ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau: Reuters
Note: AI technology was used to generate this article’s audio.
- Jordanian authorities detained Saif al-Din Khader, a suspected member of the ShinyHunters hacking group, according to three people familiar with the matter.
- Sources said Khader is cooperating with the FBI and helping investigators identify other alleged members of the group.
A suspected member of the ShinyHunters hacking group was detained in Jordan this week and is cooperating with US and international law enforcement, three people familiar with the matter told Reuters.
Jordanian authorities detained an individual, whose alleged hacker alias is “Rey,” the sources said. Two sources said he was taken into custody on Tuesday.
Reuters could not immediately determine the circumstances of Khader’s detention or where he is being held.
Two sources said Khader is assisting the FBI and other law enforcement agencies in locating other alleged members of the group. One source said he has been walking investigators through his electronic devices and digital correspondence.
“His cooperation is critical to ongoing efforts to arrest these hackers,” the source told Reuters.
The FBI declined to comment on Khader’s detention specifically but said it was continuing to investigate the cyber incident allegedly involving ShinyHunters.
The bureau said it had already worked with international partners to arrest multiple suspects and would use “no resource” to bring those responsible to justice.
The detention comes after ShinyHunters claimed it had stolen data relating to every FBI employee.
A Reuters analysis of a sample of the data previously shared by the group found extensive personally identifiable information belonging to FBI employees, along with sensitive information about their job roles and psychiatric and medical records.
The alleged breach has raised comparisons with the 2015 cyberattack on the US Office of Personnel Management, which compromised sensitive information belonging to millions of Americans who had undergone background checks for security clearances.
The FBI has not publicly confirmed the full extent of the data allegedly stolen by ShinyHunters.
ShinyHunters has appeared increasingly disrupted since claiming responsibility for the FBI intrusion.
Reuters said it was unable to reach the group through an online account previously used to communicate with journalists. Its dark web site also disappeared after the FBI's deadline for the group to withdraw an advisory-related threat expired.
FBI Director Kash Patel had indicated that further arrests could follow the detention of another alleged ShinyHunters member, Pepijn van der Stap, in the Netherlands.
“FBI teams are working new leads RIGHT NOW,” Patel said on X on Wednesday. “More arrests are on the table.”
The group had previously threatened further action against the FBI after accusing the bureau of making “exaggerated claims of access” in an advisory about its activities.
However, in its most recent communication with Reuters, operators using a ShinyHunters-linked email address said they wanted “no further escalation” with the FBI and suggested the message could be interpreted as the group “backing down completely.”
Khader’s alleged connection to ShinyHunters was reportedly known to cybersecurity researchers before his detention.
Independent journalist Brian Krebs reported in 2025 that Khader was a key member of Scattered Lapsus$ Hunters, an umbrella group associated with ShinyHunters and other hacking collectives.
Krebs also reported that Khader had previously said he had left the data-breach and extortion scene and was cooperating with law enforcement.
Despite that reported claim, ShinyHunters continued to operate and claimed responsibility for several major breaches in 2026, including attacks involving video game developer Rockstar Games and education technology company Canvas.
Cybersecurity researchers have described ShinyHunters as a prolific data-theft and extortion group believed to consist largely of young, English-speaking hackers.
Law enforcement agencies in the US and other countries have struggled to prosecute members of related groups, with the young age of some suspects, the informal structure of the groups and victims’ reluctance to cooperate with investigators among the challenges cited by experts and officials.



