• TabCode is free and will always be free - no ads, no paywalls, just knowledge and community.
    Stay, learn, share, and contribute. Together, we can make TabCode a better place for everyone.

ShinyHunters Hacker Arrested in Jordan

x32x01
  • by x32x01 ||
A key alleged member of the ShinyHunters hacking group has been detained in Jordan following the group’s recent cyberattack against the FBI. According to sources cited by Reuters, Saif al-Din Khader, also known by the alias “Rey,” is cooperating with U.S. investigators and may be helping authorities identify other members of the group.

The arrest comes at a critical moment for ShinyHunters, which has been linked to some of the most significant data theft and extortion campaigns of recent years.



Who Is Saif al-Din Khader?​

Saif al-Din Khader is reportedly a Jordanian national who has been associated with ShinyHunters and the broader Scattered Lapsus$ Hunters ecosystem.
According to Reuters, Khader was detained by Jordanian authorities earlier this week. Two sources said he is cooperating with the FBI and providing information that could help investigators locate other hackers involved with the group.
The FBI has not publicly confirmed the specific arrest, but the bureau said it continues to investigate the cyber incident allegedly involving ShinyHunters and has already worked with international partners to arrest multiple suspects.

⚠️ Important: Khader is an alleged member of the group, and details about his exact role and the circumstances of his detention remain subject to the ongoing investigation.



The FBI Breach That Triggered the Latest Crackdown​

The arrest comes shortly after ShinyHunters claimed responsibility for a major cyberattack involving the FBI's systems.
The group claimed it obtained sensitive information connected to FBI employees and demanded that the bureau change statements it had previously made about the group.
The FBI treated the incident seriously and launched an international investigation. Its Cyber Division also publicly warned members of ShinyHunters that investigators were working to identify and locate them.
ShinyHunters later took its own website offline after a deadline it had given the FBI expired without the bureau changing its position.
That sequence of events was followed by arrests in different countries, including the Netherlands and now Jordan.



Saif Was Already Known to Security Researchers​

Khader's identity was not completely unknown to the cybersecurity community.
Journalist Brian Krebs previously reported on Khader and described him as a key figure connected to Scattered Lapsus$ Hunters, an umbrella term associated with ShinyHunters and related hacking communities.
In that earlier interaction, Khader reportedly claimed that he had left the world of data theft and extortion and was cooperating with law enforcement.
However, ShinyHunters continued conducting high-profile attacks afterward.
This makes the latest detention particularly significant because investigators may already have historical information connecting Khader to other members and operations.



ShinyHunters' Long History of Major Breaches​

ShinyHunters is not a new hacking operation.
The group first became widely known for stealing and selling huge databases containing personal information. Over the years, it has been associated with attacks involving major companies and online services.
One of its earlier high-profile incidents involved AT&T. Data attributed to ShinyHunters included information on tens of millions of AT&T customers, with a dataset involving roughly 70 million records eventually appearing online.
The group's activity later expanded into much larger campaigns involving cloud services, financial institutions, ticketing platforms, education technology, and enterprise software.



The Snowflake Campaign​

One of the most important campaigns associated with ShinyHunters involved compromised accounts connected to Snowflake customers.
The campaign affected major organizations, including:
  • Ticketmaster
  • Santander
  • AT&T
  • Other organizations using cloud-based services
In the Ticketmaster case, attackers claimed to have obtained data relating to hundreds of millions of customers. ShinyHunters later advertised a massive Ticketmaster dataset on cybercrime forums.
The incidents highlighted an important security lesson: attackers do not always need to exploit a sophisticated vulnerability in a cloud platform. Compromised credentials and poorly protected accounts can be enough to gain access to valuable data.



From Ticketmaster to PowerSchool​

The group's activity also became connected to other major data-theft incidents.
Santander reported a major breach involving customer and employee information, while PowerSchool suffered a serious incident involving sensitive information belonging to students and teachers.
These incidents showed how attractive organizations outside the traditional technology sector have become to data-extortion groups.
Education companies, banks, telecommunications providers, ticketing platforms, and SaaS providers can all hold enormous amounts of valuable personal information.



The Salesforce Attacks​

More recently, ShinyHunters and groups operating under the Scattered Lapsus$ Hunters label became associated with attacks against Salesforce customers.
Security researchers have linked these campaigns to social engineering and voice phishing, where attackers impersonate IT or support personnel to convince employees to provide access or perform actions that ultimately give attackers access to corporate data.

Victims and targeted organizations included major companies such as:
  • Google
  • Cisco
  • Adidas
  • Allianz Life
  • Qantas
  • Farmers Insurance
  • Workday
  • Several LVMH-related companies
CrowdStrike also reported activity involving Scattered Lapsus$ Hunters targeting Salesforce customers through voice-phishing campaigns.
The important point is that these attacks often focused on identity and human trust, rather than simply exploiting a software vulnerability.



What Makes ShinyHunters So Dangerous?​

ShinyHunters' success comes from combining several attack techniques rather than relying on a single method.
Their campaigns have been associated with:
  • Credential theft
  • Social engineering
  • Phishing and voice phishing
  • Cloud account compromise
  • Data theft
  • Extortion
  • Abuse of legitimate access
  • Targeting employees and support teams
This approach can be extremely effective because compromising one employee account can sometimes provide access to large amounts of corporate data.

🔐 For defenders, this is a major lesson: protecting the perimeter alone is not enough. Identity security, phishing resistance, strong authentication, monitoring, and strict access controls are equally important.



What Happens Next?​

The Jordan detention could become an important development in the investigation if Khader is indeed providing information to authorities.

Investigators are likely interested in identifying:
  • Other ShinyHunters members
  • Individuals who helped conduct previous attacks
  • Infrastructure used by the group
  • Communication channels
  • Stolen data repositories
  • Extortion operations
  • Financial relationships connected to previous attacks
The FBI is already working with international law-enforcement partners, and officials have indicated that additional arrests could follow.
The FBI has previously announced the arrest of an alleged ShinyHunters leader in the Netherlands. According to the bureau, the group has allegedly breached more than 140 organizations and received at least $70 million in extortion payments since last year.
That means the Jordan case may be only one part of a much larger international investigation.



Why This Case Matters to Cybersecurity​

The ShinyHunters investigation is bigger than one hacker or one company.
It demonstrates how modern cybercrime groups can operate across multiple countries, use different aliases, collaborate with loosely connected groups, and repeatedly target organizations that store huge amounts of personal information.
The attacks also show why organizations need to treat identity security and social engineering as core cybersecurity problems.
A strong firewall will not stop an attacker who convinces an employee to hand over legitimate access.

For security teams, some of the most important defenses include:
  • Phishing-resistant MFA
  • Strong identity and access management
  • Least-privilege permissions
  • Monitoring unusual account activity
  • Protection of privileged accounts
  • Security awareness training
  • Rapid credential revocation
  • Logging and detection across SaaS platforms
  • Regular review of third-party access

The Bigger Picture​

The detention of Saif al-Din Khader in Jordan is another major development in the international investigation into ShinyHunters.
The group has already been connected to attacks involving some of the world's largest companies and services. Now, following the alleged FBI breach, international law enforcement appears to be increasing pressure on the people behind the operation.
Whether Khader's reported cooperation leads investigators to additional members remains to be seen.
But one thing is clear: the ShinyHunters story is far from over. 🔎



Frequently Asked Questions​

-----------------

Who is Saif al-Din Khader?​

Saif al-Din Khader, also known as “Rey,” is an alleged ShinyHunters member who was detained in Jordan in October 2026. Sources told Reuters that he is cooperating with the FBI and may be helping investigators identify other members.

What is ShinyHunters?​

ShinyHunters is a cybercrime group associated with large-scale data theft and extortion. It has been linked to attacks involving organizations such as AT&T, Ticketmaster, Santander, Rockstar Games, and other major companies.

Did ShinyHunters hack the FBI?​

ShinyHunters claimed responsibility for a recent cyberattack involving FBI systems and alleged that it obtained sensitive employee information. The FBI has confirmed an ongoing investigation into the incident, but specific details about the group's claims remain under investigation.

What happened to ShinyHunters after the FBI attack?​

The group faced increasing law-enforcement pressure, including arrests in the Netherlands and the reported detention of an alleged member in Jordan. Its website also went offline after a deadline it had given the FBI expired.

What companies have been targeted by ShinyHunters?​

ShinyHunters has been associated with major incidents involving organizations including AT&T, Ticketmaster, Santander, PowerSchool, Rockstar Games, and Salesforce customers. Some incidents involve related groups or overlapping operations, so attribution can vary between cases.
 
Similar threads
x32x01
Replies
0
Views
36
x32x01
x32x01
x32x01
Replies
0
Views
115
x32x01
x32x01
x32x01
Replies
0
Views
119
x32x01
x32x01
x32x01
Replies
0
Views
144
x32x01
x32x01
x32x01
Replies
0
Views
118
x32x01
x32x01
Forum Statistics
Threads
1,119
Messages
1,125
Members
16
Latest Member
b_a_s_m_a_l_a7
Back
Top