Full Report
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and
Analysis Summary
# Threat Actor: Saif al-Din Khader (Alias: Rey)
## Attribution & Identity
* **Real Name:** Saif al-Din Khader
* **Primary Aliases:** Rey, ReyXBF
* **Known Associations:**
* **ShinyHunters:** Suspected core member/extortionist.
* **Scattered LAPSUS$ Hunters (SLH/SLSH):** Identified as one of three administrators; this group is an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters.
* **Hellcat:** Former administrator of the ransomware group’s data leak website (late 2024).
* **BreachForums:** Administrator of the most recent incarnation (2024).
* **The Com:** Law enforcement alleges links to this violent cybercrime collective, though the actor disputes this.
## Activity Summary
Khader was reportedly detained by Jordanian authorities on September 29, 2026, and is currently cooperating with the FBI. His group, ShinyHunters, has recently engaged in high-profile operations including:
* **FBI Breach (2026):** Hacking the "apply.fbijobs[.]gov" portal and stealing ~3TB of data to pressure the agency into retracting allegations.
* **Inter-Group Hijacking (2026):** Taking over the darknet website of the rival Cl0p ransomware gang.
* **Mass Extortion:** Involvement in breaching over 140 organizations since 2025, resulting in at least $70 million in extortion payments.
## Tactics, Techniques & Procedures
* **Social Engineering:** Advanced manipulation to gain initial access.
* **SIM Swapping:** Used to bypass multi-factor authentication (MFA).
* **Cloud Targeting:** Specifically targeting third-party vendors within cloud-based platforms to access downstream client data.
* **Vulnerability Exploitation:** Exploiting unpatched flaws in web software (e.g., Grav CMS).
* **Data Extortion:** Stealing sensitive data and threatening public release to compel payment.
* **Swatting & Physical Violence:** Associated with "The Com," involving physical intimidation and law enforcement harassment.
## Targeting
* **Sectors:** Third-party cloud service providers, Government (FBI), Cybersecurity/Technology, and rival cybercriminal infrastructure.
* **Geography:** Global; specifically US government entities and international enterprises.
* **Victims:** FBI (apply.fbijobs[.]gov), Cl0p (rival gang), and over 140 unidentified organizations.
## Tools & Infrastructure
* **Malware/Software:** Grav CMS (exploited for site takeovers).
* **Infrastructure:**
* apply.fbijobs[.]gov (Breached target)
* BreachForums (Administrative role)
* Hellcat leak site (Administrative role)
## Implications
The detention of "Rey" represents a significant intelligence win for Western law enforcement. As a high-level administrator across multiple major threat groups (ShinyHunters, SLSH, BreachForums), his cooperation likely provides the FBI with direct attribution for numerous unidentified members. This signals a breakdown in the perceived anonymity of "The Com" and its affiliates, potentially leading to a series of cascading arrests within the ecosystem.
## Mitigations
* **Supply Chain Security:** Implement rigorous auditing of third-party cloud vendors and limit their access to the principle of least privilege.
* **MFA Hardening:** Shift away from SMS-based MFA to hardware security keys (FIDO2) to defend against SIM swapping and sophisticated social engineering.
* **Vulnerability Management:** Prioritize patching for public-facing web applications and Content Management Systems (CMS).
* **Identity Governance:** Deploy runtime identity controls to monitor for anomalous access patterns that suggest a compromised credential or session hijacking.