
ShinyHunters Is Collapsing From the Inside. Meet Rey, the Hacker Who Flipped.
Mahmud Hasan
October 4, 2026
Who "Rey" allegedly is
On Tuesday, September 29, Jordanian authorities detained Saif al-Din Khader, a Jordanian hacker known online as "Rey" and "ReyXBF," and Reuters reported — citing three people familiar with the matter — that he is now cooperating with the FBI to locate the other members of ShinyHunters. One source put it bluntly: "His cooperation is critical to ongoing efforts to arrest these hackers."
Two sources said he's walking law enforcement through his own devices and digital communications to identify his alleged co-conspirators. The FBI declined to confirm any specific arrest, but said it "continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice."
Khader's résumé, as assembled by independent security journalist Brian Krebs and BleepingComputer, reads like a tour of the last two years of high-profile cybercrime. Krebs identified him in November 2025 as one of three administrators of Scattered LAPSUS$ Hunters — assessed to be an amalgam of the Scattered Spider, LAPSUS$, and ShinyHunters crews. Before that, Krebs reported, Rey administered the data-leak site for the Hellcat ransomware group and, in 2024, took over as administrator of the latest incarnation of the BreachForums hacking forum.
BleepingComputer's own reporting fills in the operational history: in January 2025, Rey was one of four threat actors who claimed responsibility for breaching Telefónica's internal Jira ticketing system, walking off with roughly 2.3GB of documents and tickets. A month later, Orange confirmed its Romanian operations had been hit after Rey leaked about 6.5GB of stolen data — which he told BleepingComputer he'd done independently, outside his Hellcat membership. He was also linked to a March 2025 Jaguar Land Rover breach (Jira issues, source code, employee information, development logs leaked) and to the September 2025 attack on the automaker that forced it to halt production for weeks at a cost of more than $220 million.
The theft that started the clock
What made the FBI's pursuit of ShinyHunters a personal vendetta was the group's September claim: they told BleepingComputer they had breached FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability, then moved laterally into FBI-managed AWS GovCloud systems. The claimed haul: between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, and medical and psychiatric records.
Caveats, straight from the reporting: BleepingComputer has not independently verified the alleged zero-day, the lateral movement, or the data volume. The FBI has confirmed only that it is investigating claims of unauthorized activity — not that data was stolen. But the claim alone, if true, would be the most audacious targeting of federal personnel data since the Chinese-linked OPM breach of 2015, which compromised vetting records of millions of Americans with security clearances. Bragging to the press about robbing the FBI guarantees the full weight of the Bureau's Cyber Division.
The FBI's flip playbook
Rey's detention is the second shoe dropping. On September 15, Dutch police arrested a 24-year-old Amsterdam man as part of the same investigation — identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, a former hacker who had been working as an offensive security lead at the Dutch firm Neo Security under the alias "Umbreon." A ShinyHunters spokesperson promptly denied any connection to him, which is exactly what you'd expect a spokesperson to say either way.
After that arrest, the FBI stopped being subtle. Cyber Division Assistant Director Brett Leatherman issued a public warning to the remaining members: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."
That is not a bluff backed by nothing. Khader told Krebs over Signal back in November 2025 that he'd already been cooperating with law enforcement since at least June 2025 — "I have told them nearly everything," he allegedly said, adding he hadn't "done anything like breaching into a corp or extortion related since September." Krebs said he couldn't verify those claims at the time. Reuters' reporting this week suggests the FBI found them credible enough to work with.
Why crews die this way
The most telling detail in BleepingComputer's report isn't the detention itself — it's what happened on the day of it. Tuesday, the same day Khader was reportedly taken into custody: an alleged ShinyHunters affiliate who had been briefing media about the FBI attack abruptly shut down his messaging account. The ShinyHunters data-leak site went offline. The group's main press representative stopped answering questions from BleepingComputer and Reuters.
Whether the silence came from a flipped admin or from panic, the effect is identical. A cybercrime crew runs on trust — trust that your collaborators aren't informants, that the guy running the leak site isn't walking agents through his phone. Once one administrator cooperates, every remaining member has to assume every message is being read. The paranoia is the weapon.
This is how these takedowns actually work. The cinematic version — dawn raids, handcuffs, seized servers — is the exception. The FBI's standard play against groups like ShinyHunters is to convert insiders and let the trust collapse do the demolition. It worked on the original LAPSUS$ teenagers arrested in the UK in 2022, on the BreachForums operators before them, and now, apparently, on the Frankenstein crew stitched from their remnants.
The honest counter-argument: it didn't kill the brand. On Thursday, a new ShinyHunters data-leak site went online, suggesting other members are continuing the extortion operation. ShinyHunters is less a roster than a label — the people operating under the name may have changed several times since it first surfaced in 2019–2020 selling tens of millions of stolen accounts on the dark web. Arresting a name is hard when the name keeps changing owners. BleepingComputer estimates the group's extortion demands in 2026 alone could reach $100 million, and as long as that money flows, there will be volunteers.
What this means for your SaaS stack
Here's the part that actually concerns working developers. ShinyHunters' signature move isn't zero-days — it's supply-chain SaaS theft. The gang breaches third-party integration companies and uses stolen authentication tokens to walk into connected SaaS environments. Recent campaigns hit Salesforce environments and were linked to breaches at Google, Cisco, and PornHub; in May, an attack on Instructure Canvas caused significant outages, and the company eventually reached an "agreement" with the threat actors to keep the stolen data offline.
The lesson is unglamorous but real: audit your OAuth grants and third-party integrations the way you'd audit open ports. Every connected app with broad read scope is a potential ShinyHunters entry point — not into your servers but into your SaaS data, where your most sensitive data actually lives now. Rotate tokens, scope integrations to the minimum they need, and treat your Jira instance (Rey's favorite target) as internet-facing infrastructure, because to attackers, it is.
Rey flipped. Others will too — Leatherman all but published the recruitment pitch. The crew will regenerate under a new name, and the FBI will flip someone in that one as well. The only part of this cycle you control is how hard your own integrations are to walk through.
References
- Reuters (via The Jerusalem Post), "Key ShinyHunters hacker detained in Jordan, is cooperating," October 3, 2026 — https://www.jpost.com/international/article-910467
- The Hacker News, "ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members," October 4, 2026 — http://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html
- BleepingComputer, "ShinyHunters hacker reportedly detained in Jordan, aiding FBI," October 2026 — https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/
- informed, clearly, "ShinyHunters Hacker Arrested in Jordan, Cooperating With FBI," October 2026 — https://informedclearly.com/en/crime/63659/shinyhunters-hacker-arrested-jordan-fbi
Comments
More in Technology

The US Banned Selling AI Chips to China. So China Rented Them Back for $7 Billion.
America's chip export controls cover physical hardware, not remote compute. A reported $7 billion Tencent–Oracle lease shows how that distinction turned sanctions into a subscription business — and why Washington's fix is stuck in the Senate.
Read more
GitHub Copilot Can Now Operate Your Computer. Don't Touch "Always Allow" Yet.
GitHub Copilot can now click through desktop apps like you do. It is disabled by default and asks for approval per app — and the "always allow" button is the one setting worth reading about before you touch it.
Read more
Your BIG-IP's OAuth Server Has a 9.8 Hole, and Hiding the Admin UI Won't Help
A 9.8 unauthenticated RCE on F5 BIG-IP's OAuth path is under active attack — and hiding the admin UI won't help. Here's the configuration check that decides your week.
Read more