Jordan is holding a suspected member of the extortion group ShinyHunters, SecurityWeek reported on 5 October 2026. Sources told Reuters the man is Saif al-Din Khader, known online as Rey, and that he is helping investigators identify other members. Jordan has confirmed a detention. It has not publicly named the suspect.
What happened
Reuters, cited by SecurityWeek, CBS News, and Help Net Security, reported that Jordanian authorities detained Khader last week. Two of three Reuters sources placed the arrest on Tuesday 29 September. One source said he has walked investigators through his devices and messages. The FBI declined to confirm this specific arrest. It said it has already worked with partners to arrest multiple subjects in the ShinyHunters investigation and that more leads are active.
The detention follows the group's claim that it defaced the FBI jobs site and stole 2 to 3 terabytes tied to FBI personnel, including a sample list of 5,000 employees sent to media. Those theft claims are not independently verified in the reporting used here. Security researcher Kevin Beaumont wrote that Rey was also linked to the Jaguar Land Rover intrusion. A separate suspect was arrested in the Netherlands as part of the wider case.
Who is affected
This is a law-enforcement development, not a new patch. The practical exposure is anyone whose data already sits in a ShinyHunters or Scattered LAPSUS$ Hunters haul: SaaS tenants, stolen SSO sessions, and employee lists used for follow-on extortion. Cooperation with investigators can also mean the group burns infrastructure and switches channels quickly.
What to do now
- Re-check identity providers for session theft: conditional access, token replay, and impossible-travel on admin accounts.
- Warn finance and HR that extortion mail using real employee names is a current pattern, not a generic phish.
- If a client was named in a prior ShinyHunters or Salesforce-integration theft, confirm the stolen-data playbook is still open.
- Do not treat an arrest as the end of the campaign. Affiliates keep operating.
Source: SecurityWeek, 5 October 2026, citing Reuters. Read the report.
Also on the blog
- Denmark CPR breach: 8.8 million identity records
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Zammad CVE-2026-102489: KEV due date is today
- CVE-2026-61500: Rejetto HFS admin session forgery
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.