Jordanian authorities arrested this week, according to two sources who spoke to Reuters, Saif al-Din Khader, known online as Rey, a person suspected of being linked to the ShinyHunters cyber theft and extortion group. According to the same sources, Khader is currently cooperating with the FBI and international law enforcement agencies, showing investigators his electronic devices and digital correspondence to help identify his alleged associates and their locations.
According to the available material, Jordanian authorities and the FBI have not officially confirmed the details of the arrest or the nature of the cooperation. BleepingComputer was also unable to independently verify all claims related to the group’s activities, including the volume of data allegedly stolen in its purported attack on FBI systems.
New Arrest After Alleged Attack on FBI
Khader’s arrest comes amid a U.S. and international campaign against ShinyHunters, which claimed in September to have breached FBI systems using an alleged zero-day vulnerability in Oracle PeopleSoft, then moved within AWS GovCloud environments managed by the agency. The group said it stole between 2 and 3 terabytes of data, including information on current and former employees and job applicants, as well as medical and psychological data and records from internal services.
The FBI confirmed that it was investigating claims of unauthorized activity but did not confirm data theft. On September 15, Dutch police arrested a 24-year-old man in Amsterdam as part of an investigation linked to the group; security reports identified him as Pepijn van der Stap, known by the alias Umbreon.
Was the Group’s Infrastructure Disrupted?
Signs of disruption within ShinyHunters’ activity appeared on the day of Khader’s arrest. An account associated with one alleged affiliate was shut down, after which the group’s data-leak site became unavailable, and its primary representative stopped responding to media inquiries. This does not prove that these developments resulted from the arrest, as a new leak site bearing the ShinyHunters name appeared on Thursday, indicating that other members remain capable of operating the operation.
ShinyHunters representatives also did not respond to BleepingComputer’s inquiries about the arrest. The FBI had publicly warned the group’s members, noting that arrests and infrastructure seizures could prompt more participants to cooperate.
Who Is Rey?
Previous reports linked the name Rey to multiple data-theft and extortion attacks. In January 2025, four attackers, including Rey, claimed responsibility for breaching Telefónica’s internal Jira system and stealing approximately 2.3 gigabytes of documents and data. He was also linked to an attack on Orange’s operations in Romania, followed by the leak of approximately 6.5 gigabytes of data, and to a series of attacks targeting Jira servers around the world.
Rey was later linked to ShinyHunters and to Telegram channels belonging to an entity called Scattered Lapsus$ Hunters. In November 2025, journalist Brian Krebs said that information from infostealer logs and direct conversations led him to identify Rey as Saif Al-Din Khader. He reported that Khader had been cooperating with law enforcement agencies since June, but noted that he was unable to verify these claims.
Why Does This Matter?
If confirmed, the information could give investigators access through a person with alleged operational ties to the group to the devices, accounts, and digital relationships used in attacks targeting cloud services and SaaS platforms. However, the appearance of a new leak site shows that the arrest of one individual does not necessarily mean the operation has stopped, while Khader’s connection to all attacks attributed to ShinyHunters and the extent of the value of his cooperation still require official confirmation and verifiable evidence.