ShinyHunters hacker reportedly detained in Jordan, aiding FBI
A suspected member of the ShinyHunters hacking group, known as Rey (Saif al-Din Khader), has been detained in Jordan and is cooperating with the FBI to help identify and locate other group members. ShinyHunters is an extortion group known for massive data thefts and attacks on cloud SaaS environments. The group claimed responsibility for a cyberattack on FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability, though this has not been independently verified. Following arrests and law enforcement pressure, ShinyHunters operations have shown signs of disruption, but some activity continues. Rey has been linked to multiple high-profile breaches and extortion campaigns over the past two years. Cooperation from detained members is aiding ongoing investigations and arrests.
AI Analysis
Technical Summary
The ShinyHunters hacking group, involved in extensive data theft and extortion campaigns targeting organizations worldwide, has suffered a significant law enforcement setback with the detention of a suspected member, Saif al-Din Khader (alias Rey), in Jordan. Khader is reportedly cooperating with the FBI and international agencies by providing access to his electronic devices and communications to help identify other members. The group claimed to have breached FBI systems via an alleged Oracle PeopleSoft zero-day vulnerability and accessed sensitive data, though these claims remain unverified. Prior arrests, including one in the Netherlands, and ongoing FBI investigations have pressured the group, causing temporary disruptions in their operations. ShinyHunters has a history of breaching cloud SaaS environments and third-party integrations, with notable attacks on companies like Google, Cisco, and Jaguar Land Rover. Rey has been linked to multiple breaches and ransomware operations, and his cooperation is considered critical to law enforcement efforts.
Potential Impact
The ShinyHunters group has conducted large-scale data thefts and extortion campaigns affecting numerous organizations globally, including breaches of sensitive data from FBI systems (alleged), cloud SaaS environments, and major corporations. The detention and cooperation of a key member potentially enable law enforcement to disrupt ongoing criminal activities and identify additional perpetrators. The group's operations have caused significant financial and operational impacts on victims, such as production halts and data leaks. However, some ShinyHunters activities appear to continue despite recent arrests.
Mitigation Recommendations
Law enforcement agencies are actively investigating and arresting members of the ShinyHunters group. Cooperation from detained individuals is aiding these efforts. Organizations should monitor official advisories and collaborate with law enforcement as appropriate. No specific technical patches or fixes apply to this threat actor activity; mitigation focuses on law enforcement disruption and incident response to breaches. The FBI has publicly urged remaining members to surrender, indicating ongoing pressure on the group.
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
Description
A suspected member of the ShinyHunters hacking group, known as Rey (Saif al-Din Khader), has been detained in Jordan and is cooperating with the FBI to help identify and locate other group members. ShinyHunters is an extortion group known for massive data thefts and attacks on cloud SaaS environments. The group claimed responsibility for a cyberattack on FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability, though this has not been independently verified. Following arrests and law enforcement pressure, ShinyHunters operations have shown signs of disruption, but some activity continues. Rey has been linked to multiple high-profile breaches and extortion campaigns over the past two years. Cooperation from detained members is aiding ongoing investigations and arrests.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ShinyHunters hacking group, involved in extensive data theft and extortion campaigns targeting organizations worldwide, has suffered a significant law enforcement setback with the detention of a suspected member, Saif al-Din Khader (alias Rey), in Jordan. Khader is reportedly cooperating with the FBI and international agencies by providing access to his electronic devices and communications to help identify other members. The group claimed to have breached FBI systems via an alleged Oracle PeopleSoft zero-day vulnerability and accessed sensitive data, though these claims remain unverified. Prior arrests, including one in the Netherlands, and ongoing FBI investigations have pressured the group, causing temporary disruptions in their operations. ShinyHunters has a history of breaching cloud SaaS environments and third-party integrations, with notable attacks on companies like Google, Cisco, and Jaguar Land Rover. Rey has been linked to multiple breaches and ransomware operations, and his cooperation is considered critical to law enforcement efforts.
Potential Impact
The ShinyHunters group has conducted large-scale data thefts and extortion campaigns affecting numerous organizations globally, including breaches of sensitive data from FBI systems (alleged), cloud SaaS environments, and major corporations. The detention and cooperation of a key member potentially enable law enforcement to disrupt ongoing criminal activities and identify additional perpetrators. The group's operations have caused significant financial and operational impacts on victims, such as production halts and data leaks. However, some ShinyHunters activities appear to continue despite recent arrests.
Defensive Guidance
Law enforcement agencies are actively investigating and arresting members of the ShinyHunters group. Cooperation from detained individuals is aiding these efforts. Organizations should monitor official advisories and collaborate with law enforcement as appropriate. No specific technical patches or fixes apply to this threat actor activity; mitigation focuses on law enforcement disruption and incident response to breaches. The FBI has publicly urged remaining members to surrender, indicating ongoing pressure on the group.
Technical Details
- Classification
- {"confidence":0.66,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/","fetched":true,"fetchedAt":"2026-10-03T19:16:16.891Z","wordCount":1354}
Threat ID: 6ac15480a43b0b3b89dfa85e
Added to database: 10/03/2026, 19:16:16 UTC
Last enriched: 10/03/2026, 19:16:22 UTC
Last updated: 10/04/2026, 03:45:28 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.