An alleged key ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers after the group’s claimed FBI data breach.

Key ShinyHunters Suspect Detained in Jordan, Reportedly Cooperating With FBI After FBI Data Theft

The420 Web Correspondent
9 Min Read

A suspected key member of the ShinyHunters hacking group has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group, according to people familiar with the investigation.

Reuters identified the suspect as Saif al-Din Khader, whose alleged hacker alias is “Rey”.

Three sources told Reuters that Jordanian authorities detained Khader this week. Two said he was taken into custody on Tuesday and is now assisting the FBI and other law-enforcement agencies in locating alleged ShinyHunters members.

The detention represents a major new development in the international investigation into ShinyHunters following the group’s claim that it stole sensitive information connected to FBI personnel.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Suspect Reportedly Helping Investigators Identify Other Hackers

Reuters could not independently establish the circumstances under which Khader was detained or where he is currently being held.

However, two sources said he is cooperating with investigators.

One source said Khader was walking law-enforcement officials through his electronic devices and digital communications to help identify other members of the network.

The FBI declined to discuss the specific detention.

It said, however, that it continues to investigate the recent cyber incident allegedly involving ShinyHunters and has already worked with international partners to arrest multiple suspects.

Khader and members of his family could not be reached by Reuters for comment.

ShinyHunters Claims It Stole Data on Every FBI Employee

The detention follows ShinyHunters’ extraordinary claim that it compromised systems linked to the FBI and obtained data relating to every bureau employee.

The420.in reported last month that the group claimed to have accessed FBI recruitment and personnel-related systems and stolen sensitive information connected to employees and job applicants.

ShinyHunters later claimed that around 38,000 FBI personnel were affected.

The full scale of the breach has not been independently confirmed.

But Reuters analysed a sample of data released by the group and found that it contained extensive personally identifiable information, sensitive job-role information and psychiatric and medical details belonging to FBI personnel.

That makes the alleged breach particularly serious because such information could potentially be used for identity theft, coercion, targeted phishing or intelligence gathering.

Sensitive Medical and Personal Records Raise National Security Concerns

The type of information allegedly exposed goes far beyond ordinary corporate customer data.

FBI employees can hold sensitive investigative, intelligence and national-security roles.

If attackers obtain home addresses, medical histories, family information or detailed job functions, the information could potentially be used to identify vulnerable personnel or target individuals with highly convincing social-engineering attacks.

Reuters said the scale of the incident has prompted comparisons with the 2015 breach of the US Office of Personnel Management.

That attack exposed highly sensitive records belonging to millions of people who had undergone federal security-clearance background checks.

The comparison does not mean the two incidents are equivalent in scale or attribution.

The final extent of the ShinyHunters breach remains under investigation.

Jordan Detention Follows Separate Arrest in Netherlands

Khader’s detention comes shortly after Dutch authorities arrested 24-year-old Pepijn van der Stap in a separate ShinyHunters investigation.

The420.in previously reported that Dutch police arrested Van der Stap on September 15 and seized electronic devices during the operation.

The arrest occurred before ShinyHunters publicly claimed responsibility for the FBI breach.

Dutch authorities suspect Van der Stap of links to the cybercrime group, although ShinyHunters publicly denied that he was a member.

Reuters reported that FBI Director Kash Patel later said investigators were actively pursuing new leads and that more arrests could follow.

Khader’s detention now appears to be another part of that wider international operation.

ShinyHunters’ Online Presence Suddenly Disrupted

There have also been signs that the group itself may be facing internal disruption.

Reuters said journalists lost contact with ShinyHunters through an online account the group had previously used for communication beginning Tuesday.

A day later, its dark-web website disappeared.

The site had previously been used to issue threats and publish material connected with the group’s alleged attacks.

ShinyHunters later told Reuters through another email address that the website went offline because of sabotage by rivals and disruption caused by an unrelated incident.

The group did not respond to Reuters’ latest request for comment.

Group Appears to Back Away From Confrontation With FBI

ShinyHunters had initially taken an aggressive public position after claiming the FBI breach.

The group said its attack was retaliation for an FBI cyber advisory that accused ShinyHunters of exaggerating the level of access it obtained during some attacks to pressure victims into paying extortion demands.

ShinyHunters gave the FBI a one-week deadline to withdraw the advisory.

The bureau did not comply.

But the group’s tone later changed sharply.

In a subsequent message to Reuters, its operators said they wanted no further escalation with the FBI and indicated that the statement could be interpreted as ShinyHunters “backing down completely”.

That shift came as arrests and other investigative activity intensified.

Who Is Saif al-Din Khader?

Khader’s alleged connection to the hacking ecosystem was known before the latest FBI investigation.

Reuters reported that cybersecurity researchers had previously identified him as a suspected member of Scattered Lapsus$ Hunters, an umbrella-style hacking community associated with ShinyHunters and other English-speaking cybercrime groups.

Independent cybersecurity journalist Brian Krebs had reported in 2025 that Khader claimed he had left data theft and extortion behind and was cooperating with law enforcement.

However, ShinyHunters continued launching or claiming major attacks during 2026.

The group has claimed breaches involving Rockstar Games and the Canvas education platform, among other targets.

Khader’s exact role in those incidents has not been established publicly.

Why ShinyHunters Is Difficult to Investigate

ShinyHunters does not operate like a traditional company or a tightly controlled ransomware gang.

Cybersecurity researchers describe it as part of a loose ecosystem of mostly young English-speaking hackers who collaborate, split into smaller groups and sometimes use multiple overlapping names.

That structure can make attribution difficult.

A person may interact with several hacking communities without being a formal member of any single organisation.

Reuters reported that law-enforcement agencies have struggled to prosecute people linked to ShinyHunters, Lapsus$ and Scattered Spider because of the groups’ informal structure, the young age of some suspects and difficulties securing cooperation from victims.

That is why access to one alleged member’s communications and devices could be particularly valuable.

Investigators may be able to reconstruct identities, online aliases and relationships between people who otherwise communicate through encrypted or anonymous platforms.

Cooperation Could Expose Wider Cybercrime Network

If Khader is genuinely cooperating, the investigation could move beyond the FBI breach itself.

His devices and conversations could potentially provide investigators with information about infrastructure, accomplices, previous victims and links between ShinyHunters and related cybercrime communities.

However, the extent of that cooperation remains based on unnamed sources.

Neither the FBI nor Jordanian authorities have publicly confirmed the detailed claims regarding what information Khader is providing.

His detention also does not establish criminal liability.

The allegations against him remain subject to investigation and any future judicial proceedings.

What this means for you

Major hacking groups increasingly operate as loose networks rather than clearly defined organisations, which makes individual arrests difficult to interpret. But when investigators gain access to one suspect’s devices and communications, it can expose connections between aliases, accounts and attacks that were previously difficult to link.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected