Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement
The FBI reportedly has detained a second person connected to its investigation into a recent data breach involving information from the law enforcement agency.
Multiple FBI sources told Reuters on Saturday that Saif al-Din Khader was arrested in Jordan on September 28.
Khader, according to Reuters, is now cooperating with the FBI and other law enforcement agencies to help locate other members of ShinyHunters — a cybercriminal group responsible for several high-profile incidents including the FBI breach.
The FBI declined to comment on Khader’s alleged arrest, only telling Recorded Future News that it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters.
“Having already worked with partners to arrest multiple subjects … we will spare no resource in bringing each of the responsible individuals to justice,” a spokesperson said.
Khader was identified last November by cybersecurity journalist Brian Krebs as a key figure within ShinyHunters. Krebs traced the username “Rey” and several hacker profiles back to Khader, whom he revealed was a 16-year-old living in Amman, Jordan.
Krebs contacted Khader’s father, which prompted a direct message from the teenager, who claimed he had already been in contact with European law enforcement agencies.
The FBI did not say where Khader is being held or whether he will be extradited. His arrest follows the detention of another alleged ShinyHunter member last week. Khader reportedly was responsible for dozens of significant incidents involving both European and American companies.
On September 29, the FBI and the Dutch National Police announced the arrest of Pepijn van der Stap — a well-known cybercriminal who was released this year after serving years in prison on a previous hacking conviction.
Krebs reported that van der Stap was a key figure in ShinyHunters and was allegedly locked in a power struggle with Khader for control of the cybercriminal operation.
Reappearing on Telegram
The ShinyHunters leak site was taken down last week, allegedly by law enforcement agencies. But the group resurfaced on Telegram on Monday, claiming it was restarting a long-defunct cybercriminal forum as a replacement for its leak site.
ShinyHunters has claimed dozens of high-profile data thefts in recent months and has been in the crosshairs of the FBI for nearly a year after dozens of attacks on large companies like Ticketmaster and AT&T as well as educational publisher McGraw Hill, Carnival Cruise Line, 7-Eleven and other companies.
The group even targeted another Russian cybercriminal operation before launching its attack on the FBI.
The FBI incident stirred anxiety within the agency, exposing the names, home addresses, cell phone numbers, Social Security numbers, FBI email addresses, employee ID numbers and much more of nearly every FBI agent.
The breach also exposed thousands of records about local police officers who work with the FBI on task forces. The bureau sent an internal memo last week to employees warning them of the breach and the potential danger to them and their families.
ShinyHunters told several news outlets in messages that it would not release the stolen information and did not want to escalate their feud with the FBI — which they said started because of an advisory about their actions that they disagreed with.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



