Hacker Linked to ShinyHunters FBI Hack Detained in Jordan | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker



In September, the infamous ShinyHunters hacking group claimed it had infiltrated the FBI job recruitment portal, stealing confidential data belonging to 5,000 employees and even changing the FBI logo to its own. The group has been implicated in the hacking of numerous large and high-profile organizations over the years, from the European Commission to Grand Theft Auto-maker Rockstar Games and the software firm behind Canvas.

Now, Reuters reports that a suspected leader of the group, Saif al-Din Khader, is being detained in the country of Jordan in the Near East. Al-Din Khader—who uses the name Rey online—is said to be cooperating with the authorities, helping FBI and global law enforcement to find the other hackers in the group, according to sources who spoke to Reuters.

According to independent security researcher Brian Krebs, Rey was responsible for releasing a ransomware strain known as ShinySp1d3r, and had been the administrator of the data leak website for Hellcat, a ransomware group which has been linked to attacks on Schneider Electric, Telefonica, and Orange Romania. He is reportedly still a teenager.

The FBI has yet to officially confirm the reports.

The latest arrest comes after a series of wins for the FBI against the group. At the end of last month, FBI Director Kash Patel claimed another member of the group, had been detained in the Netherlands, who Krebs alleged was named Pepijn van der Stap. Meanwhile, earlier this week, Reuters reported that ShinyHunters’ dark web site, which members can use to communicate anonymously and which cannot be accessed via the regular internet, had disappeared.

Recommended by Our Editors

Patel has been clear that the FBI’s campaign against the hacking group will continue, saying on X earlier this week that the FBI’s teams are working on new leads and that more arrests “are on the table.”

ShinyHunters has been clear that it doesn’t plan to ransom the stolen data and that it is not an act of extortion, claiming the attack “was all a marketing campaign to protect our business and actively combat disinformation” in a statement to journalists. The group instead demanded that the FBI correct or remove a public advisory it had issued about the group in May 2026, which said the hackers often exaggerated their claims of access to victims’ data.

About Our Expert





Source link

...........