FBI confirms 'multiple' arrests related to ShinyHunters hack
FBI says multiple suspects were arrested in the ShinyHunters investigation, with reported detentions in Jordan and the Netherlands.
The FBI told The Register that partners have arrested multiple suspects in an investigation into a September incident allegedly involving the ShinyHunters data-theft and extortion group. Reports say Saif al-Din Khader, alias Rey, was detained in Jordan on September 29 and is cooperating; he has been described as a technical operator of Scattered LAPSUS$ Hunters, previously linked to the late-August 2025 Jaguar Land Rover breach that halted manufacturing and exposed employee payroll data. Dutch police earlier arrested a 24-year-old alleged leader identified in reports as Pepijn van der Stap. ShinyHunters also claimed a late-September intrusion into FBIJobs.gov and said that break-in was not financially motivated.
- FBI confirms multiple arrests in the ShinyHunters investigation.
- Saif al-Din Khader, alias Rey, was reportedly detained in Jordan on September 29.
- Dutch police arrested alleged leader Pepijn van der Stap, age 24.
- The group was linked to Jaguar Land Rover and claimed an FBIJobs.gov intrusion.
Full article618 words · extracted from theregister.com · click to collapse
REG AD
security
Another few bite the dust
The FBI and law enforcement partners have arrested “multiple” suspects as part of an investigation into a September hack allegedly involving data-theft-and-extortion group ShinyHunters, the bureau told The Register.
“The bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice,” an FBI spokesperson told us in an email on Monday.
The FBI declined to comment on the specific arrests, including that of Saif al-Din Khader, a suspected ShinyHunters member who has reportedly been detained in Jordan, according to Reuters.
REG AD
Khader, who goes by the alias Rey, was reportedly brought into custody on September 29, and is said to be cooperating with the FBI to identify other members of the group.
REG AD
ShinyHunters did not respond to The Register’s inquiries about the arrest and Khader’s alleged involvement with the criminal group.
Rey confirmed his real identity - Khader - to security journalist Brian Krebs last year. Krebs described Khader as the “technical operator and public face” of Scattered LAPSUS$ Hunters.
“Rey got picked up finally,” said security sleuth Kevin Beaumont following news of the arrest. According to Beaumont, Rey was “one of the kids who got into JLR.”
The Jaguar Land Rover (JLR) breach, which occurred in late August 2025, affected the company's IT systems and halted manufacturing operations. Dealer systems also went down, and suppliers faced canceled or delayed orders.
In addition to crippling the carmaker’s business operations for months, the digital thieves stole personal payroll data belonging to thousands of JLR employees.
The cyberattack, one of the most costly in UK history, was attributed to Scattered LAPSUS$ Hunters.
Khader’s detention came two weeks after the Dutch National Police arrested a 24-year-old whom the FBI described as “one of the alleged leaders of ShinyHunters.”
While Dutch cops have not named the suspect, Krebs and other reports say he is Pepijn van der Stap, who was convicted in 2023 for hacking and extorting numerous organizations and was on supervised release after three years in prison.
REG AD
Van der Stap also worked as a software engineer at the Amsterdam-based cybersecurity startup Hadrian and volunteered as a security researcher at the Dutch Institute for Vulnerability Disclosure (DIVD).
In a video message following the arrest, Brett Leatherman, assistant director of the FBI's Cyber Division, had some advice for the “remaining members” of the data theft and extortion gang.
“Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left,” Leatherman said last week. “The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
At the time, the FBI declined to answer The Register’s questions about the video message, including whether it had seized any of the cybercrime group’s infrastructure, and whether any of ShinyHunters’ members had taken Leatherman up on his offer to “reach out first.”
In late September, ShinyHunters hacked the FBIJobs.gov portal and claimed it stole sensitive personal details about current, former, and prospective FBI employees. A spokesperson told The Register that unlike most of its digital break-ins, this one was “NOT financially motivated … We want the FBI to correct or retract their statements they made, which included substantial false allegations.”
Later, in an exclusive interview, the spokesperson told us the attention-grabbing hack was “fundamentally a public relations and marketing initiative for our business.” ®