TL;DR
- what: Saif al-Din Khader, the alleged ShinyHunters and Scattered LAPSUS$ Hunters administrator known as Rey, was reportedly detained in Jordan on September 29, 2026 and is cooperating with the FBI.
- impact: The FBI says the wider crew allegedly breached more than 140 organizations and collected at least $70 million in extortion, often by going through third-party vendors on cloud platforms.
- fix: No patch applies here: the mitigation is shrinking the social engineering and third-party SaaS access paths the group exploits, because arrests have not stopped the brand before.
- who: Organizations that rely on cloud platforms and third-party vendors holding their sensitive data, and the help desks and identity teams that guard those accounts.
For years, the person behind the alias Rey sat at the center of the data extortion economy. He ran the leak site for the Hellcat ransomware group, took over the latest version of BreachForums, and was named as one of three administrators of Scattered LAPSUS$ Hunters. Now, according to Reuters, citing three people familiar with the matter, he is in custody in Jordan and helping the FBI name the people he used to work with.
Reuters identifies Rey as Saif al-Din Khader, also known as ReyXBF, and reports that he was taken into custody on September 29, 2026. "His cooperation is critical to ongoing efforts to arrest these hackers," one source told the agency. The Hacker News reported the development on October 4, 2026.
An insider who was already talking
Rey was not an unknown figure. In November 2025, independent journalist Brian Krebs named him as one of the three administrators of Scattered LAPSUS$ Hunters (SLH), a group assessed to be a merger of Scattered Spider, LAPSUS$, and ShinyHunters. Krebs also reported that Rey had been administrator of the Hellcat data leak site, a ransomware operation that surfaced in late 2024, and had taken over BreachForums that same year.
The more important detail is this: Khader told Krebs he had been cooperating with law enforcement since at least June 2025. If that is accurate, the detention is not the start of his cooperation. It formalizes a relationship that may have been feeding investigators for more than a year.
A fast-moving week for the FBI
The Jordan detention follows the arrest last week of a 24-year-old man in Amsterdam over his alleged role in the group's operations. Authorities have not released his name. Independent reports have identified him as Pepijn van der Stap, a reformed hacker employed as an offensive security lead at Dutch company Neo Security. A ShinyHunters spokesperson denied any connection to him.
Brett Leatherman, assistant director of the FBI's cyber division, described the arrested man as an alleged leader and put numbers on the case: "Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments. They often target third-party vendors in cloud-based platforms, stealing sensitive data and extort victims with threats to publish it."
FBI director Kash Patel followed with: "FBI teams are working new leads RIGHT NOW. More arrests are on the table."
⚠️ The group hit the FBI directly — In recent weeks, ShinyHunters reportedly breached the FBI's apply.fbijobs[.]gov portal and stole around three terabytes of data. It also reportedly hijacked the darknet site of rival gang Cl0p by exploiting an unpatched Grav CMS flaw. The group says it wants no payment from the FBI, only to pressure the agency over what it calls false claims, including claims tying it to The Com.
A brand, not a crew
Research from Sekoia and Beazley Security traces ShinyHunters back to two earlier groups, TheDarkOverlord and GnosticPlayers. The brand appeared publicly around April or May 2020, trading stolen databases on RaidForums. Researchers Enzo Saez and Robert (Bobby) Venal sum up why it has lasted: "Six years on, ShinyHunters is less a group than a brand and business model that has outlived its founders."
They describe a division of labor that is "almost modular: initial access from social engineers, amplification and recruitment from adjacent actors, and monetization under a shared, recognizable brand." That structure has already survived indictments, arrests, and forum seizures "without ever going quiet for long."
The RedEye take
This is a real win, and the cooperation angle matters more than the arrest. An administrator who ran leak sites and a major criminal forum knows handles, payment trails, and infrastructure. Leatherman said so directly: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left." Expect more arrests, and expect some members to turn themselves in.
But defenders should not read this as the threat going away. The Sekoia and Beazley findings point the other way. When the access, amplification, and monetization roles can be swapped out, removing one administrator slows the brand down without ending it. The skills that breached 140 organizations, social engineering and abuse of trusted vendor access, are common across this ecosystem and easy to recruit for. The risk to your organization comes from the playbook, and the playbook is still on the market.
There is also a warning in the Amsterdam case. If the reports are accurate, the alleged leader was working as an offensive security professional. Whatever the courts decide, every security leader should take on board that the line between defender and attacker skill sets is thin, and that trust inside the security community is not a control.
What defenders should learn
- Your vendors are your attack surface. The FBI says this crew often targets third-party vendors on cloud platforms. Ask which vendors hold your most sensitive data, how they authenticate support staff, and how quickly they would tell you about a compromise.
- Plan for brand persistence, not one-time incidents. A modular group can come back under the same name with new operators. Threat models and tabletop exercises should assume a repeat extortion attempt after any arrest headline.
- Extortion is not only about money. ShinyHunters says it wants leverage over the FBI, not cash. Response playbooks built only around a payment decision miss leaks driven by reputation or grudges. Include legal, communications, and leadership in data extortion planning.
- Arrests produce intelligence that eventually reaches victims. Cooperating insiders and seized infrastructure often lead to victim notifications months later. Make sure your organization can be reached by law enforcement and has a process for checking that kind of outreach.
- Unpatched web platforms hurt everyone, including criminals. The group reportedly took over Cl0p's site through an unpatched Grav CMS flaw. Neglected content management systems on the edge of your network are just as exposed.
Source — Based on reporting by Ravie Lakshmanan, The Hacker News, October 4, 2026, which cites Reuters, Brian Krebs, FBI statements, and research from Sekoia and Beazley Security: https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html
Originally published on RedEye Threat Intelligence.
Top comments (0)