A suspected high-ranking member of the notorious ShinyHunters digital extortion collective, operating under the online alias "Rey," has reportedly been detained by authorities in Jordan, according to people familiar with the matter. The suspect, whose real name is Saif-al-Din Khader and who also utilized the handle ReyXBF, was taken into custody on September 29, 2026. Sources indicate that Khader is actively cooperating with the U.S. Federal Bureau of Investigation (FBI) and international law enforcement agencies to help identify and locate other core members of the cybercrime organization. Read Also: Lunex Malware-as-a-Service Platform Unmasked as the Engine Behind Psychedelic Stealer Attacks in Ukraine North Korean Threat Actors Expand Supply Chain Attacks to Terraform Registry and Go Modules with Sophisticated Multi-Channel Malware "His cooperation is critical to ongoing efforts to arrest these hackers," one source told Reuters, which first reported the detention. Khader is a well-known figure within high-level cybercriminal circles. In a detailed threat intelligence report published in November 2025, independent security journalist Brian Krebs identified Khader as one of the three principal administrators behind Scattered LAPSUS$ Hunters, an aggressive digital threat group assessed to be a strategic amalgamation of personnel from Scattered Spider, LAPSUS$, and ShinyHunters. Before his involvement with that hybrid collective, Khader served as an administrator for the data leak website associated with Hellcat, a ransomware operation that emerged in late 2024. During that same year, he assumed control as an administrator for the most recent iteration of BreachForums, a prominent hub for stolen data and illicit trading. Furthermore, records show that Khader had already begun cooperating with law enforcement agencies as early as June 2025. This latest development marks a significant escalation in the ongoing international crackdown against the ShinyHunters network. It follows closely on the heels of another major law enforcement action last week, which involved the arrest of a 24-year-old man in Amsterdam due to his alleged participation in the cybercriminal group’s operations. Although Dutch authorities have not officially confirmed his identity, independent investigative reports revealed the suspect to be Pepijn van der Stap, a reformed hacker who had more recently been employed as an offensive security lead at Neo Security, a Dutch cybersecurity firm. Following that arrest, a spokesperson for ShinyHunters publicly denied any operational connections to van der Stap. The successive arrests have drawn direct responses from top U.S. law enforcement officials. Following the Amsterdam operation, FBI Director Kash Patel took to social media to emphasize the momentum of the investigation. "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest," Patel posted online, following up shortly thereafter to note that more apprehensions remained under active consideration. Over recent weeks, ShinyHunters has thrust itself into the center of the global cybersecurity spotlight through a series of high-profile and disruptive cyber operations. The collective claimed responsibility for hijacking the darknet website of a rival extortion group, Cl0p, by exploiting an unpatched vulnerability in Grav CMS. Shortly thereafter, the group made headlines by infiltrating the FBI’s online recruitment portal, "apply.fbijobs.gov," exfiltrating approximately three terabytes of sensitive data. Despite breaking into the federal portal, ShinyHunters insisted that its motive was not financial extortion. Instead, the group claimed the hack was intended to exert political pressure on the FBI, challenging public statements made by the agency regarding the collective’s alleged operational ties to "The Com." The Com is a loose-knit cybercrime collective notorious for employing aggressive tactics such as social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, and physical violence. Law enforcement officials have underscored the sheer scale of the financial and operational damage caused by the network. Brett Leatherman, assistant director of the FBI’s cyber division, noted in a recorded public statement that the cybercriminal group and its co-conspirators have breached more than 140 organizations since the previous year, raking in at least $70 million in illicit extortion payments. "They often target third-party vendors in cloud-based platforms, stealing sensitive data and extorting victims with threats to publish it," Leatherman said, specifically characterizing van der Stap as one of the primary leaders of the threat actor group. Leatherman directly addressed remaining members of the cybercrime organization, warning them that international borders and perceived anonymity will no longer shield them from prosecution. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you," Leatherman added. "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours." Detailed threat intelligence analysis conducted by cybersecurity firms Sekoia and Beazley Security traces the historical lineage of ShinyHunters back to two earlier progenitor groups, TheDarkOverlord and GnosticPlayers, both of which specialized in corporate extortion and bulk data leak operations. The ShinyHunters brand itself officially materialized around April and May 2020. Security researchers Enzo Saez and Robert Venal observed in a joint retrospective analysis that the collective has evolved over six years into something resembling a persistent business model rather than a traditional hierarchical gang. "What began in 2020 as a small crew trading stolen databases on RaidForums has become a persistent, self-renewing group that has absorbed indictments, arrests, and forum seizures without ever going quiet for long," the researchers noted. "That resilience is the real story. It doesn’t come from any single leader or cell, but from a division of labor that has become almost modular: initial access from social engineers, amplification and recruitment from adjacent actors, and monetization under a shared, recognizable brand." Post navigation China-Linked Warlock Ransomware Group Continues Exploitation of Microsoft SharePoint Vulnerabilities Targeting Critical Infrastructure China-Aligned TA419 Campaign Targets U.S. Artificial Intelligence Experts with Advanced Phishing Tactics