ShinyHunters Suspect Held in Jordan Is Cooperating After the Group Tried to Extort the FBI
FAFO: A suspected ShinyHunters member tied to the FBI employee-data theft is in custody and helping the bureau identify the rest of the crew.

A suspected ShinyHunters member whose crew claimed it stole data on FBI employees is in Jordanian custody and is helping the bureau identify the rest of the group, according to people familiar with the case.
Three sources told Reuters that Jordanian authorities detained Saif al-Din Khader this week. Two said he was taken in on Tuesday. Two said he is cooperating with the FBI and other agencies to locate other hackers. One source said he is walking investigators through his devices and communications, and called that cooperation critical to further arrests. Reuters could not determine where he is being held.
The FBI declined to confirm a specific arrest abroad. It said it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice.”
Khader has been publicly tied to the alias “Rey” since November 2025, when journalist Brian Krebs identified him as a teenager from Amman linked to Scattered LAPSUS$ Hunters, an alliance associated with ShinyHunters, Scattered Spider, and LAPSUS$. Krebs reported that Khader later said he was trying to distance himself from the alliance and claimed he had been cooperating with law enforcement since at least June. Reuters said attempts to reach Khader and his family over the past week and a half failed.
The detention follows a breach the group said was aimed at the FBI itself. On Sept. 22, ShinyHunters said it had hit the bureau and stolen data “on almost ALL FBI Agents, and individuals who filed an application with the FBI for a job.” It pointed to a defaced jobs page and a sample it said covered about 5,000 agents. Reuters partially verified names, home addresses, Social Security numbers, assignments, and, in some cases, family names against credit records and previously breached data. Later review found medical and psychiatric information in the stolen set. An internal FBI memo told staff to assume every employee may have been exposed.
The group said the intrusion was a response to a May 2026 FBI advisory that described ShinyHunters’ harassment and intimidation tactics and told victims not to pay. ShinyHunters set a deadline of the end of Tuesday, Sept. 29, for the bureau to revise or remove that advisory. The deadline passed. The advisory stayed up.
That same day, Cyber Division chief Brett Leatherman posted a video after Dutch authorities arrested a 24-year-old on suspicion of aiding data thefts and extortions tied to the group. Leatherman said other crews “believed anonymity or their friends would protect them, and they were wrong,” and told ShinyHunters: “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” Director Kash Patel posted as well. Leatherman said the group is believed to have breached more than 140 organizations and extorted $70 million since last year, often through vendors and cloud platforms.
The group told BleepingComputer it entered through an Oracle PeopleSoft flaw, then moved into FBI-managed Amazon Web Services GovCloud systems, and claimed 2 to 3 terabytes of data. The FBI has confirmed it is investigating unauthorized activity on FBIjobs.gov. It has not confirmed the full volume.
Support Independent Conservative News
RWTNews is independent conservative news — no corporate backing, no agenda driven by advertisers. We rely entirely on readers like you to keep the lights on and the truth coming. If you've found value in what you read here, consider supporting us with a one-time or monthly contribution. Every dollar goes directly toward keeping this site running and growing.
Secured by Stripe. Your payment info is never stored on our servers.
