In September, the infamous ShinyHunters hacking group claimed it had infiltrated the FBI job recruitment portal, stealing confidential data belonging to 5,000 employees and even changing the FBI logo to its own. The group has been implicated in the hacking of numerous large and high-profile organizations over the years, from the European Commission to Grand Theft Auto-maker Rockstar Games and the software firm behind Canvas.
Now, Reuters reports that a suspected leader of the group, Saif al-Din Khader, is being detained in the country of Jordan in the Near East. Al-Din Khader—who uses the name Rey online—is said to be cooperating with the authorities, helping FBI and global law enforcement to find the other hackers in the group, according to sources who spoke to Reuters.
According to independent security researcher Brian Krebs, Rey was responsible for releasing a ransomware strain known as ShinySp1d3r, and had been the administrator of the data leak website for Hellcat, a ransomware group which has been linked to attacks on Schneider Electric, Telefonica, and Orange Romania. He is reportedly still a teenager.
The FBI has yet to officially confirm the reports.
The latest arrest comes after a series of wins for the FBI against the group. At the end of last month, FBI Director Kash Patel claimed another member of the group, had been detained in the Netherlands, who Krebs alleged was named Pepijn van der Stap. Meanwhile, earlier this week, Reuters reported that ShinyHunters’ dark web site, which members can use to communicate anonymously and which cannot be accessed via the regular internet, had disappeared.
Recommended by Our Editors
Patel has been clear that the FBI’s campaign against the hacking group will continue, saying on X earlier this week that the FBI’s teams are working on new leads and that more arrests “are on the table.”
This Tweet is currently unavailable. It might be loading or has been removed.
ShinyHunters has been clear that it doesn’t plan to ransom the stolen data and that it is not an act of extortion, claiming the attack “was all a marketing campaign to protect our business and actively combat disinformation” in a statement to journalists. The group instead demanded that the FBI correct or remove a public advisory it had issued about the group in May 2026, which said the hackers often exaggerated their claims of access to victims’ data.
About Our Expert
Experience
I’m a reporter covering weekend news. Before joining PCMag in 2024, I picked up bylines in BBC News, The Guardian, The Times of London, The Daily Beast, Vice, Slate, Fast Company, The Evening Standard, The i, TechRadar, and Decrypt Media.
I’ve been a PC gamer since you had to install games from multiple CD-ROMs by hand. As a reporter, I’m passionate about the intersection of tech and human lives. I’ve covered everything from crypto scandals to the art world, as well as conspiracy theories, UK politics, and Russia and foreign affairs.
Click Here For The Original Source.
