A suspected member of the ShinyHunters digital extortion group, known online as “Rey,” has reportedly been detained by authorities in Jordan, as confirmed by Reuters. The individual, whose real name is Saif ‌al-Din Khader, was taken into custody on September 29, 2026, and is cooperating with the U.S. Federal Bureau of Investigation (FBI) to help identify other members of the group.
Sources indicate that Rey’s cooperation is crucial for ongoing efforts to apprehend additional hackers associated with ShinyHunters. This development follows a recent arrest of another individual linked to the group, highlighting a significant escalation in law enforcement’s efforts against this notorious cybercriminal organization.
Background on Rey and ShinyHunters
Rey, also known as ReyXBF, has been a prominent figure within the cybercrime community. In a November 2025 report by independent security journalist Brian Krebs, he was identified as one of the three administrators of Scattered LAPSUS$ Hunters (SLH), a group that combines elements from Scattered Spider, LAPSUS$, and ShinyHunters. Previously, Rey managed the data leak website for Hellcat, a ransomware group that emerged in late 2024, and took over as the administrator of BreachForums in 2024. Notably, he has been cooperating with law enforcement since at least June 2025.
Recent Developments and Law Enforcement Actions
The recent arrest of Rey is part of a broader crackdown on ShinyHunters, which has been implicated in numerous high-profile cyberattacks. Just last week, a 24-year-old man from Amsterdam was arrested for his involvement with the group. Although his identity has not been officially disclosed, reports suggest it was Pepijn van der Stap, a reformed hacker now working in offensive security. Following this arrest, FBI Director Kash Patel stated that the agency is actively pursuing new leads and anticipates further arrests.
ShinyHunters has gained notoriety for its aggressive tactics, including hijacking the darknet site of rival cybercriminals and exploiting vulnerabilities to steal sensitive data. The group has claimed responsibility for breaching over 140 organizations and extorting at least $70 million in ransom payments. Brett Leatherman, assistant director of the FBI’s cyber division, emphasized the group’s targeting of third-party vendors in cloud-based platforms, where they steal sensitive data and threaten to publish it unless paid.
Implications for Cybersecurity
The ongoing investigation into ShinyHunters underscores the evolving landscape of cybercrime, where groups can rapidly adapt and reorganize despite law enforcement efforts. The resilience of ShinyHunters, described by cybersecurity researchers as a “brand and business model,” highlights the modular nature of modern cybercriminal operations. This adaptability poses significant challenges for law enforcement and cybersecurity professionals alike.
As the investigation unfolds, the FBI has urged other members of ShinyHunters to come forward, suggesting that the pressure from recent arrests may lead to further cooperation from within the group. The agency’s proactive stance indicates a commitment to dismantling the operational structure of ShinyHunters and similar organizations.
For cybersecurity professionals, the developments surrounding ShinyHunters serve as a reminder of the persistent threat posed by organized cybercrime and the importance of robust security measures to protect sensitive data from such groups.
For further details, see the report from The Hacker News.


