Threat Intelligence

Jordan Detains ShinyHunters Member "Rey", FBI Gains Insider

⏱️ 4 min read📅 10/4/2026👁️ 1 views

Jordan detains key ShinyHunters operative, FBI gains insider

Jordanian authorities have taken Saif al‑Din Khader, aka “Rey”, into custody, and the FBI says the hacker is already feeding it information.

Why the arrest matters

Rey was one of the most active members of the ShinyHunters forum, a marketplace that trades stolen data from dozens of high‑profile vendors. His detention could force the group’s infrastructure offline, as the public leak site vanished shortly after the arrest.

Verified breaches linked to Rey

Investigations tie Rey to two recent intrusions:

  • A breach of Telefónica’s internal Jira system in January 2025, confirmed by BleepingComputer.
  • Orange’s Romanian operations suffered a cyberattack in February 2025 after data allegedly leaked by Rey.

Separately, Jaguar Land Rover reported a September 2025 attack claimed by the Scattered Lapsus$ Hunters, a group that has collaborated with ShinyHunters in the past.

Unverified claims floating around

Some members of the ShinyHunters community have boasted about compromising FBI systems via an alleged Oracle PeopleSoft zero‑day and exfiltrating 2–3 TB of data. Both the vulnerability use and the data volume remain unverified, and the FBI has only confirmed it is investigating “unauthorized activity” without confirming any theft.

Other arrests

Dutch police apprehended Pepijn van der Stap, known as “Umbreon”, on 15 September. KrebsOnSecurity and DataBreaches identified him as a ShinyHunters affiliate, indicating a coordinated law‑enforcement push against the forum.

What defenders should do now

Even if Rey’s cooperation curtails the group’s operations, the fallout may still surface:

  1. Assume that any data previously posted on the ShinyHunters leak site could be re‑published on a new platform. Scan for credential dumps related to the listed products.
  2. Prioritize patching and monitoring for signs of compromise on systems mentioned in the verified breaches—Jira instances, Oracle PeopleSoft, and any AWS GovCloud workloads.
  3. Review privileged access logs for unusual lateral movement, especially from accounts that accessed PeopleSoft or AWS resources.
  4. Engage with incident‑response teams early if you see evidence of data from the listed vendors appearing in underground forums.

Outlook

The detention of a high‑profile insider is a rare win for law enforcement, but the ShinyHunters ecosystem is resilient. Expect new leak sites to emerge and possibly fresh claims of high‑value breaches. Staying vigilant on the affected product stack is the safest bet.

#ShinyHunters#Jordan#FBI#DataLeak#Cybercrime