- by x32x01 ||
A key alleged member of the ShinyHunters hacking group has been detained in Jordan following the group’s recent cyberattack against the FBI. According to sources cited by Reuters, Saif al-Din Khader, also known by the alias “Rey,” is cooperating with U.S. investigators and may be helping authorities identify other members of the group.
The arrest comes at a critical moment for ShinyHunters, which has been linked to some of the most significant data theft and extortion campaigns of recent years.
According to Reuters, Khader was detained by Jordanian authorities earlier this week. Two sources said he is cooperating with the FBI and providing information that could help investigators locate other hackers involved with the group.
The FBI has not publicly confirmed the specific arrest, but the bureau said it continues to investigate the cyber incident allegedly involving ShinyHunters and has already worked with international partners to arrest multiple suspects.
⚠️ Important: Khader is an alleged member of the group, and details about his exact role and the circumstances of his detention remain subject to the ongoing investigation.
The group claimed it obtained sensitive information connected to FBI employees and demanded that the bureau change statements it had previously made about the group.
The FBI treated the incident seriously and launched an international investigation. Its Cyber Division also publicly warned members of ShinyHunters that investigators were working to identify and locate them.
ShinyHunters later took its own website offline after a deadline it had given the FBI expired without the bureau changing its position.
That sequence of events was followed by arrests in different countries, including the Netherlands and now Jordan.
Journalist Brian Krebs previously reported on Khader and described him as a key figure connected to Scattered Lapsus$ Hunters, an umbrella term associated with ShinyHunters and related hacking communities.
In that earlier interaction, Khader reportedly claimed that he had left the world of data theft and extortion and was cooperating with law enforcement.
However, ShinyHunters continued conducting high-profile attacks afterward.
This makes the latest detention particularly significant because investigators may already have historical information connecting Khader to other members and operations.
The group first became widely known for stealing and selling huge databases containing personal information. Over the years, it has been associated with attacks involving major companies and online services.
One of its earlier high-profile incidents involved AT&T. Data attributed to ShinyHunters included information on tens of millions of AT&T customers, with a dataset involving roughly 70 million records eventually appearing online.
The group's activity later expanded into much larger campaigns involving cloud services, financial institutions, ticketing platforms, education technology, and enterprise software.
The campaign affected major organizations, including:
The incidents highlighted an important security lesson: attackers do not always need to exploit a sophisticated vulnerability in a cloud platform. Compromised credentials and poorly protected accounts can be enough to gain access to valuable data.
Santander reported a major breach involving customer and employee information, while PowerSchool suffered a serious incident involving sensitive information belonging to students and teachers.
These incidents showed how attractive organizations outside the traditional technology sector have become to data-extortion groups.
Education companies, banks, telecommunications providers, ticketing platforms, and SaaS providers can all hold enormous amounts of valuable personal information.
Security researchers have linked these campaigns to social engineering and voice phishing, where attackers impersonate IT or support personnel to convince employees to provide access or perform actions that ultimately give attackers access to corporate data.
Victims and targeted organizations included major companies such as:
The important point is that these attacks often focused on identity and human trust, rather than simply exploiting a software vulnerability.
Their campaigns have been associated with:
🔐 For defenders, this is a major lesson: protecting the perimeter alone is not enough. Identity security, phishing resistance, strong authentication, monitoring, and strict access controls are equally important.
Investigators are likely interested in identifying:
The FBI has previously announced the arrest of an alleged ShinyHunters leader in the Netherlands. According to the bureau, the group has allegedly breached more than 140 organizations and received at least $70 million in extortion payments since last year.
That means the Jordan case may be only one part of a much larger international investigation.
It demonstrates how modern cybercrime groups can operate across multiple countries, use different aliases, collaborate with loosely connected groups, and repeatedly target organizations that store huge amounts of personal information.
The attacks also show why organizations need to treat identity security and social engineering as core cybersecurity problems.
A strong firewall will not stop an attacker who convinces an employee to hand over legitimate access.
For security teams, some of the most important defenses include:
The group has already been connected to attacks involving some of the world's largest companies and services. Now, following the alleged FBI breach, international law enforcement appears to be increasing pressure on the people behind the operation.
Whether Khader's reported cooperation leads investigators to additional members remains to be seen.
But one thing is clear: the ShinyHunters story is far from over. 🔎
The arrest comes at a critical moment for ShinyHunters, which has been linked to some of the most significant data theft and extortion campaigns of recent years.
Who Is Saif al-Din Khader?
Saif al-Din Khader is reportedly a Jordanian national who has been associated with ShinyHunters and the broader Scattered Lapsus$ Hunters ecosystem.According to Reuters, Khader was detained by Jordanian authorities earlier this week. Two sources said he is cooperating with the FBI and providing information that could help investigators locate other hackers involved with the group.
The FBI has not publicly confirmed the specific arrest, but the bureau said it continues to investigate the cyber incident allegedly involving ShinyHunters and has already worked with international partners to arrest multiple suspects.
⚠️ Important: Khader is an alleged member of the group, and details about his exact role and the circumstances of his detention remain subject to the ongoing investigation.
The FBI Breach That Triggered the Latest Crackdown
The arrest comes shortly after ShinyHunters claimed responsibility for a major cyberattack involving the FBI's systems.The group claimed it obtained sensitive information connected to FBI employees and demanded that the bureau change statements it had previously made about the group.
The FBI treated the incident seriously and launched an international investigation. Its Cyber Division also publicly warned members of ShinyHunters that investigators were working to identify and locate them.
ShinyHunters later took its own website offline after a deadline it had given the FBI expired without the bureau changing its position.
That sequence of events was followed by arrests in different countries, including the Netherlands and now Jordan.
Saif Was Already Known to Security Researchers
Khader's identity was not completely unknown to the cybersecurity community.Journalist Brian Krebs previously reported on Khader and described him as a key figure connected to Scattered Lapsus$ Hunters, an umbrella term associated with ShinyHunters and related hacking communities.
In that earlier interaction, Khader reportedly claimed that he had left the world of data theft and extortion and was cooperating with law enforcement.
However, ShinyHunters continued conducting high-profile attacks afterward.
This makes the latest detention particularly significant because investigators may already have historical information connecting Khader to other members and operations.
ShinyHunters' Long History of Major Breaches
ShinyHunters is not a new hacking operation.The group first became widely known for stealing and selling huge databases containing personal information. Over the years, it has been associated with attacks involving major companies and online services.
One of its earlier high-profile incidents involved AT&T. Data attributed to ShinyHunters included information on tens of millions of AT&T customers, with a dataset involving roughly 70 million records eventually appearing online.
The group's activity later expanded into much larger campaigns involving cloud services, financial institutions, ticketing platforms, education technology, and enterprise software.
The Snowflake Campaign
One of the most important campaigns associated with ShinyHunters involved compromised accounts connected to Snowflake customers.The campaign affected major organizations, including:
- Ticketmaster
- Santander
- AT&T
- Other organizations using cloud-based services
The incidents highlighted an important security lesson: attackers do not always need to exploit a sophisticated vulnerability in a cloud platform. Compromised credentials and poorly protected accounts can be enough to gain access to valuable data.
From Ticketmaster to PowerSchool
The group's activity also became connected to other major data-theft incidents.Santander reported a major breach involving customer and employee information, while PowerSchool suffered a serious incident involving sensitive information belonging to students and teachers.
These incidents showed how attractive organizations outside the traditional technology sector have become to data-extortion groups.
Education companies, banks, telecommunications providers, ticketing platforms, and SaaS providers can all hold enormous amounts of valuable personal information.
The Salesforce Attacks
More recently, ShinyHunters and groups operating under the Scattered Lapsus$ Hunters label became associated with attacks against Salesforce customers.Security researchers have linked these campaigns to social engineering and voice phishing, where attackers impersonate IT or support personnel to convince employees to provide access or perform actions that ultimately give attackers access to corporate data.
Victims and targeted organizations included major companies such as:
- Cisco
- Adidas
- Allianz Life
- Qantas
- Farmers Insurance
- Workday
- Several LVMH-related companies
The important point is that these attacks often focused on identity and human trust, rather than simply exploiting a software vulnerability.
What Makes ShinyHunters So Dangerous?
ShinyHunters' success comes from combining several attack techniques rather than relying on a single method.Their campaigns have been associated with:
- Credential theft
- Social engineering
- Phishing and voice phishing
- Cloud account compromise
- Data theft
- Extortion
- Abuse of legitimate access
- Targeting employees and support teams
🔐 For defenders, this is a major lesson: protecting the perimeter alone is not enough. Identity security, phishing resistance, strong authentication, monitoring, and strict access controls are equally important.
What Happens Next?
The Jordan detention could become an important development in the investigation if Khader is indeed providing information to authorities.Investigators are likely interested in identifying:
- Other ShinyHunters members
- Individuals who helped conduct previous attacks
- Infrastructure used by the group
- Communication channels
- Stolen data repositories
- Extortion operations
- Financial relationships connected to previous attacks
The FBI has previously announced the arrest of an alleged ShinyHunters leader in the Netherlands. According to the bureau, the group has allegedly breached more than 140 organizations and received at least $70 million in extortion payments since last year.
That means the Jordan case may be only one part of a much larger international investigation.
Why This Case Matters to Cybersecurity
The ShinyHunters investigation is bigger than one hacker or one company.It demonstrates how modern cybercrime groups can operate across multiple countries, use different aliases, collaborate with loosely connected groups, and repeatedly target organizations that store huge amounts of personal information.
The attacks also show why organizations need to treat identity security and social engineering as core cybersecurity problems.
A strong firewall will not stop an attacker who convinces an employee to hand over legitimate access.
For security teams, some of the most important defenses include:
- Phishing-resistant MFA
- Strong identity and access management
- Least-privilege permissions
- Monitoring unusual account activity
- Protection of privileged accounts
- Security awareness training
- Rapid credential revocation
- Logging and detection across SaaS platforms
- Regular review of third-party access
The Bigger Picture
The detention of Saif al-Din Khader in Jordan is another major development in the international investigation into ShinyHunters.The group has already been connected to attacks involving some of the world's largest companies and services. Now, following the alleged FBI breach, international law enforcement appears to be increasing pressure on the people behind the operation.
Whether Khader's reported cooperation leads investigators to additional members remains to be seen.
But one thing is clear: the ShinyHunters story is far from over. 🔎