Updated:
A suspected member of the ShinyHunters hacking group was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. The suspect, Saif al-Din Khader, is alleged to have used the online name “Rey”; two sources said he was taken into custody on Tuesday, September 29.
The sources said Khader is helping U.S. and international investigators identify and locate other alleged members of the group. Reuters could not establish the circumstances of his detention or where he is being held, and attempts to reach Khader and his family were unsuccessful. The FBI did not comment on the specific detention.
The case has drawn heightened attention after ShinyHunters claimed it had obtained data on FBI employees and applicants. The bureau has acknowledged an incident involving its jobs portal but said the source of the breach and the alleged data exposure were still under investigation; the full scope of any material taken has not been publicly confirmed.
FBI says investigation is continuing
In a statement, the FBI said it was aggressively investigating the cyber incident allegedly involving ShinyHunters and had already worked with partners to arrest multiple suspects. The bureau said it would devote resources to bringing those responsible to justice, without identifying any particular arrest or activity in Jordan.
One source told Reuters that Khader was walking investigators through his electronic devices and digital correspondence to help them find other alleged participants. The source described the cooperation as important to efforts to make further arrests. That account has not been publicly detailed by the FBI, and the sources did not say whether Khader faces charges in Jordan or whether any transfer to another jurisdiction is planned.
Jordanian authorities have not publicly released the suspect’s name in the reporting available. A Jordanian official, quoted by state media, said investigations were under way into the suspect’s activities and connected groups, according to contemporaneous reporting. The public record does not yet establish what legal process will follow or when authorities may provide more information.
What is known about the alleged FBI incident
On September 23, the FBI said a cybercriminal group was claiming to have compromised the FBIJobs.gov portal and affected employee personally identifiable information. The bureau said it had not determined whether the point of entry was a third-party provider or the FBI’s own enterprise, and said it was working with providers supporting the portal to mitigate risks.
ShinyHunters later asserted that it had taken data relating to nearly all FBI employees and job applicants. Those claims remain distinct from what the government has confirmed. Reuters reported that its analysis of a sample supplied by the group found personal information about FBI staff, details about job roles, and psychiatric and medical information; the sample does not, by itself, establish the total volume or completeness of the alleged theft.
The claims have raised concerns because information about law-enforcement personnel can expose individuals and their families to privacy and security risks. Reuters compared the alleged theft with the 2015 breach of the U.S. Office of Personnel Management, which compromised records on millions of people vetted for security clearances. The cases differ, and the available reporting does not establish that the ShinyHunters incident involved comparable numbers or categories of records.
Group’s online presence appears disrupted
Reuters reported that it could no longer reach ShinyHunters through an online account the group had previously used to communicate with journalists, and that the group’s dark-web site disappeared after the FBI incident. The outlet said the site had hosted threats directed at the bureau. The apparent disruption does not establish that the group has ceased operating or that investigators have recovered the alleged data.
The group had said its September action was retaliation for an FBI advisory that it objected to. In a later communication to Reuters, people operating an email address linked to ShinyHunters said they wanted no further escalation and suggested their position could be read as backing down. The group’s claims and statements have not been independently verified, and its operators did not respond to Reuters’ latest request for comment.
Detention follows a separate arrest in the Netherlands
Khader’s detention follows the arrest in the Netherlands of another suspected ShinyHunters member, Pepijn van der Stap. Dutch police confirmed that a 24-year-old man from Amsterdam was arrested in September in an investigation into the group; U.S. and Dutch authorities have not publicly confirmed the suspect’s identity in their statements, though news organizations have identified him as van der Stap.
FBI Director Kash Patel said on social media after that arrest that investigators were pursuing new leads and that further arrests were possible. The Jordan detention adds a second reported international law-enforcement action in the probe, but authorities have not publicly described the cases’ relationship or said whether the suspects are accused of the same acts.
Questions remain about custody and alleged stolen data
Khader’s alleged role and cooperation are based on accounts from people familiar with the matter, not a public court filing or detailed FBI announcement. His detention does not establish guilt, and the available information does not specify any charges, hearing dates, or extradition proceedings. Those details, along with the ultimate disposition of the case, remain unknown.
Investigators also have not publicly resolved how the FBIJobs.gov portal was accessed, how much information was taken, or whether the group still controls copies. The FBI has said it is investigating the incident and working with relevant third parties; no further public timetable for findings or a case update has been announced.







