Jordan Detains Alleged ShinyHunters Member 'Rey' in FBI-Linked Operation

A suspect tied to the prolific extortion crew is reportedly cooperating with U.S. investigators after a September arrest.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit interrogation room with an empty metal chair under a hanging ceiling lamp, muted blue and
Share

Key points

  • A suspected ShinyHunters member using the handle "Rey," reportedly named Saif al-Din Khader, was detained in Jordan on September 29, 2026, according to Reuters sources.
  • The suspect is said to be cooperating with the U.S. Federal Bureau of Investigation to identify other members of the group.
  • No U.S. Indictment has been unsealed publicly, and Jordanian authorities have not issued a formal statement naming the suspect.
  • We've published 24 stories on ShinyHunters in the last 90 days, and this arrest lands one day after we reported the group's claim to have breached FBI systems itself.

An alleged member of the ShinyHunters extortion crew has been detained in Jordan and is reportedly helping U.S. Investigators map the rest of the group, according to Reuters as picked up by The Hacker News.

The suspect used the handle "Rey" on criminal forums. Three people familiar with the matter told Reuters he was taken into custody on September 29, 2026. His real name is given as Saif al-Din Khader. He's cooperating with the FBI, the federal agency that leads major cybercrime investigations.

Neither the FBI nor Jordan's Public Security Directorate has published a statement confirming the arrest. No charging document has appeared on the U.S. Department of Justice's public docket.

Who are ShinyHunters?

ShinyHunters is a criminal crew that steals large databases from companies and pressures those companies to pay by threatening to publish the stolen data on a public leak site. The group has been active in various forms since 2020 and has been linked to a string of high-profile thefts involving cloud-hosted customer records.

Not every claim on their extortion page is accurate. Some listings recycle data from older breaches or from other gangs entirely.

Why does this arrest matter?

If the cooperation reporting holds up, it's the kind of arrest that can unravel a group rather than merely dent it. ShinyHunters operates as a loose crew that trades access and infrastructure with other criminals, so a cooperating insider can hand investigators handles, wallet addresses and chat logs reaching well beyond one person.

Past takedowns of data-theft crews have produced short pauses followed by rebrands. The Lapsus$ arrests in 2022 and 2023 are the closest comparison: public claims dropped, then similar tactics reappeared under new names. The timing here is striking. Just one day before Rey's detention, we reported that ShinyHunters itself was claiming to have breached FBI systems using a critical Oracle vulnerability. Whether that claim was bluster, a distraction or something else is now a sharper question.

Detail Reported figure
Date of detention September 29, 2026
Country of arrest Jordan
Suspect alias Rey
Reported real name Saif al-Din Khader
Cooperating agency U.S. FBI

Common questions

Should I do anything if my data was in a ShinyHunters leak?

Treat it like any other breach exposure. Change the password for the affected service, turn on two-factor authentication where offered, and watch for phishing emails that reference details only the breached company would know.

Does an arrest mean the leak site goes offline?

Not automatically. Leak sites tied to loose crews often stay up after individual arrests because other members hold the keys. A full takedown usually requires coordinated action against the hosting infrastructure, and that hasn't been reported here.

© 2026 Threat Vectr