# ShinyHunters Hacker Detained in Jordan, Cooperating With FBI

> A suspected ShinyHunters hacker known as Rey was detained in Jordan and is cooperating with the FBI, impacting the extortion group's infrastructure.

- Published: 2026-10-04T03:24:50.000Z
- Severity: info
- Category: Threat Intel
- Tags: ShinyHunters, Ransomware, Data Breach, Credential Theft, HellCat
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/
- Canonical: https://runtimerebel.com/blog/shinyhunters-hacker-detained-in-jordan-cooperating-with-fbi

## Key points

- Immediate impact: A key suspected member of the ShinyHunters extortion group was detained in Jordan, leading to operational disruptions and infrastructure shutdowns.
- Affected systems: Cloud SaaS environments, Jira servers, and previous targets including Salesforce integrations and corporate AWS infrastructure.
- Remediation: Organizations should monitor SaaS environments for unauthorized token access and review third-party integration security protocols.

## Overview of ShinyHunters Disruptions

Law enforcement pressure against prominent extortion syndicates has intensified following reports that a suspected ShinyHunters member operating under the alias "Rey" was detained in Jordan. According to [Reuters](https://www.reuters.com/), Jordanian authorities detained Saif al-Din Khader, who is now reportedly cooperating with the Federal Bureau of Investigation (FBI) and international partners. Sources indicate that Khader is providing investigators with access to electronic devices and digital communications to help map out co-conspirators and uncover hidden infrastructure.

The reported detention coincides with an ongoing international law enforcement crackdown following high-profile extortion campaigns. Security researchers and media outlets observed sudden operational silences, including the temporary offline status of primary data leak sites and the abrupt closure of affiliated messaging accounts. Despite these disruptions, new leak portals quickly emerged, demonstrating the decentralized and resilient nature of modern cybercrime syndicates.

## [Threat Actor](/glossary#threat-actor) Profile and Historical Campaigns

The threat actor known as Rey has been tied to multiple high-impact extortion operations over recent years. Beyond associations with ShinyHunters, Rey previously claimed membership in the HellCat [ransomware](/glossary#ransomware) operation and was linked to attacks targeting corporate Jira ticketing systems, including incidents involving Telefónica and Orange Romania. Investigations also placed the individual with administrative privileges inside Telegram channels operated by the collective known as "Scattered Lapsus$ Hunters," a group allegedly drawing personnel from legacy cybercrime formations like Lapsus$, Scattered Spider, and ShinyHunters.

Previous notable activity attributed to these connected ecosystems includes attacks on cloud environments, Salesforce integration endpoints, and major corporate targets such as Jaguar Land Rover. The tactics employed by these threat actors frequently rely on compromised authentication tokens, third-party vendor access vectors, and targeted data theft designed to pressure organizations into extortion payments.

## Law Enforcement Pressure and Arrests

International authorities have steadily increased the friction for cybercriminal networks through coordinated arrests and infrastructure seizures. In September, Dutch police apprehended a 24-year-old Amsterdam man identified as Pepijn van der Stap, known online as "Umbreon," as part of ongoing investigations into ShinyHunters activity. FBI leadership subsequently issued public warnings urging remaining participants to surrender, highlighting that seized digital assets and flipped informants provide continuous visibility into underground operations.

## Actionable Defensive Strategies

While law enforcement disruptions reduce immediate pressure, security teams must maintain rigorous defensive postures against cloud-focused extortion groups. Defending against these threat actors requires proactive monitoring and identity [hardening](/glossary#hardening):

* **SaaS Session Monitoring:** Implement strict logging and anomaly detection for cloud SaaS environments, focusing on unauthorized token usage, impossible travel alerts, and unusual [API](/glossary#api) query volumes.
* **Third-Party Risk Management:** Audit integrations with third-party vendors and contractors, enforcing principle-of-least-privilege access controls across all connected enterprise platforms.
* **Credential Hygiene:** Require [phishing](/glossary#phishing)-resistant multi-factor authentication ([MFA](/glossary#mfa)) for all administrative accounts and internal ticketing platforms such as Jira.

**Related:** [Manchester Airports Group Data Leak Exposed by FulcrumSec Extortion](/blog/manchester-airports-group-data-leak-exposed-by-fulcrumsec-extortion), [Data Analyst Sentenced to Prison for Extorting Brightly Software](/blog/data-analyst-sentenced-to-prison-for-extorting-brightly-software)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/shinyhunters-hacker-detained-in-jordan-cooperating-with-fbi
