CyberSecurityNews

ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers


A suspected ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group. Reuters reported on October 3 that three people familiar with the matter confirmed the detention of Saif al-Din Khader, whose alleged online nickname is Rey.

Two sources said Jordanian authorities took Khader into custody on Tuesday, September 29. They also said he was helping the FBI and law enforcement agencies worldwide locate other group members. Reuters could not establish why he was detained or where he was being held, and attempts to contact him and his family were unsuccessful.

The FBI declined to confirm any specific arrest or overseas operation. However, it said it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters,” adding that it had already worked with partners to arrest multiple subjects. The bureau pledged to pursue everyone responsible.

FBI Data Theft Claims

The detention follows ShinyHunters’ claim that it stole information on every FBI employee. That claim remains unverified, and the reported cooperation does not establish Khader’s role in the incident or prove the group’s account of its access.

Earlier reporting on the alleged FBI jobs portal breach described a defacement of apply.fbijobs.gov, where attackers displayed a fake seizure notice. The FBI subsequently took its application service and Special Agent Applicant Portal offline while investigating unauthorized activity affecting its recruitment systems.

ShinyHunters claimed it exploited an undisclosed Oracle PeopleSoft flaw that allowed code to run without logging in. The group said it then moved into FBI-managed AWS GovCloud systems and downloaded between two and three terabytes of data. Oracle, AWS, and the FBI have not confirmed that attack path.

The attackers supplied journalists with a sample of 5,000 alleged employee records containing names, home addresses, phone numbers, Social Security numbers, birth dates, assignments, and family details. Reuters partially matched information in at least 10 cases, but that check did not establish that the records came from compromised FBI systems.

These distinctions matter because taking control of a public website does not automatically prove access to an agency’s wider network. Investigators need to compare server logs, account activity, cloud access records, and outgoing data transfers to establish how the attackers entered and what they actually removed.

If genuine, the reported personnel records could support targeted phishing, identity fraud, harassment, or threats against employees and relatives. Details about assignments and family contacts could make fraudulent messages more convincing, even without attackers retaining access to government systems.

The Jordan detention also follows the arrest of an alleged ShinyHunters leader in the Netherlands. Dutch police detained a 24-year-old Amsterdam suspect on September 15, with FBI support. ShinyHunters denied that suspect’s association with the group, and the allegations remain unproven.

Reuters described ShinyHunters as a group believed by experts to consist mainly of young, English-speaking hackers focused on data theft and extortion. Khader’s reported cooperation could help investigators connect online identities with real people, but Reuters did not disclose what information he had provided.

For now, the key unanswered questions concern Khader’s legal status, the scope of his cooperation, and the true extent of the alleged FBI data theft. Neither the detention report nor the group’s public claims resolves those questions. The FBI’s investigation remains active, with further findings needed to separate confirmed evidence from attacker statements and other unverified allegations.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC



Source link