ShinyHunters Member Arrested, Cooperating with FBI in Jordan
Key Takeaways A suspected member of the ShinyHunters hacking group, Saif al-Din Khader (allegedly known as “Rey”), has been detained in Jordan. Khader is reportedly cooperating with the...
Key Takeaways
- A suspected member of the ShinyHunters hacking group, Saif al-Din Khader (allegedly known as “Rey”), has been detained in Jordan.
- Khader is reportedly cooperating with the FBI and international law enforcement to identify other individuals associated with ShinyHunters.
- This detention follows ShinyHunters’ unverified claim of having stolen 2-3 terabytes of data, including sensitive personnel records, from FBI recruitment systems.
- The FBI maintains an active investigation into the alleged breach and aims to pursue all responsible parties.
Suspected ShinyHunters Member Detained in Jordan, Cooperating with FBI
A significant development in the ongoing investigation into the ShinyHunters hacking group has emerged, with reports indicating the detention of a suspected member in Jordan. Identified as Saif al-Din Khader, who allegedly uses the online alias “Rey,” the individual is reportedly assisting the FBI in identifying other hackers linked to the notorious cybercrime syndicate.
Table Of Content
According to Reuters described on October 3, three individuals with knowledge of the situation confirmed Khader’s detention. Sources indicated that Jordanian authorities took Khader into custody on Tuesday, September 29. These same sources elaborated that Khader is actively collaborating with the FBI and other global law enforcement agencies to pinpoint additional members of the ShinyHunters group. The specific reasons for his detention and his current location remain undisclosed, and attempts to reach Khader or his family were unsuccessful.
While the FBI refrained from confirming any particular arrest or ongoing overseas operation, the bureau affirmed its commitment to “aggressively investigate the recent cyber incident allegedly involving ShinyHunters.” The FBI further stated that it has already collaborated with partners to apprehend multiple suspects and vowed to bring all responsible parties to justice.
Unverified Claims of FBI Data Theft
This detention follows ShinyHunters’ assertion that it successfully exfiltrated data belonging to every FBI employee. However, this claim remains unverified. Khader’s reported cooperation does not, at this stage, confirm his direct involvement in this specific incident or substantiate the group’s account of their alleged access to FBI systems.
Previous reports concerning the purported breach of the FBI jobs portal detailed a defacement of apply.fbijobs.gov, where attackers displayed a fabricated seizure notice. In response, the FBI temporarily took its application service and Special Agent Applicant Portal offline to investigate unauthorized activity affecting its recruitment infrastructure.
ShinyHunters claimed to have exploited an undisclosed vulnerability within Oracle PeopleSoft, which allegedly permitted code execution without authentication. The group further asserted that they subsequently gained access to FBI-managed AWS GovCloud systems and downloaded between two and three terabytes of data. Neither Oracle, AWS, nor the FBI has corroborated this alleged attack vector or the extent of the data exfiltration.
As evidence, the attackers provided journalists with a sample of 5,000 alleged employee records. This sample purportedly contained sensitive information such as names, home addresses, phone numbers, Social Security numbers, dates of birth, assignments, and family details. While Reuters partially matched information in at least ten instances, this verification did not definitively confirm that the records originated from compromised FBI systems.
It is crucial to differentiate between controlling a public-facing website and gaining access to an agency’s broader internal network. Investigators must meticulously analyze server logs, account activity, cloud access records, and outgoing data transfers to accurately determine the attackers’ entry points and the precise scope of data removed.
If the reported personnel records are indeed genuine, they could pose significant risks, enabling targeted phishing campaigns, identity fraud, harassment, or direct threats against FBI employees and their families. The inclusion of assignment details and family contacts could render fraudulent communications highly convincing, even if the attackers no longer retain access to government systems.
The detention in Jordan also comes on the heels of another arrest: an alleged ShinyHunters leader was apprehended in the Netherlands. Dutch police, with FBI assistance, detained a 24-year-old suspect in Amsterdam on September 15. However, ShinyHunters has denied any association between this suspect and their group, and the allegations against him remain unproven.
Reuters described ShinyHunters as a collective believed by cybersecurity experts to primarily consist of young, English-speaking hackers focused on data theft and extortion. Khader’s reported cooperation could prove instrumental in connecting online identities to real individuals, though Reuters did not disclose the specifics of the information he has provided.
Key questions persist regarding Khader’s legal status, the full scope of his cooperation, and the precise extent of the alleged FBI data theft. Neither the detention report nor the group’s public claims definitively answer these critical inquiries. The FBI’s investigation remains active, and further findings are necessary to distinguish confirmed evidence from attacker statements and other unverified allegations.
What You Should Do
- Law enforcement and intelligence agencies should continue to collaborate internationally to track and apprehend cybercriminals.
- Organizations, especially those handling sensitive government data, must maintain robust security postures, including regular vulnerability assessments and penetration testing.
- Employees, particularly those in high-risk organizations, should remain vigilant against sophisticated phishing attempts and social engineering tactics that leverage personal information.
- Implement multi-factor authentication (MFA) across all systems, especially for access to sensitive data and administrative portals.
- Conduct regular security awareness training for all personnel, emphasizing the risks of data breaches and the importance of secure online practices.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.