Jordan Confirms Arrest of Suspected ShinyHunters Member as FBI Investigation Expands

Jordan has confirmed the arrest of a suspected ShinyHunters member amid reports that alleged hacker Saif al-Din Khader is cooperating with the FBI and helping investigators identify other members of the group.
FBI seal centered over the Amman, Jordan skyline at night.

Jordan has confirmed the arrest of a suspected member of ShinyHunters as the international investigation into the hacking and extortion group expands following its high-profile breach of FBI systems.

A Jordanian official confirmed that authorities arrested a suspect last week and are continuing to investigate the individual in connection with ShinyHunters and other groups associated with it.

Jordanian authorities have not publicly identified the person in custody. However, Reuters, citing three people familiar with the matter, identified the suspect as Saif al-Din Khader, an alleged ShinyHunters member known online as “Rey.”

Two sources told Reuters that Khader is cooperating with the FBI and other law enforcement agencies and providing information that could help investigators identify additional hackers associated with the group.

The reported cooperation comes amid mounting international law enforcement pressure on ShinyHunters, including a separate arrest in the Netherlands and an unusually direct public warning from the FBI to remaining members of the operation.

Suspected ShinyHunters member reportedly cooperating with FBI

Reuters first reported that Jordanian authorities had detained Khader, with sources familiar with the investigation saying he was taken into custody in Jordan.

One source told Reuters that the suspect was walking investigators through electronic devices and digital communications as authorities attempt to identify other alleged participants in the hacking operation.

The FBI has not publicly confirmed Khader’s identity, his alleged role within ShinyHunters or his reported cooperation with investigators.

However, the bureau told Reuters that it continues to aggressively investigate the recent cyber incident involving ShinyHunters and is working with international partners to identify and apprehend people allegedly involved with the group.

Jordan’s subsequent acknowledgment provides official confirmation that an arrest occurred, although it does not independently establish that the detainee is Khader or confirm the reported cooperation with U.S. investigators.

Arrest follows ShinyHunters breach of FBI recruitment systems

The arrest comes shortly after ShinyHunters claimed responsibility for one of its most consequential intrusions to date: a compromise involving FBI recruitment infrastructure and sensitive personnel information.

As BreachNews previously reported, the FBI began investigating unauthorized activity affecting FBIJobs.gov after ShinyHunters claimed it compromised the recruitment system through vulnerabilities affecting Oracle PeopleSoft.

The group claimed it obtained between 2TB and 3TB of data covering current and former FBI personnel, job applicants and internal records. ShinyHunters also claimed it moved beyond the recruitment environment into additional FBI-managed infrastructure.

Those broader claims have not been fully verified, but subsequent reporting provided significant corroboration that sensitive FBI personnel information was compromised.

A sample containing approximately 5,000 purported employee records was distributed to journalists, with independent reporting verifying information associated with multiple FBI personnel. The material reportedly included Social Security numbers, home addresses, employment information and records identifying personnel involved in sensitive intelligence and counterintelligence work.

Additional reporting examined purported medical and psychiatric information belonging to FBI personnel, with portions of the material independently authenticated.

BreachNews later reported that FBI employees were internally warned about the exposure of personnel information as the bureau continued investigating the scope of the incident.

The complete size of the stolen dataset and the full extent of ShinyHunters’ access remain unresolved.

FBI publicly warned remaining ShinyHunters members

The reported detention in Jordan comes as the FBI has adopted an increasingly public posture toward people it believes are associated with ShinyHunters.

FBI Cyber Division Assistant Director Brett Leatherman recently issued a direct message to remaining members of the group, urging them to contact authorities and warning that investigators continue to gather information about their identities and activities.

“The longer you stay in this, the more we learn about you,” Leatherman said. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”

As BreachNews reported following the FBI warning, the bureau says ShinyHunters and alleged co-conspirators have compromised more than 140 organizations since 2025 and received at least $70 million through extortion.

The FBI’s message followed another major development in Europe.

Dutch police arrested 24-year-old Pepijn van der Stap in Amsterdam on Sept. 15 as part of an investigation into ShinyHunters. Dutch authorities seized data storage devices during the operation and said additional arrests remained possible.

The FBI subsequently described Van der Stap as one of the alleged leaders of ShinyHunters. ShinyHunters has reportedly denied that he is associated with the group, and Dutch authorities have not publicly tied him to the FBIJobs.gov intrusion.

ShinyHunters activity continued despite law enforcement pressure

The arrests have not resulted in the immediate disappearance of infrastructure and activity attributed to ShinyHunters.

The group’s leak site temporarily went offline around the time its self-imposed deadline for the FBI to correct or remove disputed information expired, initially raising questions about whether law enforcement action may have been responsible.

ShinyHunters subsequently resurfaced on replacement infrastructure.

As BreachNews reported on Oct. 1, a replacement ShinyHunters leak site appeared with new extortion claims involving O’Reilly Automotive and Dexcom.

The group attributed the earlier outage to infrastructure problems and distributed denial-of-service attacks rather than a law enforcement takedown. That explanation has not been independently verified, but the appearance of replacement infrastructure demonstrates that at least part of the operation remained active.

The continued activity also underscores the decentralized nature of modern cybercrime groups, where arrests of individual participants do not necessarily dismantle the broader operation.

ShinyHunters reportedly says it is backing down

Despite the appearance of replacement infrastructure, communications attributed to ShinyHunters suggest the group may be attempting to de-escalate its confrontation with the FBI.

Reuters reported that ShinyHunters recently said it wanted no further escalation and indicated that its message could be interpreted as the group “backing down completely.”

The change in tone follows weeks of increasingly public confrontation between ShinyHunters and the bureau.

The group previously described its FBI intrusion as retaliation for an FBI warning that it said inaccurately characterized its activities. ShinyHunters demanded that the bureau correct or remove information it disputed and initially left open the question of what would happen if the FBI refused.

ShinyHunters later said it never intended to publicly release the FBI dataset and characterized the operation as a publicity effort rather than an attempt to extort the U.S. government.

Those statements cannot be independently verified. Portions of the allegedly stolen FBI information have already been distributed to journalists and other third parties, meaning the potential exposure does not depend solely on whether ShinyHunters publicly releases the broader dataset.

PeopleSoft attack claims remain partly unresolved

Major technical questions surrounding the FBI intrusion also remain unanswered.

ShinyHunters has attributed its initial access to vulnerabilities affecting Oracle PeopleSoft, technology used within the FBI recruitment environment.

The group had already demonstrated an ability to exploit PeopleSoft vulnerabilities before the FBI incident. In June, BreachNews reported on ShinyHunters-linked exploitation of an Oracle PeopleSoft zero-day affecting organizations including universities.

The campaign was later associated with CVE-2026-35273, a critical vulnerability affecting Oracle PeopleSoft.

One confirmed victim was the National Association of Insurance Commissioners. NAIC confirmed a cyberattack linked to exploitation of the PeopleSoft vulnerability as organizations investigated the broader campaign.

Google Threat Intelligence Group and Mandiant subsequently documented renewed ShinyHunters exploitation of CVE-2026-35273, including techniques designed to bypass web application firewall mitigations protecting vulnerable PeopleSoft Environment Management Hub endpoints.

ShinyHunters has claimed that techniques involving the known vulnerability were used against FBIJobs.gov while also alleging that it discovered and exploited another previously unknown vulnerability affecting the same PeopleSoft component.

The alleged additional vulnerability remains unverified.

Oracle, CISA and the FBI have not publicly confirmed a second PeopleSoft zero-day corresponding to ShinyHunters’ claim, and no separate CVE has been assigned to the purported flaw.

International investigation into ShinyHunters expands

The arrest in Jordan adds another front to an increasingly international investigation into ShinyHunters and people allegedly associated with the group.

The reported cooperation could prove particularly significant if investigators gain access to communications, devices or accounts capable of identifying other participants or linking individuals to specific intrusions.

At the same time, the continued appearance of ShinyHunters-branded infrastructure and breach claims illustrates the difficulty of determining how much of the operation has actually been disrupted.

ShinyHunters has been linked to an extensive series of data theft and extortion incidents throughout 2026. BreachNews has tracked the group’s activity across numerous organizations, including healthcare companies, technology providers, educational institutions and major corporations.

The group’s recent activity has included the claimed breach of Fresenius Medical Care and an unusual incident in which ShinyHunters claimed it compromised the leak site operated by the Cl0p ransomware group.

Jordanian authorities said their investigation into the arrested suspect, ShinyHunters and groups connected to it remains ongoing.

Neither Khader’s alleged membership in ShinyHunters nor his involvement in the FBI intrusion has been established in court. The claim that he is cooperating with investigators is based on Reuters’ reporting from sources familiar with the investigation and has not been publicly confirmed by the FBI or Jordanian authorities.

BreachNews will continue monitoring the international investigation, additional arrests, developments surrounding the FBI breach and any technical confirmation of ShinyHunters’ claimed additional Oracle PeopleSoft vulnerability.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →