ShinyHunters suspect Rey detained in Jordan, sources say
Reuters: Saif al-Din Khader held 29 September, reportedly aiding FBI

ShinyHunters suspect Rey detained in Jordan, sources say

Reuters reported on 3 October 2026 that a suspected ShinyHunters member was detained in Jordan and is cooperating with the FBI. Three people familiar with the matter identified him as Saif al-Din Khader, known online as Rey. Two sources said he was taken into custody on 29 September. Reuters could not confirm where he is held, and no charges have been published.

What happened

ShinyHunters is a long-running data-theft and extortion crew. In September 2026 the group claimed it had stolen personnel data tied to FBI employees and job applicants after activity against FBIjobs.gov, which investigators have linked to an Oracle PeopleSoft flaw. The FBI said it was aware of those claims and was investigating. Reuters reported that data in the stolen set included medical and personal information on FBI employees.

Independent reporter Brian Krebs had previously identified Rey, also ReyXBF, as an administrator tied to Scattered LAPSUS$ Hunters, Hellcat, and a later BreachForums incarnation. Khader had told Krebs he was already cooperating with law enforcement. This week's account is still sourced to people familiar with the matter, not to a court filing.

Who is affected

  • Organizations previously named in ShinyHunters or Scattered LAPSUS$ Hunters extortion, including anyone still negotiating or monitoring a leak site
  • Teams that exposed Oracle PeopleSoft or similar HR portals to the internet
  • Staff whose data may sit in dumps the crew already posted

A detention does not close the crew. Other operators can keep extorting from existing stolen sets.

What to do now

Do not treat this report as the end of ShinyHunters exposure. If you were named in a recent ShinyHunters or related leak, keep monitoring the leak sites and do not pay on the assumption the operator is in custody. Confirm PeopleSoft and other internet-facing HR systems are patched and not accepting anonymous access. Reset credentials that could have been in a dump, and warn staff about follow-on phishing that quotes their own HR data.

Source: Reuters, 3 October 2026.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

TA419 phishes AI policy experts with Microsoft AitM
China-aligned credential theft past MFA using a proxied Microsoft login