
Key ShinyHunters hacker detained in Jordan cooperates with FBI after breach of agency records
Jordanian authorities have arrested Saif al-Din Khader, who is now assisting federal investigators in identifying fellow members of the cyber extortion group following the theft of employee files.
Detention in Jordan
Jordanian authorities have taken Saif al-Din Khader, an alleged key member of the cyber extortion group ShinyHunters, into custody. Khader, known in hacker communities under the online moniker Rey, was detained on Tuesday in Jordan. According to three people familiar with the case, Khader is actively cooperating with investigators from the Federal Bureau of Investigation and international partner agencies. His cooperation aims to help authorities identify and locate other individuals participating in the syndicate. Cybersecurity specialists describe ShinyHunters as a network consisting largely of young, English-speaking hackers focused on large-scale corporate data theft and extortion campaigns worldwide.
The claimed FBI personnel breach
The detention follows claims published by ShinyHunters on 22 September 2026, when the group announced that it had penetrated internal FBI networks. The group asserted that it had exfiltrated extensive databases covering nearly every current and former employee at the agency, alongside records belonging to individuals who applied for employment. The intrusion has drawn comparisons to the 2015 cyberattack against the United States Office of Personnel Management, an incident attributed to Chinese-linked hackers that exposed sensitive background information on millions of Americans vetted for federal security clearances.
To validate its breach claims, the hacking collective shared what it described as a defaced screenshot of the FBI recruitment website and published a data sample containing records on roughly 5,000 personnel. Review of the released sample indicated that it included names, residential addresses, Social Security numbers, operational roles, and job assignments. The compromised material also featured names of agents' family members as well as sensitive medical and psychiatric evaluations.
- FBI releases an advisory detailing ShinyHunters methods and advising targets against paying ransoms.
- ShinyHunters announces an intrusion into FBI networks and publishes a sample of 5,000 records.
- Jordanian authorities take Saif al-Din Khader into custody in Jordan.
- Reports confirm Khader is cooperating with the FBI to locate other syndicate members.
Retaliatory motives on the dark web
In dark web postings and online messages, ShinyHunters stated that the breach was not driven by financial motives. Instead, the syndicate characterized the attack as direct retaliation for an advisory published by the FBI in May 2026. That public advisory outlined the operational tactics and extortion techniques used by ShinyHunters and explicitly urged targeted organizations not to pay ransom demands. In its public communications following the breach, the group demanded that the FBI officially retract the advisory detailing its extortion methods.
Law enforcement response and global operations
The FBI declined to discuss the specific circumstances surrounding Khader's detention or clarify his current physical location. However, the bureau released an official statement affirming that it is aggressively investigating the cyber incident linked to the hacking collective. Federal authorities confirmed that collaborative efforts with foreign law enforcement partners have already led to the detention of multiple suspects connected to the group.
The FBI continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects, and we will spare no resource in bringing each of the responsible individuals to justice.
International authorities continue joint investigative operations to trace remaining infrastructure, unmask further aliases, and execute additional warrants tied to the group.


