Byte by Mahmud logoByteby Mahmud
ShinyHunters Is Collapsing From the Inside. Meet Rey, the Hacker Who Flipped.
Technology7 min read2 views

ShinyHunters Is Collapsing From the Inside. Meet Rey, the Hacker Who Flipped.

Mahmud Hasan

Mahmud Hasan

October 4, 2026

Who "Rey" allegedly is

On Tuesday, September 29, Jordanian authorities detained Saif al-Din Khader, a Jordanian hacker known online as "Rey" and "ReyXBF," and Reuters reported — citing three people familiar with the matter — that he is now cooperating with the FBI to locate the other members of ShinyHunters. One source put it bluntly: "His cooperation is critical to ongoing efforts to arrest these hackers."

Two sources said he's walking law enforcement through his own devices and digital communications to identify his alleged co-conspirators. The FBI declined to confirm any specific arrest, but said it "continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects — and we will spare no resource in bringing each of the responsible individuals to justice."

Khader's résumé, as assembled by independent security journalist Brian Krebs and BleepingComputer, reads like a tour of the last two years of high-profile cybercrime. Krebs identified him in November 2025 as one of three administrators of Scattered LAPSUS$ Hunters — assessed to be an amalgam of the Scattered Spider, LAPSUS$, and ShinyHunters crews. Before that, Krebs reported, Rey administered the data-leak site for the Hellcat ransomware group and, in 2024, took over as administrator of the latest incarnation of the BreachForums hacking forum.

BleepingComputer's own reporting fills in the operational history: in January 2025, Rey was one of four threat actors who claimed responsibility for breaching Telefónica's internal Jira ticketing system, walking off with roughly 2.3GB of documents and tickets. A month later, Orange confirmed its Romanian operations had been hit after Rey leaked about 6.5GB of stolen data — which he told BleepingComputer he'd done independently, outside his Hellcat membership. He was also linked to a March 2025 Jaguar Land Rover breach (Jira issues, source code, employee information, development logs leaked) and to the September 2025 attack on the automaker that forced it to halt production for weeks at a cost of more than $220 million.

The theft that started the clock

What made the FBI's pursuit of ShinyHunters a personal vendetta was the group's September claim: they told BleepingComputer they had breached FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability, then moved laterally into FBI-managed AWS GovCloud systems. The claimed haul: between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, and medical and psychiatric records.

Caveats, straight from the reporting: BleepingComputer has not independently verified the alleged zero-day, the lateral movement, or the data volume. The FBI has confirmed only that it is investigating claims of unauthorized activity — not that data was stolen. But the claim alone, if true, would be the most audacious targeting of federal personnel data since the Chinese-linked OPM breach of 2015, which compromised vetting records of millions of Americans with security clearances. Bragging to the press about robbing the FBI guarantees the full weight of the Bureau's Cyber Division.

The FBI's flip playbook

Rey's detention is the second shoe dropping. On September 15, Dutch police arrested a 24-year-old Amsterdam man as part of the same investigation — identified by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, a former hacker who had been working as an offensive security lead at the Dutch firm Neo Security under the alias "Umbreon." A ShinyHunters spokesperson promptly denied any connection to him, which is exactly what you'd expect a spokesperson to say either way.

After that arrest, the FBI stopped being subtle. Cyber Division Assistant Director Brett Leatherman issued a public warning to the remaining members: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

That is not a bluff backed by nothing. Khader told Krebs over Signal back in November 2025 that he'd already been cooperating with law enforcement since at least June 2025 — "I have told them nearly everything," he allegedly said, adding he hadn't "done anything like breaching into a corp or extortion related since September." Krebs said he couldn't verify those claims at the time. Reuters' reporting this week suggests the FBI found them credible enough to work with.

Why crews die this way

The most telling detail in BleepingComputer's report isn't the detention itself — it's what happened on the day of it. Tuesday, the same day Khader was reportedly taken into custody: an alleged ShinyHunters affiliate who had been briefing media about the FBI attack abruptly shut down his messaging account. The ShinyHunters data-leak site went offline. The group's main press representative stopped answering questions from BleepingComputer and Reuters.

Whether the silence came from a flipped admin or from panic, the effect is identical. A cybercrime crew runs on trust — trust that your collaborators aren't informants, that the guy running the leak site isn't walking agents through his phone. Once one administrator cooperates, every remaining member has to assume every message is being read. The paranoia is the weapon.

This is how these takedowns actually work. The cinematic version — dawn raids, handcuffs, seized servers — is the exception. The FBI's standard play against groups like ShinyHunters is to convert insiders and let the trust collapse do the demolition. It worked on the original LAPSUS$ teenagers arrested in the UK in 2022, on the BreachForums operators before them, and now, apparently, on the Frankenstein crew stitched from their remnants.

The honest counter-argument: it didn't kill the brand. On Thursday, a new ShinyHunters data-leak site went online, suggesting other members are continuing the extortion operation. ShinyHunters is less a roster than a label — the people operating under the name may have changed several times since it first surfaced in 2019–2020 selling tens of millions of stolen accounts on the dark web. Arresting a name is hard when the name keeps changing owners. BleepingComputer estimates the group's extortion demands in 2026 alone could reach $100 million, and as long as that money flows, there will be volunteers.

What this means for your SaaS stack

Here's the part that actually concerns working developers. ShinyHunters' signature move isn't zero-days — it's supply-chain SaaS theft. The gang breaches third-party integration companies and uses stolen authentication tokens to walk into connected SaaS environments. Recent campaigns hit Salesforce environments and were linked to breaches at Google, Cisco, and PornHub; in May, an attack on Instructure Canvas caused significant outages, and the company eventually reached an "agreement" with the threat actors to keep the stolen data offline.

The lesson is unglamorous but real: audit your OAuth grants and third-party integrations the way you'd audit open ports. Every connected app with broad read scope is a potential ShinyHunters entry point — not into your servers but into your SaaS data, where your most sensitive data actually lives now. Rotate tokens, scope integrations to the minimum they need, and treat your Jira instance (Rey's favorite target) as internet-facing infrastructure, because to attackers, it is.

Rey flipped. Others will too — Leatherman all but published the recruitment pitch. The crew will regenerate under a new name, and the FBI will flip someone in that one as well. The only part of this cycle you control is how hard your own integrations are to walk through.

References

  • Reuters (via The Jerusalem Post), "Key ShinyHunters hacker detained in Jordan, is cooperating," October 3, 2026 — https://www.jpost.com/international/article-910467
  • The Hacker News, "ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members," October 4, 2026 — http://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html
  • BleepingComputer, "ShinyHunters hacker reportedly detained in Jordan, aiding FBI," October 2026 — https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/
  • informed, clearly, "ShinyHunters Hacker Arrested in Jordan, Cooperating With FBI," October 2026 — https://informedclearly.com/en/crime/63659/shinyhunters-hacker-arrested-jordan-fbi

Comments

Leave a comment

Your email stays private — only your name is shown.

More in Technology