A ShinyHunters arrest has landed at an awkward moment for the group. According to a Reuters report, a suspected member who goes by “Rey” was detained in Jordan this week and is now helping the FBI. Reuters names him as Saif al-Din Khader and cites sources familiar with the matter. Nothing has been announced officially.

Table of Contents
What has been reported
Reuters says Jordanian authorities took Khader into custody on Tuesday. Other outlets put the date at 29 September. One source told the agency he is “walking investigators through his electronic devices and digital correspondence” to help the FBI find others in the group. Another said his cooperation is “critical to ongoing efforts to arrest these hackers.”
The FBI has not confirmed the detention. It did say it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters” and has already worked with partners to arrest multiple subjects. Reuters adds that FBI Director Kash Patel has indicated more arrests are coming.
The timing matters because ShinyHunters claims to have stolen data on every FBI employee. That claim comes from the group and the FBI has not confirmed the theft. BleepingComputer reports the group says it took two to three terabytes through a flaw in Oracle PeopleSoft. We have not been able to verify that figure ourselves.
Who is Rey?
This is not the first time the alias has surfaced. In November 2025, the journalist Brian Krebs identified Rey as one of three administrators of the Scattered LAPSUS$ Hunters collective. Krebs also reported that Rey had run data leak sites for the Hellcat ransomware gang and for BreachForums.
Rey told Krebs he had been talking to law enforcement since June 2025 and had stopped breaching companies in September of that year. Krebs could not verify those claims. The group kept hitting targets well into 2026, so the detention does not tell us how long the cooperation has really lasted.
It also follows a Dutch arrest. Police in Amsterdam detained a 24-year-old man in September, later named as Pepijn van der Stap, in connection with the same group. DataBreaches.Net has more on the background, including how security firm Kela first linked Khader to the alias.
Will the ShinyHunters arrest slow the attacks?
Probably not soon. BleepingComputer notes that the group’s leak site went offline on Tuesday, the same day as the detention, and that a new one appeared on Thursday. That looks like a group that is rattled but still working.
Each ShinyHunters arrest is slow to pay off. Each arrest gives investigators devices, chat logs and contacts. Those take months to turn into charges. Meanwhile the people who remain free have every reason to move fast and burn what access they already hold.
What ShinyHunters actually does
The group is best known for stealing data and then extorting the victim, rather than locking systems. The group has breached more than 140 organisations and extorted about $70 million. The method is often unglamorous. Staff get phoned or messaged by someone posing as IT support and talk themselves into handing over a login or approving an access request.
That is why one ShinyHunters arrest should not make a UK business relax. The tools are cheap and the scripts are shared. The technique works on people, not firewalls. A group can lose a leader and the playbook stays in circulation.
What UK organisations should check now
You do not need to be an FBI-sized target to be worth a call. Here is a short list that fits this style of attack.
- Help desk verification. Can a caller reset a password or enrol a new MFA device with only a name and an employee number? Fix that first.
- SaaS and single sign-on logs. Look for unusual sign-ins, new device registrations and large exports from cloud platforms.
- Third-party access. List which suppliers can reach your data, and what happens if one of them is breached.
- Patch exposure. Our write-up on the Oracle PeopleSoft breach shows how long a window attackers can get between disclosure and a fix reaching customers.
- Staff awareness, tested. Policy documents do not stop a convincing phone call. A social engineering assessment shows whether your own people would hold the line.
Our view
Treat this ShinyHunters arrest as a sign that the investigation is moving, not as proof the threat has gone. The reports so far come from anonymous sources, and the FBI has said little. Expect more names, more arrests and probably more leak-site activity over the coming weeks.
If you want to know how your own help desk and staff would fare against this style of attack, get in touch with Aardwolf Security and we can scope a test that fits your size and budget.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.