A key member of the ShinyHunters hacking group was detained in Jordan this week and is cooperating with the FBI to identify his fellow hackers, according to three people familiar with the matter who spoke to Reuters.
The suspect, identified as Saif al-Din Khader — whose alleged hacker nickname is “Rey” — was taken into custody by Jordanian authorities on Tuesday, two of the sources said. He is now helping the FBI and global law enforcement locate other members of the group, with one source stating that Khader is walking investigators through his electronic devices and digital communications to help identify and locate his alleged co-conspirators. “His cooperation is critical to ongoing efforts to arrest these hackers,” a source told Reuters.
The FBI declined to comment on any specific arrest or activity abroad but said the bureau “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice”.
ShinyHunters first claimed responsibility for breaching the FBI in late September 2026, stating it had compromised the FBIJobs.gov portal and stolen data “on almost ALL FBI Agents, and individuals who filed an application with the FBI for a job”. The group claimed the haul amounted to between 2 and 3 terabytes of data.
A Reuters analysis of a sample of the data shared by the hackers subsequently revealed that the records contained extensive personally identifiable information, sensitive job role information, and psychiatric and medical information. The group told Reuters the data included medical information, discharges, prescriptions, clinical visits, and “any health issues with Agents”.
The documents Reuters reviewed varied in sensitivity. One medical record, part of a “fitness for duty” exam given to prospective employees, noted that an applicant took aspirin daily and was allergic to dust and cats. Another record said a potential employee exhibited “symptoms of depression” in high school. A third document carried an electrocardiogram result. Reuters partially authenticated some of the files by running two Social Security numbers against credit bureau data and matching a pre-employment mental health evaluation against a former FBI analyst’s LinkedIn profile.
ShinyHunters said it had compromised several of the bureau’s internal services, including the FBI’s background and employee applicant screening system, FBI MedLink, which contains medical records.
The Jordanian detention follows the arrest of a 24-year-old man from Amsterdam on September 15 who Dutch police said is suspected of playing a role in ShinyHunters. The man is also suspected of attempted solicitation of two murders, though police said that suspicion is linked to information found on the suspect’s laptop and is not related to the ShinyHunters investigation. A court in Rotterdam ordered the suspect held for a further 90 days.
FBI Director Kash Patel highlighted the arrest in a post on X, calling the detainee “one of the alleged leaders of ShinyHunters — a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world”. “As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest,” Patel said.
The website used by ShinyHunters went offline on Wednesday, one day after the group’s deadline for the FBI to retract or modify a May 2026 advisory about the group’s tactics expired. The hackers had given the FBI a week to either “correct or simply REMOVE” the advisory, which described the organization as a “cyber criminal group specializing in large-scale data breaches and extortion”. The advisory remains online.
Reuters could not determine why the site was offline, and ShinyHunters could not be reached for comment. The group later denied the site was offline, claiming it had moved after DDoS attacks.
In a statement to Nextgov/FCW, ShinyHunters said it does not intend to publish the troves of sensitive FBI employee data it claims to have stolen, describing its confrontation with the bureau as a “marketing campaign”. “Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to,” the group said.
The group accused news outlets and the public of misinterpreting its earlier demand that the FBI correct or remove the advisory. It said it had deliberately left unspecified what would happen if the bureau did not comply and claimed it had never expected compliance. “This was not a threat. It may have been worded like a threat but ultimately the public has drove this story out of context and made their own wild assumptions and speculations,” the statement said.
Despite a joint manifesto published in September 2025 in which ShinyHunters and several other groups announced they were retiring from hacking, the group remained active. In August 2026, ShinyHunters listed Logitech/Streamlabs on its dark web portal, claiming to have collected data from the consumer tech brand. In the 60 days preceding that listing, ShinyHunters claimed 15 other victims, primarily targeting organizations in the Technology, Healthcare, and Professional Services sectors. Recent targets included Metabase, Lumenis Ltd., and RingCentral, Inc..






Comments
No comments yet. Be the first to share your thoughts.