The FBI has told The Register that law enforcement has worked with partners to arrest multiple subjects linked to the group, which is believed to be responsible for significant data theft and extortion campaigns. The bureau declined to comment on specific arrests, including that of Saif al-Din Khader, a suspected ShinyHunters member who has reportedly been detained in Jordan since 29 September.
Khader, who goes by the alias Rey and was described by security journalist Brian Krebs as the “technical operator and public face” of the group Scattered LAPSUS$ Hunters, is said to be cooperating with the FBI. Security researcher Kevin Beaumont noted that “Rey got picked up finally” and was “one of the kids who got into JLR.”
The JLR breach, which took place in late August 2025, disrupted the carmaker’s IT systems and halted manufacturing operations for months. It shut down dealer systems, led to cancelled or delayed supplier orders, and resulted in the theft of personal payroll data for thousands of employees. The attack was attributed to Scattered LAPSUS$ Hunters, a group with which ShinyHunters is closely linked.
Khader’s detention came two weeks after Dutch National Police arrested a 24-year-old man whom the FBI described as “one of the alleged leaders of ShinyHunters.” While Dutch authorities have not named the suspect, reports identify him as Pepijn van der Stap, who was convicted in 2023 for hacking and extortion and was on supervised release. Van der Stap had been working as a software engineer at cybersecurity startup Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure.
In a video message following the Dutch arrest, Brett Leatherman, assistant director of the FBI’s Cyber Division, addressed remaining members of the group: “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
ShinyHunters has claimed responsibility for hacking the FBIJobs.gov portal in late September, stealing personal details of current, former and prospective FBI employees. In an exclusive interview, a spokesperson for the group said the breach was “fundamentally a public relations and marketing initiative for our business” and that it was not financially motivated. The group demanded the FBI correct statements it said contained “substantial false allegations.”