ShinyHunters Suspect Rey Reportedly Detained in Jordan

Stephanie Adlam
4 Min Read
A blue handcuff holds a dossier while paper copies escape.
A detention does not erase copies of stolen records.

A suspected ShinyHunters member known as “Rey” has reportedly been detained in Jordan and is helping investigators find other members. Reuters published the development on October 3, citing three people familiar with the case. The report changes the investigation’s direction; it does not establish that stolen information has been recovered or erased.[1]

Devices and correspondence become an investigative trail

Reuters identified the suspect as Saif al-Din Khader. Its sources described cooperation involving his devices and digital correspondence. The FBI declined to confirm a particular overseas arrest. Reuters also observed that a previously used group contact became unreachable and its leak site disappeared. Those observations do not prove why the site went offline.

The distinction matters: investigators can learn who communicated with whom without yet knowing where every copy of stolen records went. An unavailable leak site is a change in publication infrastructure, not a receipt showing that all recipients deleted their files.

A separate arrest had already been confirmed

On September 29, the FBI publicly announced a Dutch police arrest of an alleged ShinyHunters leader. That announcement concerns a separate suspect. The bureau linked the suspect and co-conspirators to more than 140 organizations breached and at least $70 million in extortion payments since the previous year; these are allegations about that activity, not a count of people affected by the reported Jordan detention.[2]

The FBI described a pattern of targeting third-party vendors in cloud platforms, stealing sensitive records and threatening publication. A customer can therefore face exposure through an organization’s supplier even without downloading malware. A local scan cannot retract records already copied from a remote service.

The pressure can continue outside the leak site

The FBI’s May ShinyHunters advisory explains how data theft can become direct harassment: threatening messages, calls to relatives and, sometimes, false emergency reports intended to send police to a victim’s address. It also warns that claims about embarrassing material may be exaggerated or entirely false.[3]

If contacted, preserve the message and verify it through a known channel. The FBI advises against paying or responding to demands. A detail from a real breach does not authenticate the sender: the same problem appears in Revolut’s customer-data disclosure. If there are separate signs of account access, use the account recovery sequence; a threatening email alone does not establish a device infection.

The reported cooperation may help investigators map the group. For affected people, the useful signal remains a verified notice specifying their exposure—not the disappearance of a criminal website.

References

  1. Jana Winter, Raphael Satter and AJ Vicens. “ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau, sources say.” Reuters, October 3, 2026; syndicated by AOL. Original reporting.
  2. FBI. “FBI Announces ShinyHunters Arrest.” September 29, 2026. Announcement and transcript.
  3. FBI/IC3. “ShinyHunters: Cyber Criminal Group Attacks Learning Management System.” May 15, 2026. Victim guidance.
Share This Article
Follow:
Stephanie is our wordsmith, transforming technical research into engaging content that resonates with users. Her expertise in cybercrime prevention and online safety ensures that Gridinsoft's advice is accessible to everyone—whether they’re tech-savvy or not.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?