A teenager from Amman, Jordan suspected of leading the data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang, according to sources cited by Reuters. The suspect, who uses the hacker handle "Rey" and has been identified by KrebsOnSecurity as Saif Al-din Khader, was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's father — Royal Jordanian Airlines.
KrebsOnSecurity first identified Rey as Khader in a November 2025 profile, in which the young man admitted working with multiple ransomware groups. On September 28, KrebsOnSecurity reported that Dutch police arrested 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding in data thefts and extortions by ShinyHunters. The story noted that immediately following the Dutchman's arrest on September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the FBI and extorting the ransomware group Cl0p.
Rey taunted both the FBI and Cl0p with memes posted to his Twitter/X account, while simultaneously including images of the avatar used by Van Der Stap's former hacker alias "Umbreon" in an apparent attempt to frame the Dutchman for both hacks.
As previously reported, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability in PeopleSoft, a software-as-a-service platform from Oracle that is broadly used to manage hiring, human resources, benefits, and payroll. Oracle quickly issued a fix for the vulnerability, which ShinyHunters first began exploiting as a zero-day in June, and Mandiant released web application firewall rules for organizations that could not apply the security update quickly enough.