Three ShinyHunters Suspects in Custody as Alleged Leader 'Rey' Cooperates with FBI After FBIjobs.gov Breach
Alleged ShinyHunters leader Saif al-Din Khader ('Rey'), reportedly 16, was detained in Jordan and is cooperating with the FBI — the third arrest after the group exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to steal roughly 2-3 TB from FBIjobs.gov,…
Jordanian authorities detained Saif al-Din Khader, known as Rey or ReyXBF, a teenager from Amman whom Reuters reported to be 16 and in FBI custody; Reuters could not confirm the circumstances of the detention or where he is held. The arrest date is disputed: FBI sources cited by Reuters put it at September 28, 2026, while The Hacker News reported September 29. Khader is reportedly cooperating with the FBI to identify other members, walking investigators through his devices and communications. Brian Krebs described him as an administrator of Scattered LAPSUS$ Hunters — tying together Scattered Spider, LAPSUS$, and ShinyHunters — and of the Hellcat and BreachForums leak sites; Khader said he had assisted law enforcement since at least June 2025. He was detained while the group was extorting Jeppesen ForeFlight, a Boeing unit sold to Thoma Bravo for $10.55 billion in November 2025; Boeing says it is reviewing the data-theft claims. The arrests follow ShinyHunters' September breach and defacement of FBIjobs.gov, a third-party-managed platform. The group claimed it exploited an Oracle PeopleSoft zero-day, CVE-2026-35273 — mass-exploited since June against dozens of organizations — moved into AWS GovCloud, and stole 2-3 terabytes including Social Security numbers, medical records, home addresses, and phone numbers. The breach exposed names, SSNs, and employee IDs for nearly every FBI agent plus records on local task-force officers; an internal FBI memo assumed all employees were affected. The group sent media a sample list of 5,000 FBI employees, which Reuters reviewed, but said it would not publish the stolen files. The FBI blamed a contractor's failure to install an issued security patch; sources identified Oracle PeopleSoft and Accenture, which Accenture did not confirm. Two other suspects were arrested: Dutch police detained Pepijn van der Stap, a 24-year-old from Amsterdam also known as Umbreon, on September 15, 2026, for aiding the group's data thefts and extortions; he was due in Rotterdam District Court, though ShinyHunters denied he was connected to the group. In the week of October 9, the FBI arrested an unnamed Canadian citizen in Pennsylvania as a suspected primary co-conspirator in the jobs-portal hack; no name or charges have been made public, and Reuters counts this as the third public arrest since the breach. The FBI says ShinyHunters breached more than 140 organizations and collected at least $70 million in extortion payments — The Hacker…
- Saif al-Din Khader, alias Rey/ReyXBF, a teenager from Amman (Reuters reported he is 16), was detained in Jordan and is reportedly cooperating with the FBI to identify other ShinyHunters members.
- Arrest date differs by source: FBI sources cited by Reuters say September 28, 2026; The Hacker News reported September 29.
- Krebs described Khader as an administrator of Scattered LAPSUS$ Hunters (linking Scattered Spider, LAPSUS$, and ShinyHunters) and of the Hellcat and BreachForums leak sites; Khader said he had assisted law enforcement since at least June…
- At the time of his detention, ShinyHunters was extorting Jeppesen ForeFlight, a Boeing unit sold to Thoma Bravo for $10.55 billion in November 2025; Boeing is reviewing the claims.
- ShinyHunters defaced FBIjobs.gov and claimed to have stolen 2-3 TB of data, including SSNs, medical records, home addresses, and phone numbers, affecting nearly every FBI employee; an internal FBI memo assumed all employees were affected.
- The group sent media a sample list of 5,000 FBI employees (reviewed by Reuters) but said it would not publish the stolen files.
- The claimed intrusion vector was Oracle PeopleSoft zero-day CVE-2026-35273, mass-exploited since June against dozens of organizations, with the group saying it moved into AWS GovCloud.
- The FBI blamed a contractor's failure to install an issued security patch on a third-party-managed platform; sources identified Oracle PeopleSoft and Accenture, which Accenture did not confirm.
Coverage timelineoldest first · each row is one article
- · 6d agoShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
The Hacker News· 76
Jordan detained ShinyHunters suspect Rey, who is reportedly helping the FBI identify other members.
- · 6d agoShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group
Security Affairs· 76
Jordan detained suspected ShinyHunters member Saif al-Din Khader, who is reportedly cooperating with the FBI.
- · 5d agoAlleged ShinyHunters Leader Arrested in Jordan
SecurityWeek· 78
Vulnerabilities in this storyAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS |
|---|