Jordanian authorities reportedly detained Saif al-Din Khader, known online as “Rey” and alleged to be a ShinyHunters member, on September 29. Reuters cited three people familiar with the matter, two of whom said he was cooperating with the FBI to identify fellow hackers. The FBI did not confirm his detention but acknowledged an ongoing investigation into a cyber incident allegedly involving ShinyHunters and arrests conducted with partner agencies. A separate alleged group leader was arrested in Amsterdam on September 15; ShinyHunters denied that person's membership, and the allegations remain unproven.
ShinyHunters claimed it stole records on every FBI employee by exploiting an undisclosed Oracle PeopleSoft vulnerability and accessing FBI-managed AWS GovCloud systems. Neither the alleged attack path nor the scope of the theft has been confirmed. Reuters partially matched information in at least 10 purported employee records, but that did not establish that the records came from compromised FBI systems. The reported detention marks a law-enforcement development, while the claimed PeopleSoft-to-GovCloud intrusion remains an unverified account rather than an established exploit chain.

See the reporting duties and controls this puts on the clock.
27 events from the most recent confirmed update back to the earliest known activity.
ShinyHunters resurfaced on Telegram after its leak site went offline and claimed it was restarting a long-defunct cybercriminal forum to replace the site. The report did not independently confirm the claimed forum revival.
ShinyHunters’ dark web site disappeared Wednesday, after Reuters lost contact with a previously used group account on Tuesday. The operators attributed the outage to rival sabotage and an unrelated disruption; the source does not establish a connection to law enforcement activity.
Sources told Reuters that Jordanian authorities detained Saif al-Din Khader, allegedly known online as Rey. Reuters could not establish why he was detained or where he was being held.
Mandiant and Google Threat Intelligence Group reported that ShinyHunters mass-exploited Oracle PeopleSoft vulnerability CVE-2026-35273 to steal data from dozens of systems. Affected sectors included higher education, technology, healthcare, agriculture, transportation and government.
Dutch police detained a 24-year-old Amsterdam suspect described as an alleged ShinyHunters leader, with FBI support. The allegations against the suspect remain unproven.
In November 2025, Brian Krebs reported that Rey was Saif al-Din Khader, based on infostealer logs and direct Signal communications with Khader. Khader also told Krebs that he had been quietly cooperating with law enforcement since June, a claim the reference does not independently verify.
On September 23, 2025, Jaguar Land Rover extended its cyberattack-related vehicle production shutdown by at least another week. Suppliers faced staff layoffs and potential closure during the shutdown and called for government intervention.
The reference links Saif al-Din Khader, known online as Rey, to the January 2025 breach of Telefónica’s internal Jira system through the HellCat ransomware operation. Approximately 2.3 GB of data was reportedly stolen; his involvement remains an allegation.
The FBI reportedly removed an Accenture contractor after the contractor failed to apply a security patch to third-party software used by the agency. Insiders identified the software as PeopleSoft, but the report does not establish that the missed patch enabled the alleged intrusion.
FBI Cyber Division assistant director Brett Leatherman issued a video urging remaining ShinyHunters members to contact the bureau, warning that arrested suspects’ cooperation and seized infrastructure could help identify them. The FBI declined to confirm whether it had seized infrastructure or whether members had responded.
Security researcher Kevin Beaumont alleged on Mastodon that Rey, identified as Saif al-Din Khader, was among the hackers who compromised JLR. The allegation was not included in Reuters' report and remains unconfirmed.
Orange Group confirmed a breach after a hacker leaked company documents. The provided reference does not specify the breach's scope or identify the attacker.
ShinyHunters told 404 Media that it would not publish the allegedly stolen FBI data and had never intended to do so. A representative characterized the operation as a marketing campaign to protect its business and counter alleged misinformation.
Another ShinyHunters leak site reportedly appeared after the group's previous site disappeared, suggesting its online operations had not been completely dismantled.
ShinyHunters told Reuters in an email that it wanted “no further escalation” with the FBI. The article also reported indications that the group would not publish the allegedly stolen FBI personnel data, although it did not establish a confirmed decision to withhold it.
FBI cyber division assistant director Brett Leatherman alleged that the arrested Amsterdam suspect and his co-conspirators breached more than 140 organizations and received at least $70 million in extortion payments. Independent reports identified the suspect as Pepijn van der Stap, although authorities had not disclosed his identity.
The FBI said it was investigating a recent cyber incident allegedly involving ShinyHunters and had worked with partners to arrest multiple subjects. It declined to confirm any specific arrest or overseas operation.
Two sources said the detained hacker was cooperating with the FBI and helping law enforcement locate other ShinyHunters members. His reported cooperation does not establish his involvement in the alleged FBI breach.
Sources said ShinyHunters was attempting to extort Jeppesen ForeFlight when Jordanian authorities detained Rey, and that the allegedly stolen information could pose aviation safety and security risks. Boeing acknowledged the threat actor’s claims and said it was reviewing the matter with its former subsidiary; Jeppesen ForeFlight said its investigation found no impact on operations or products.
ShinyHunters denied that the suspect arrested in Amsterdam was associated with the group.
Reuters partially matched information in at least 10 cases from the supplied records. Its checks did not establish that the records originated from compromised FBI systems.
The attackers provided a sample of 5,000 alleged employee records reportedly containing personal identifiers, home addresses, assignments, and family details.
ShinyHunters claimed it exploited an undisclosed Oracle PeopleSoft vulnerability, accessed FBI-managed AWS GovCloud systems, and downloaded two to three terabytes of data containing information on every FBI employee. The claimed attack path and scope of the theft remain unconfirmed.
The FBI took its application service and Special Agent Applicant Portal offline while investigating unauthorized activity affecting its recruitment systems.
Khader reportedly placed a defacement image featuring the Pokémon character Umbreon on the FBI recruitment website to implicate Pepijn van der Stap in the compromise. Journalist Brian Krebs reported that van der Stap used the nickname Umbreon in his extortion activities; the alleged attempt to implicate him remains unconfirmed.
Earlier reporting described attackers taking over apply.fbijobs.gov and displaying a fake seizure notice. The public website takeover did not establish access to the FBI's wider network.
ShinyHunters reportedly compromised rival cybercrime group Clop and defaced its leak site. The reference states that the reported FBI intrusion followed shortly afterward.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
22 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcekrebsonsecurity.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcecybersecuritynews.com
Open sourcereuters.com
Open sourcemalware.news
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.