Skip to content

ShinyHunters member 'Rey' detained in Jordan, aiding FBI

Reuters reports Jordanian authorities detained Saif al-Din Khader, alias 'Rey', who is cooperating with the FBI to locate other ShinyHunters members. He is a suspect, not charged.

Published 3 min read

Jordanian authorities have detained a suspected ShinyHunters member known online as "Rey", identified as Saif al-Din Khader, and he is reportedly cooperating with the FBI to locate other members of the extortion group. The story is a Reuters exclusive, reported by BleepingComputer; there is no indictment, charging document, or official statement confirming it yet, so treat the identification and the cooperation as sourced reporting, not an established fact.

What's reported

Per Reuters, citing two sources, Khader was taken into custody in Jordan on Tuesday. One source said he is "walking law enforcement through his electronic devices and digital communications" to help identify and locate alleged co-conspirators. No charges against Khader have been made public, and no court filing names him. He is a suspect at this stage.

ShinyHunters is a long-running data-theft and extortion brand tied to a string of named incidents, including Salesforce-environment thefts affecting large enterprises, the Instructure Canvas breach, Snowflake-customer attacks, and more recently a claim to have stolen data on FBI personnel through an Oracle PeopleSoft zero-day. That last claim is the group's own and remains unverified.

Attribution caveat

"Rey" is an online handle, and attaching a legal name to a handle is exactly where extortion-crew reporting most often goes wrong. Reuters attributes the identification to unnamed sources; we have no indictment to anchor it. Likewise, "cooperating with the FBI" is a characterization from sources, not a confirmed plea or agreement. We state both as reported and will update if a filing surfaces.

The group is still operating

A detention is not a takedown. The ShinyHunters data-leak site went offline around the time the news broke, but a replacement site reportedly appeared within days. Treat the brand as active: one detained operator does not end the extortion infrastructure, the stolen datasets already in circulation, or copycats using the name.

What to do today

If your organization was exposed to a ShinyHunters campaign (Salesforce data pulls, Snowflake tenants, Canvas/Instructure, or any dataset that surfaced on their leak site), this news changes nothing operationally — do not wait on a prosecution:

  1. Rotate any credentials, API tokens, or OAuth grants tied to data you believe was taken. Stolen secrets outlive arrests.
  2. Assume leaked data stays leaked. Notify affected users and reset exposed authenticators regardless of the legal timeline.
  3. Watch for extortion follow-ups referencing old thefts — a detained operator does not retire a dataset, and new leak sites recycle old claims.

Context

ShinyHunters-linked arrests are stacking up: an alleged member using the handle "Umbreon" was reported arrested in Amsterdam in mid-September 2026. The brand's reach is the reason this matters to defenders here — we have covered its Oracle PeopleSoft zero-day campaign and its Instructure Canvas breach. The pattern across both: the group monetizes access long after the initial intrusion, so the clean-up window is defined by your data, not by whether anyone is in custody.

Related stories