An Insider Joins the Hunt for ShinyHunters
The hunt for ShinyHunters has unexpectedly gained an insider. Authorities in Jordan detained Saif al-Din Khader, who is believed to be a member of the group.
According to sources, Khader is now helping the FBI. He is said to be assisting the search for other members and the analysis of the community’s digital traces.
What the Sources Say
Three sources familiar with the case told Reuters about the detention and the cooperation. Two of them say he was taken into custody on September 29.
The circumstances of the arrest and his place of detention remain unknown. One source said Khader is showing investigators his devices and messages. The aim is to help identify his alleged accomplices.
The FBI Stays Silent on the Arrest
The FBI did not confirm a specific arrest abroad. It said only that it continues to investigate a recent cyber incident allegedly linked to ShinyHunters. It added that it has already worked with partners to detain several suspects.
Earlier, Dutch authorities detained a man also tied to the group. A court kept that suspect in custody for another 90 days.
Who Is Khader
Khader is linked to the alias Rey. His name appeared in material about Scattered Lapsus$ Hunters. That collective brought together members of several well-known extortion and hacking communities.
Back in 2025, journalist Brian Krebs reported that Khader spoke of quitting hacking and cooperating with law enforcement. Even so, ShinyHunters kept up its attacks in 2026.
The Claimed FBI Breach
The new detention followed a loud claim by ShinyHunters that it had breached the FBI. The group says it obtained data on every bureau employee.
Journalists examined a sample of the stolen information. They found personal details and job data, as well as medical and psychiatric information. However, no one has independently confirmed the full scale of the claimed leak.
The PeopleSoft Angle
In recent weeks, ShinyHunters also attacked PeopleSoft. It bypassed security filters with modified URLs. The group claimed it used PeopleSoft against the FBI too.
Yet no one has confirmed a link between that specific vulnerability and the bureau incident. Therefore, the existence of stolen data and the alleged method of entry should be kept apart for now.
Disruptions Hit the Group’s Infrastructure
After Khader’s detention, noticeable outages hit ShinyHunters infrastructure. From September 29, journalists could not reach the group through its usual account. On September 30, the group’s dark web site vanished.
Group representatives later blamed the shutdown on sabotage by rivals and on a separate, unrelated incident. No link to Khader’s detention has been established.
Why His Cooperation Matters
Khader’s cooperation could give investigators more than one more arrest. Access to his devices and messages may help map ties inside a scattered network. Its members often operate under shifting names and aliases.
The FBI has not publicly confirmed Khader’s role. As a result, his involvement in ShinyHunters remains an allegation.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!