute extra leads within the ongoing investigation based mostly on this arrest.” In a follow-up X publish, Patel mentioned, “FBI groups are working new leads RIGHT NOW. Extra arrests are on the desk.”
In latest weeks, the prolific hacking crew has come underneath the highlight for hijacking the darknet web site of a fellow cybercriminal outfit, Cl0p, by exploiting an unpatched flaw in Grav CMS and its hack of the FBI’s “apply.fbijobs[.]gov” portal, stealing round three terabytes of delicate knowledge.
ShinyHunters insisted that it isn’t in search of a financial payoff within the FBI case, however somewhat apply stress on the FBI to amend what it mentioned had been false allegations in regards to the group and problem claims made by the company about its connections with The Com, a loose-knit cybercrime collective infamous for social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, and bodily violence.
“Since final 12 months, this cybercriminal and his co-conspirators have allegedly breached greater than 140 organizations and brought a minimum of $70 million in extortion funds,” Brett Leatherman, assistant director of the FBI’s cyber division, mentioned in a recorded assertion. “They usually goal third-party distributors in cloud-based platforms, stealing delicate knowledge and extort victims with threats to publish it.”
Leatherman, who described van der Stap as an alleged chief of the group, additionally urged different members to talk out and mentioned that they’ll now not disguise behind perceived worldwide anonymity and evade detection.
“Arrests have a means of adjusting who’s keen to speak, and seized infrastructure has a means of displaying us who’s left. The longer you keep on this, the extra we study you,” Leatherman added. “You understand how to seek out us, and we all know the best way to discover you. I counsel you attain out first whereas the selection remains to be yours.”
In a deep-dive report tracing ShinyHunters’ origins and their tactical evolution, cybersecurity corporations Sekoia and Beazley Safety mentioned its lineage goes again to 2 progenitor hacking teams, TheDarkOverlord and GnosticPlayers, that specialised in extortion and knowledge leak operations. The ShinyHunters model emerged publicly round April or Might 2020.
“Six years on, ShinyHunters is much less a bunch than a model and enterprise mannequin that has outlived its founders,” researchers Enzo Saez and Robert (Bobby) Venal mentioned. “What started in 2020 as a small crew buying and selling stolen databases on RaidForums has turn out to be a persistent, self-renewing group that has absorbed indictments, arrests, and discussion board seizures with out ever going quiet for lengthy.”
“That resilience is the actual story. It does not come from any single chief or cell, however from a division of labor that has turn out to be virtually modular: preliminary entry from social engineers, amplification and recruitment from adjoining actors, and monetization underneath a shared, recognizable model.”










