Suspected ShinyHunters Member "Rey" Reportedly Detained in Jordan, Cooperating with FBI
What happened
Reuters reports, citing three people familiar with the matter, that a suspected member of the ShinyHunters digital extortion group known by the alias "Rey" was detained by authorities in Jordan. The individual is identified as Saif al-Din Khader and is said to have been taken into custody on September 29, 2026. According to the report, Rey is cooperating with the U.S. Federal Bureau of Investigation (FBI) to help identify other members of the group.
These details come from sourcing described as people familiar with the matter rather than an official law enforcement statement, so specifics of the arrest, charges, and the scope of cooperation remain unconfirmed and may evolve as the story develops.
Why it matters for defenders
ShinyHunters has been linked to large-scale data theft and extortion campaigns against numerous organizations, often involving stolen customer and corporate data later sold or leveraged for extortion. A detained member cooperating with the FBI could lead to further arrests, infrastructure takedowns, or the exposure of tactics, tooling, and victim lists used by the group. Organizations that have previously dealt with ShinyHunters-linked incidents, or that hold data types the group has historically targeted, should treat this as a signal that related investigations and disclosures may follow.
Who may be affected
- Organizations with past or ongoing extortion incidents attributed to ShinyHunters
- Companies whose data may surface in cooperating-witness disclosures to law enforcement
- Security teams tracking the broader extortion/data-leak ecosystem this group operates within
What defenders should watch for now
- Monitor threat intel feeds and law enforcement advisories for follow-on arrests or indictments tied to ShinyHunters as the FBI investigation progresses
- Review any prior incident response findings or IOCs associated with ShinyHunters activity in your environment for reassessment
- Watch dark-web and extortion-leak sites for unusual activity, such as rushed data dumps, that sometimes follows law enforcement pressure on a group
- Reinforce standard defenses against the group's known playbook — credential theft, social engineering/vishing against help desks, and third-party/SaaS data exfiltration — since member cooperation does not immediately dismantle group capability or copycat activity
Developing story
This is based on a single news report sourced to unnamed individuals and has not been independently verified through official channels at the time of writing. Details may change as more information becomes available. For the original reporting, see The Hacker News.