Yaamlabs

Threat intel

ShinyHunters suspect Rey held in Jordan: use the lull

Jordan detained the ShinyHunters member known as Rey, reportedly now helping the FBI. What is confirmed, what is not, and what to fix while the group regroups.

Jordanian authorities have detained Saif al-Din Khader, the young Jordanian who has used the handle "Rey" in the ShinyHunters extortion group and the wider Scattered Lapsus$ Hunters alliance. Reuters first reported the detention on October 3, citing three people familiar with the case, two of them US officials according to CBS News. Those sources say he is walking investigators through his devices and messages to help find other members. On October 4 The National reported that Jordanian state media had confirmed the arrest and said "investigations are ongoing with the suspect about the activities of the group and the groups it is connected with."

This is the second arrest in the case in three weeks, after the Dutch arrest we covered yesterday. The FBI links ShinyHunters to more than 140 breached organizations and at least $70 million in extortion payments since 2025. Within days of the detention a new ShinyHunters leak site was online, which means other members still run the brand. If you are negotiating with it, were named on a leak site, or run the Jira, PeopleSoft or SSO setups it has used, the steps below apply now.

What is confirmed and what is not

Most of what has been published rests on anonymous sources, so it helps to sort it. Officially on the record: Jordan's state media statement as reported by The National, and the FBI's line that it "continues to aggressively investigate" and has "already worked with partners to arrest multiple subjects." The FBI declined to comment on Khader specifically. FBI Director Kash Patel posted that "more arrests are on the table."

Reported only through unnamed sources: that Khader is cooperating, that he has handed over devices and correspondence, and the exact date. The Record puts the detention on September 28. Hackread, The Hacker News and Reuters' own account of losing contact with the group's account point to Tuesday, September 29. His location in custody has not been disclosed. He has not been charged in any public court filing we could find, and he is presumed innocent.

One claim from the earlier coverage has firmed up. When we wrote about the FBI breach claim on September 26, the theft was unverified. Since then Reuters partly authenticated a sample of about 5,000 personnel records, matching details for more than 22 people against credit records, and NBC News reports the Justice Department has told staff that Social Security numbers, dates of birth, addresses and emergency contacts were exposed.

How a cooperating insider changes the case

Rey was not a peripheral member. BleepingComputer reports he held administrative access in Scattered Lapsus$ Hunters channels, and Hackread reports he had recently taken control of the ShinyHunters name in a dispute with the Dutch suspect. A person in that position has chat histories, wallet addresses, server logins and the handles of people he worked with. FBI Cyber Division Assistant Director Brett Leatherman, who on September 30 urged remaining members to "reach out first while the choice is still yours," put it this way: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left."

There is a caveat. Rey told Brian Krebs in November 2025 that he had been talking to law enforcement since June 2025, and Help Net Security and Security Affairs repeat that account. If true, some of what he knows may already have been used, and the rest of the group has had months to suspect him.

Before ShinyHunters, Rey operated under the Hellcat name. KELA and BleepingComputer tie him to the January 2025 Telefónica Jira breach, the Orange Romania theft of about 6.5 GB in February 2025, and the March 2025 Jaguar Land Rover leak. In the JLR case the login came from a third-party employee's Jira credentials that infostealer malware had captured years earlier and that were still valid.

What the group is doing now

The day Khader was reportedly detained, Reuters lost contact with the group's usual messaging account and an affiliate who had briefed reporters on the FBI attack closed theirs. The dark web leak site was offline by Wednesday. On Thursday, October 1, a new site appeared listing O'Reilly Automotive and DexCom with a Friday deadline; Cybernews and Hackread report both entries were deleted on October 3. ShinyHunters told Cybernews the outage came from upgrades and attacks by rivals, not the FBI.

On the FBI data the group now backs down. It says it "never intended" to publish the FBI material and calls the whole episode "a marketing campaign to protect our business," while SecurityWeek reports it promised to "make examples" of victims who treat the arrests as a free pass. Someone still controls the brand and can post and delete listings.

What to do while the group is disrupted

If you have received a demand, keep the record. Save the full negotiation chat, the sample files they sent, any wallet addresses and the leak site URL with a timestamped screenshot, then report it at ic3.gov. The FBI's May 15 advisory, PSA260515, already asked victims not to pay. With a cooperating insider and seized devices, investigators may be able to match your case to specific people and payments, and they need your side of the record to do that.

Silence from your contact is not the end. A handle going dark, a listing being deleted, or a new handle asking you to "continue" are all consistent with what happened this week. Treat a new contact as unverified. Ask for proof tied to your environment (file paths, record IDs, timestamps) and check it against your own logs before you engage further.

Close the Jira path Rey used. In Atlassian Administration, list every Jira and Confluence account that belongs to a contractor or partner, sort by last active date, and deactivate anything idle for 90 days or longer. Force those users through your SSO with multi-factor authentication (MFA) instead of local passwords, and revoke their API tokens. If you buy infostealer log monitoring, search it for your Atlassian hostnames; the JLR credentials had been sitting in such logs for years.

Confirm the fixes we have already covered. The group's two current entry routes are Oracle PeopleSoft CVE-2026-35273, fixed in Oracle's June 10 Security Alert yet still yielding web shells in late September (our patch and IOC guide), and phone calls that talk staff through an SSO login and MFA approval (the factor and download hunts).

If your HR data is exposed, tell staff before the press does. NBC News reports some FBI employees learned of their own exposure from the media, and the Bureau's guidance to staff was to assume exposure and treat unsolicited contacts with suspicion. Personal details from an HR system are exactly what a convincing vishing call needs. Name the fields that leaked and tell employees how the help desk will and will not contact them.

The wider lesson

The stolen credentials and unpatched systems a group relies on stay exposed after its members are arrested. The Hellcat history shows a stale contractor login doing as much damage as a zero-day. A quiet week after an arrest is a good time to remove access nobody uses and to finish the patch and MFA work that keeps being deferred.

Our attack surface management work finds forgotten external logins and exposed PeopleSoft and Atlassian instances, and security operations can run the account and factor hunts above across your tenants. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: The Record, BleepingComputer, The National, CBS News, Hackread, Help Net Security, SecurityWeek, Security Affairs, SecurityWeek on the FBI appeal, NBC News, Cybernews, Nextgov, KELA, FBI IC3 PSA260515.

Back to the blog, or read this post on the full site.