// 2 CRITICAL · 1 ZERO-DAY · 4 CVE · 2 EXPLOIT · 2 ADVISORY IN THE LAST 24H→
Jordanian teenager Saif al-Din Khader, known as "Rey," was detained in Jordan on September 28–29, 2026, and is cooperating with the FBI to identify other ShinyHunters members, according to Reuters citing multiple federal sources.

Jordanian teenager Saif al-Din Khader, known in the underground as "Rey," was detained in Jordan between September 28 and 29, 2026, and is cooperating with the FBI to identify other ShinyHunters members. Reuters reports this, citing multiple FBI sources that could not determine the precise circumstances of the detention or the location where he is being held. The FBI confirmed "multiple arrests" in the investigation but declined specific comment on Khader.

Key Takeaways
  • Saif al-Din Khader, alias "Rey," was detained in Jordan between September 28 and 29, 2026; the FBI confirms "multiple arrests" in the investigation but declines specific comment on him.
  • Khader is cooperating with the FBI to identify other group members, according to sources close to the case speaking to Reuters.
  • The detention follows the arrest of Pepijn van der Stap in Amsterdam two weeks prior; the two were locked in a dispute over control of the ShinyHunters brand documented by Brian Krebs in 2025.
  • The 1995 Jordan-U.S. extradition treaty is considered invalid by the Jordanian Supreme Court; the Constitution prohibits extradition of Jordanian citizens, leaving Khader's legal fate uncertain.
  • ShinyHunters is not dismantled: the group has reactivated its Telegram presence after its leak site was taken offline.

From Amman to the FBI's Radar: A Year in Review

Brian Krebs identified him in November 2025. A teenager from Amman, 15 years old, technical administrator of Scattered Lapsus Hunters — the cell that later evolved the ShinyHunters brand. Khader confirmed his real identity to Krebs, contacted the journalist via Signal, and spoke with the nonchalance of someone who had not yet grasped the scope of his own exposure.

In a message to Krebs, Khader wrote: "I don't really care, I just want to move on from all this even if it means prison time." Ten months later, that sentence materialized into a Jordanian detention with federal agents examining his devices.

The cooperation is not clear in the strict legal sense: the dossier does not specify whether Khader was arrested, interrogated, or agreed to cooperate in exchange for concessions. Reuters was unable to determine either the precise circumstances of the detention or the location where he is being held. The uncertainty on these fundamental points prevents reading the move as a classic "defection" or as pure coercion.

Internal Dispute and Investigative Pressure

ShinyHunters is not a traditional hierarchical organization. It is rather a commercial brand and a business model: initial access via social engineering, amplification through insider recruitment, monetization under a recognizable name on the black market for data.

This modular structure has made the group resilient but also vulnerable to internal fractures. Krebs documented the 2025 dispute between Khader and van der Stap over control of the ShinyHunters brand and data. When the Dutchman was arrested in Amsterdam on September 15, 2026, the chain of command shrank.

The FBI seized the timing. On October 5, a spokesperson told The Register: "Having already worked with partners to arrest multiple subjects... we will spare no resources in bringing each of those responsible to justice." The phrase was repeated nearly identically to Recorded Future News, suggesting a deliberate communications calibration.

"Arrests have the power to change who is willing to talk, and seized infrastructure has a way of showing us who is left" — Brett Leatherman, Assistant Director of the FBI Cyber Division

The FBI Breach and Operational Context

In the context of ShinyHunters' claim of a breach of FBI recruitment portals, the group declared the theft of 2–3 terabytes of data. The dossier does not establish a documented direct link between Khader and the Oracle PeopleSoft intrusion. The FBI has neither publicly confirmed nor denied the extent of the breach.

The group's infrastructure was taken offline, then reactivated on Telegram. BleepingComputer, which had direct contact with ShinyHunters, explicitly stated it could not verify whether the shutdown was caused by Khader's detention or other law enforcement actions. The temporal correlation exists; causation is not proven.

What Changes

Khader's detention does not end ShinyHunters' operations. The group has already demonstrated reconstitution capability: new leak site, Telegram presence, replicable business model. The source does not specify whether other arrests directly resulted from Khader's cooperation.

The case raises structural questions about the prosecutability of minor cybercriminals. Khader was 15 at the time of Krebs' identification; his current age is not officially confirmed. The 1995 extradition treaty, considered invalid by the Jordanian Supreme Court, and the constitutional ban on extraditing Jordanian citizens complicate any prospect of a U.S. trial.

Source Limitations and Information Chain

The primary structured source for this piece is the Reuters investigation, based on anonymous FBI sources. The other cited sources — The Hacker News, BleepingComputer, Help Net Security, SecurityWeek, BankInfoSecurity, The Register, KrebsOnSecurity — converge on the core facts of the detention and cooperation, but many derive from the same Reuters information base. KrebsOnSecurity provides independent historical context on Khader's identity and group dynamics, dated November 2025.

The exact circumstances of the detention, the place of detention, current legal status, and extradition prospects remain unclear. The FBI has not publicly confirmed details of Khader's cooperation. The dossier does not establish a documented direct link between Khader and the Oracle PeopleSoft breach.

Information is based on a primary structured source (Reuters) with convergence of secondary sources. Limits of independent verifiability are declared where relevant.

Information has been verified against cited sources and updated at time of publication.

Sources


Sources and references
  1. therecord.media
  2. thehackernews.com
  3. helpnetsecurity.com
  4. bleepingcomputer.com
  5. securityweek.com
  6. bankinfosecurity.com
  7. theregister.com
  8. krebsonsecurity.com