A suspected member of the ShinyHunters digital extortion group, who goes by the online alias “Rey,” has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter.
Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and law enforcement to identify other members of the group.
“His cooperation is critical to ongoing efforts to arrest these hackers,” a source told the news agency.
Rey, who also went by the online alias ReyXBF, is not an unknown face. In a report published in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of Scattered LAPSUS$ Hunters (SLH or SLSH), a group that’s assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.
“Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024,” Krebs noted at the time. “Also in 2024, Rey would take over as administrator of the most recent incarnation of BreachForums.” Khader also told Krebs that he had been cooperating with law enforcement since at least June 2025.
The development is the latest action in the ShinyHunters saga, which also saw the arrest of a 24-year-old Amsterdam man last week for their involvement in the threat actor’s malicious cyber operations.
Although his identity has not been disclosed, independent reports revealed that it was Pepijn van der Stap, a reformed hacker who has been employed as an offensive security lead at the Dutch company Neo Security. A ShinyHunters spokesperson subsequently denied having any connections with van der Stap.
Following the arrest, FBI director Kash Patel said, “FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest.” In a follow-up X post, Patel said, “FBI teams are working new leads RIGHT NOW. More arrests are on the table.”
In recent weeks, the prolific hacking crew has come under the spotlight for hijacking the darknet website of a fellow cybercriminal outfit, Cl0p, by exploiting an unpatched flaw in Grav CMS and its hack of the FBI’s “apply.fbijobs[.]gov” portal, stealing around three terabytes of sensitive data.
ShinyHunters insisted that it’s not seeking a monetary payoff in the FBI case, but rather apply pressure on the FBI to amend what it said were false allegations about the group and challenge claims made by the agency about its connections with The Com, a loose-knit cybercrime collective notorious for social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, and physical violence.
“Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a recorded statement. “They often target third-party vendors in cloud-based platforms, stealing sensitive data and extort victims with threats to publish it.”
Leatherman, who described van der Stap as an alleged leader of the group, also urged other members to speak out and said that they can no longer hide behind perceived international anonymity and evade detection.
“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you,” Leatherman added. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
In a deep-dive report tracing ShinyHunters’ origins and their tactical evolution, cybersecurity companies Sekoia and Beazley Security said its lineage goes back to two progenitor hacking groups, TheDarkOverlord and GnosticPlayers, that specialized in extortion and data leak operations. The ShinyHunters brand emerged publicly around April or May 2020.
“Six years on, ShinyHunters is less a group than a brand and business model that has outlived its founders,” researchers Enzo Saez and Robert (Bobby) Venal said. “What began in 2020 as a small crew trading stolen databases on RaidForums has become a persistent, self-renewing group that has absorbed indictments, arrests, and forum seizures without ever going quiet for long.”
“That resilience is the real story. It doesn’t come from any single leader or cell, but from a division of labor that has become almost modular: initial access from social engineers, amplification and recruitment from adjacent actors, and monetization under a shared, recognizable brand.”