← Blog · · df00tech

ShinyHunters Suspect 'Rey' Reportedly Detained in Jordan, Cooperating with FBI

security-news campaign

What happened

According to BleepingComputer, a suspected member of the ShinyHunters extortion group, known online by the alias "Rey," has reportedly been detained in Jordan. The report states this individual is cooperating with the FBI to help identify and locate other members of the group. Details on the arrest, timeline, and scope of cooperation remain limited at this stage.

Why it matters for defenders

ShinyHunters has been linked to a string of high-profile data breach and extortion campaigns over the past several years, frequently involving stolen databases sold or leaked for extortion leverage. A detained member cooperating with law enforcement could lead to further arrests, disruption of the group's infrastructure, or exposure of tooling and tactics — but it could also prompt remaining members to accelerate activity, change infrastructure, or rebrand to evade attention. Organizations that have previously been targeted or extorted by ShinyHunters-linked activity should treat this as a signal to review exposure, not as confirmation that the threat has subsided.

What defenders should watch for now

  • Monitor threat intel and leak-site trackers for ShinyHunters rebranding, new aliases, or shifts in extortion infrastructure following this disclosure.
  • Review any prior incident history or data exposure tied to ShinyHunters campaigns for signs of renewed activity or follow-on extortion attempts.
  • Watch for opportunistic activity from other extortion groups that may attempt to fill any operational gap.
  • Continue baseline hunting for large-scale data exfiltration patterns (bulk database queries, unusual export volumes, anomalous API/service account access) that are common precursors to this type of extortion activity, independent of attribution.

Developing story

This is based on a single news report and details — including the suspect's identity, the specifics of any cooperation agreement, and downstream effects on the group's operations — may evolve or be revised. No CVE or specific technical indicator is associated with this item. For the original reporting, see BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.