In a significant law enforcement victory against cybercrime, a key suspect linked to the notorious ShinyHunters data extortion group has been detained in Jordan. The suspect, identified as Saif al-Din Khader (allegedly known online as "Rey"), was taken into custody around September 29, 2026. Sources familiar with the investigation report that Khader is actively cooperating with the Federal Bureau of Investigation (FBI), providing crucial information to help identify and locate other members of the group. This development follows ShinyHunters' audacious claim in September 2026 that it had breached FBI systems, and it represents a major disruption to the group's operations.
ShinyHunters is a well-known threat actor group responsible for numerous high-profile data breaches and the subsequent sale or leakage of stolen data on dark web forums. Their operations typically involve gaining unauthorized access to corporate networks, exfiltrating large databases, and then extorting the victims or selling the data. The group has been linked to breaches at companies like Microsoft, AT&T, and Ticketmaster.
The detention of Khader is directly linked to the group's recent claim of hacking the FBI itself and stealing 2-3 TB of sensitive data, including PII of FBI personnel. Khader's alleged cooperation is seen as a critical breakthrough, potentially leading to further arrests and the dismantling of the group's infrastructure. Following his detention, the ShinyHunters leak site on the dark web became inaccessible, suggesting a direct impact on their operations.
This article focuses on law enforcement action rather than technical TTPs. However, ShinyHunters' typical modus operandi involves:
T1190 - Exploit Public-Facing Application) or using stolen credentials purchased from other cybercriminals.T1213 - Data from Information Repositories).T1657 - Financial Theft.Khader was also reportedly an administrator for other criminal forums like Hellcat and BreachForums, highlighting the interconnected nature of the cybercrime ecosystem.
The detention and cooperation of a key member like "Rey" is a significant blow to ShinyHunters and potentially affiliated groups. It disrupts their immediate operations, as evidenced by their leak site going offline. More importantly, the intelligence provided could lead to a cascading series of arrests, dismantling a significant portion of this cybercrime network. This action serves as a strong deterrent and demonstrates the effectiveness of international law enforcement cooperation in tracking down and apprehending major threat actors.
No specific Indicators of Compromise (IOCs) were mentioned in the source articles.
Detection and response are not directly applicable to this law enforcement story. However, defending against groups like ShinyHunters involves robust perimeter security, vulnerability management, and data exfiltration detection.
Standard mitigation against data breach actors like ShinyHunters includes:
Regularly patching public-facing applications is a key defense against the initial access methods used by groups like ShinyHunters.
Enforcing MFA prevents attackers from using stolen or weak credentials to gain access to systems.
Monitoring and filtering outbound network traffic can help detect and block data exfiltration attempts.
Suspected ShinyHunters member Saif al-Din Khader is reportedly detained in Jordan.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.