ShinyHunters Suspect Detained, Cooperating with FBI

Suspected ShinyHunters Hacker 'Rey' Detained in Jordan

MEDIUM
October 4, 2026
3m read
Threat ActorData Breach

Related Entities

Threat Actors

ShinyHunters Scattered LAPSUS$ HuntersHellcat

Other

Saif al-Din KhaderReyBreachForumsPepijn van der Stap

Full Report

Executive Summary

In a significant law enforcement victory against cybercrime, a key suspect linked to the notorious ShinyHunters data extortion group has been detained in Jordan. The suspect, identified as Saif al-Din Khader (allegedly known online as "Rey"), was taken into custody around September 29, 2026. Sources familiar with the investigation report that Khader is actively cooperating with the Federal Bureau of Investigation (FBI), providing crucial information to help identify and locate other members of the group. This development follows ShinyHunters' audacious claim in September 2026 that it had breached FBI systems, and it represents a major disruption to the group's operations.


Threat Overview

ShinyHunters is a well-known threat actor group responsible for numerous high-profile data breaches and the subsequent sale or leakage of stolen data on dark web forums. Their operations typically involve gaining unauthorized access to corporate networks, exfiltrating large databases, and then extorting the victims or selling the data. The group has been linked to breaches at companies like Microsoft, AT&T, and Ticketmaster.

The detention of Khader is directly linked to the group's recent claim of hacking the FBI itself and stealing 2-3 TB of sensitive data, including PII of FBI personnel. Khader's alleged cooperation is seen as a critical breakthrough, potentially leading to further arrests and the dismantling of the group's infrastructure. Following his detention, the ShinyHunters leak site on the dark web became inaccessible, suggesting a direct impact on their operations.

Technical Analysis

This article focuses on law enforcement action rather than technical TTPs. However, ShinyHunters' typical modus operandi involves:

  • Initial Access: Exploiting vulnerabilities in public-facing applications (T1190 - Exploit Public-Facing Application) or using stolen credentials purchased from other cybercriminals.
  • Collection: Targeting and exfiltrating large user databases from compromised networks (T1213 - Data from Information Repositories).
  • Monetization: The group operates on a data extortion model, threatening to release data unless a ransom is paid. They also frequently sell stolen data on criminal marketplaces. This aligns with T1657 - Financial Theft.

Khader was also reportedly an administrator for other criminal forums like Hellcat and BreachForums, highlighting the interconnected nature of the cybercrime ecosystem.

Impact Assessment

The detention and cooperation of a key member like "Rey" is a significant blow to ShinyHunters and potentially affiliated groups. It disrupts their immediate operations, as evidenced by their leak site going offline. More importantly, the intelligence provided could lead to a cascading series of arrests, dismantling a significant portion of this cybercrime network. This action serves as a strong deterrent and demonstrates the effectiveness of international law enforcement cooperation in tracking down and apprehending major threat actors.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) were mentioned in the source articles.

Detection & Response

Detection and response are not directly applicable to this law enforcement story. However, defending against groups like ShinyHunters involves robust perimeter security, vulnerability management, and data exfiltration detection.

Mitigation

Standard mitigation against data breach actors like ShinyHunters includes:

  • Strong Credential Policies: Enforcing MFA and strong, unique passwords to prevent credential stuffing and reuse.
  • Vulnerability Management: Aggressively patching public-facing systems to prevent exploitation.
  • Data Exfiltration Controls: Implementing Data Loss Prevention (DLP) and network monitoring to detect and block large, unauthorized data transfers.

Timeline of Events

1
September 29, 2026
Suspected ShinyHunters member Saif al-Din Khader is reportedly detained in Jordan.
2
October 4, 2026
This article was published

MITRE ATT&CK Mitigations

Regularly patching public-facing applications is a key defense against the initial access methods used by groups like ShinyHunters.

Enforcing MFA prevents attackers from using stolen or weak credentials to gain access to systems.

Monitoring and filtering outbound network traffic can help detect and block data exfiltration attempts.

Timeline of Events

1
September 29, 2026

Suspected ShinyHunters member Saif al-Din Khader is reportedly detained in Jordan.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

ShinyHuntersThreat ActorCybercrimeFBILaw EnforcementArrestData Breach

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.