Full Report
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]
Analysis Summary
# Threat Actor: Rey (Saif al-Din Khader)
## Attribution & Identity
* **Real Name:** Saif al-Din Khader.
* **Online Alias:** Rey.
* **Associated Groups:**
* **ShinyHunters:** Core member/affiliate of the prominent extortion group.
* **Scattered Lapsus$ Hunters:** Identified as an administrator for this group (a 2025 entity claiming to comprise former members of Lapsus$, Scattered Spider, and ShinyHunters).
* **HellCat:** Former member; conducted independent operations under this banner.
* **Status:** Reported detained in Jordan (October 2026) and currently cooperating with the FBI/international law enforcement.
## Activity Summary
Khader has been linked to several high-profile cyber-extortion campaigns between 2024 and 2026:
* **FBI Breach (Sept 2026):** Alleged involvement in breaching FBI-managed AWS GovCloud systems via an Oracle PeopleSoft zero-day.
* **Orange Group Breach:** Independent operation involving the leak of 6.5GB of corporate data.
* **Jaguar Land Rover (2025):** Multiple breaches, including a March 2025 data leak and a September 2025 attack that caused $220 million in losses and halted production.
* **Cloud SaaS Campaigns:** Linked to ShinyHunters' targeting of Salesforce environments involving victims like Google, Cisco, and Qantas.
## Tactics, Techniques & Procedures
* **Exploitation:** Utilization of zero-day vulnerabilities (e.g., Oracle PeopleSoft) for initial access.
* **Lateral Movement:** Moving from compromised on-premises or third-party applications into cloud environments (AWS GovCloud).
* **Data Exfiltration:** Stealing large volumes (terabytes) of sensitive data, including PII, medical records, source code, and internal logs.
* **Extortion:** Threatening to leak stolen data on dedicated leak sites (DLS) or Telegram to compel ransom payments.
* **Supply Chain/Third-Party Targeting:** Breaching third-party integration companies to reach primary targets (e.g., Salesforce-linked attacks).
* **Communication:** Active use of Telegram for coordination and Signal for encrypted communication.
## Targeting
* **Sectors:** Government (FBI), Telecommunications (Orange), Automotive (Jaguar Land Rover), Technology (Google, Cisco), and Cloud SaaS providers.
* **Geography:** Global (operations spanning Jordan, Netherlands, USA, and Europe).
* **Victims:** FBI, Jaguar Land Rover, Orange Group, Qantas, Allianz Life, LVMH, Google, Cisco, PornHub, and Clop ransomware gang (data leak site hijack).
## Tools & Infrastructure
* **Infrastructure:**
* ShinyHunters Data Leak Site (onion-based).
* Telegram channels (Scattered Lapsus$ Hunters).
* AWS GovCloud (Targeted infrastructure).
* **Information Gathering:** Usage of infostealer logs to identify targets or manage credentials.
## Implications
* **Law Enforcement Breakthrough:** Khader’s cooperation represents a significant intelligence windfall for the FBI, potentially leading to the de-anonymization of other high-level threat actors in the Lapsus$/Scattered Spider ecosystem.
* **Group Volatility:** The detention caused immediate disruption, including the temporary shutdown of the ShinyHunters leak site and affiliate communication channels, though the group appears resilient enough to launch new infrastructure.
* **Increased Risk to Cloud Environments:** The actor's success in pivoting from software vulnerabilities to AWS GovCloud highlights critical risks for organizations relying on "secure" cloud instances.
## Mitigations
* **Zero-Day Management:** Prioritize patching for enterprise software like Oracle PeopleSoft and Salesforce integrations.
* **Cloud Security Hardening:** Implement strict IAM policies and monitoring for lateral movement between third-party SaaS tools and core cloud infrastructure (AWS/Azure).
* **Data Loss Prevention (DLP):** Deploy robust DLP tools to detect the exfiltration of large datasets (TB-scale) to unauthorized external IPs.
* **Supply Chain Audits:** Review permissions granted to third-party integrations and service accounts to minimize the blast radius of a credential compromise.