Saif al-Din Khader, a hacker known online as “Rey” and also reported to have used the alias “ReyXBF”, was detained by Jordanian authorities on September 29, according to several reports, and is now said to be helping investigators identify other people associated with ShinyHunters.

Khader, however, says his cooperation with law enforcement began long before his detention.

Cybersecurity journalist Brian Krebs identified Khader as Rey in November 2025 after tracing online accounts, infostealer data and other digital evidence. Khader subsequently contacted Krebs over Signal and said he had been speaking with law enforcement since at least June 2025 and had “told them nearly everything”.

Krebs could not independently verify the claim at the time. Khader showed him evidence suggesting he had contacted Europol, but could not name any law-enforcement officials he said were responding to him.

Nearly a year later, parts of that account have acquired new significance. Reuters, citing three people familiar with the matter, identified Khader as the person detained in Jordan. Two sources said he is helping the FBI and international law enforcement locate other people associated with ShinyHunters. One said investigators are being walked through his electronic devices and digital correspondence.

CBS News has since separately reported Khader’s detention and cooperation, citing two US officials and another source with knowledge of the case.

Jordan has also confirmed the arrest of a suspected ShinyHunters member, although authorities in the kingdom have not publicly identified the detainee as Khader. Jordanian state media quoted an official saying investigations were continuing into “the activities of the group and the groups it is connected with”.

The FBI has declined to discuss Khader’s detention specifically. It has said, however, that it has worked with international partners to arrest multiple subjects while continuing to investigate the recent incident attributed to ShinyHunters.

The emerging picture is more complicated than that of a hacker being arrested and deciding afterwards to cooperate. If Khader was telling Krebs the truth in 2025, investigators may already have been receiving information from him for more than a year before he was placed in custody.

What his detention has added remains unclear. Access to his current devices and communications could provide investigators with material that was not available through earlier conversations, but there is no public account of what Khader previously supplied or what investigators already knew.

Krebs reported that Rey was one of only three administrators of the Telegram channel operated by Scattered LAPSUS$ Hunters, usually shortened to SLSH. He had previously administered the leak site used by the Hellcat ransomware operation and in 2024 became an administrator of an incarnation of BreachForums, an English-language forum repeatedly used to trade and publish stolen data.

BreachForums is a platform rather than a hacking group, while Hellcat, ShinyHunters, Scattered Spider and LAPSUS$ have different histories, participants and operations.

Scattered LAPSUS$ Hunters emerged publicly in 2025 and was described by Krebs as an apparent amalgamation of operators associated with Scattered Spider, LAPSUS$ and ShinyHunters. Its activities included leak channels, extortion and a ransomware offering called ShinySp1d3r. The shared branding did not necessarily mean that every person operating under one name belonged to all of the others.

Research published on October 1 by Sekoia and Beazley Security describes a similarly fluid structure around ShinyHunters itself.

The researchers concluded that modern ShinyHunters spans multiple distinct threat clusters operating under one shared name and is better understood as a data-theft and extortion brand than as a conventional organisation with fixed membership. They assess with high confidence that it is connected to the broader online ecosystem known as The Com.

The FBI uses “The Com”, short for “The Community”, to describe a primarily English-speaking international online ecosystem made up of interconnected networks. It says members may participate across different subsets and relationships can overlap as groups form, split and regroup.

Sekoia says a similar division can exist within ShinyHunters operations. The people who first gain access to a company are not necessarily the same people who later advertise its data or conduct extortion under the ShinyHunters identity.

The 2024 Snowflake campaign provides one example. Sekoia says the underlying intrusions were tracked separately by Mandiant as UNC5537, while ShinyHunters increasingly functioned as a brand, data broker and public extortion voice around the stolen information.

Dutch police arrested a 24-year-old Amsterdam man on September 15 on suspicion of playing a role within ShinyHunters and participating in a criminal organisation. Reuters identified him through his employer as Pepijn van der Stap. The FBI later described him as one of the group’s alleged leaders, while people speaking under the ShinyHunters name denied that he had any connection to them.

Activity under the name continued.

In the following days, ShinyHunters compromised and defaced infrastructure belonging to Cl0p, claimed an intrusion into FBI-related systems and continued activity connected with attacks against Oracle PeopleSoft. The developments formed the basis of TheZeal’s earlier reports Hackers Hacking Hackers, ShinyHunters Targets the FBI, ShinyHunters Expands Oracle PeopleSoft Attacks and Is the FBI Bluffing ShinyHunters?.

The confrontation with the FBI became unusually public.

ShinyHunters challenged a May FBI report describing the group’s activities, disputed several allegations and gave the bureau a week to correct or remove the document. Asked by BleepingComputer whether attacking the FBI might intensify efforts by the United States government to identify those involved, a representative replied: “I don’t care.”

FBI Cyber Division Assistant Director Brett Leatherman responded publicly on September 29 with a message of his own: “You know how to find us, and we know how to find you.”

Two Reuters sources say Khader was detained that same day.

The following day, the ShinyHunters dark web leak site disappeared. The timing immediately invited questions about whether the outage was connected to law-enforcement activity, but there was no evidence establishing that connection.

ShinyHunters later told Cybernews that it had taken the site offline for infrastructure upgrades following DDoS attacks by rivals and hardware problems, while supporting data centres had suffered disruption from an unrelated incident.

The group subsequently resurfaced at a new onion address, which Cybernews confirmed was operational.

On October 1, the replacement site listed O’Reilly Automotive and medical-device company Dexcom as alleged new victims and threatened to publish purported corporate data if the companies did not respond. Cybernews reported that neither listing contained proof samples, and neither alleged breach had been independently established at the time.

In its most recent exchange with Reuters, operators using a ShinyHunters-linked email address said they wanted “no further escalation” with the bureau. They told Reuters the message could be interpreted as “ShinyHunters backing down completely”.

The statement was notably different from the defiant language used only days earlier, but it was not an announcement that ShinyHunters had ceased operating. The replacement leak site and subsequent victim claims showed continued activity under the name.

The sequence adds another layer to the question raised by TheZeal in Is the FBI Bluffing ShinyHunters?.

The chronology does not show that the FBI’s public warning produced Khader’s detention. Two Reuters sources place him in custody on September 29, the same day Leatherman’s warning was published, while the Dutch arrest had occurred two weeks earlier. What has become clearer is that the public exchange was taking place against the background of an international investigation already reaching people associated with the wider ShinyHunters ecosystem.

If Khader’s account to Krebs was accurate, he had been communicating with law enforcement since at least June 2025 and believed he had already told investigators almost everything he knew. If those claims overstated the extent of his earlier cooperation, the access investigators reportedly have to him now could represent something quite different.

There is no public record showing what Khader has provided, what investigators have found on his devices or how much of that information was already known. Nor is it clear who currently controls the ShinyHunters identity. Research describing it as multiple overlapping clusters operating under a common name makes that considerably less straightforward than identifying a single leader or membership list.

For now, Khader is reportedly in custody and cooperating, ShinyHunters has stepped back from its confrontation with the FBI, and the ShinyHunters name continues to appear online.

Update: The Record reported on October 5 that ShinyHunters had resurfaced on Telegram and was claiming it would restart BreachForums as a replacement for its leak site. The report linked to a Telegram channel associated with the BreachForums name, but TheZeal has not independently authenticated who controls the channel or the statement attributed to ShinyHunters.

The claim conflicts with a previous statement attributed to ShinyHunters after US and French authorities seized BreachForums infrastructure in October 2025. BleepingComputer verified that earlier message using ShinyHunters’ PGP key. In it, the group said “the era of forums is over” and stated that it would not launch another BreachForums.

There is currently no evidence in the reporting that a new BreachForums is operational. For now, the reported relaunch remains a claim attributed to ShinyHunters rather than a confirmed return of the forum.