FBI confirms multiple arrests in ShinyHunters investigation, suspect detained in Jordan

Group linked to costly JLR breach and FBIJobs.gov hack faces widening crackdown

By LineZotpaper
Published
Read Time3 min
The FBI has confirmed that multiple suspects have been arrested as part of an investigation into the data-theft-and-extortion group ShinyHunters, with one alleged member detained in Jordan and another in the Netherlands. The arrests follow a series of high-profile cyberattacks, including a breach of Jaguar Land Rover (JLR) and a hack of the FBI’s own jobs portal.

The FBI has told The Register that law enforcement has worked with partners to arrest multiple subjects linked to the group, which is believed to be responsible for significant data theft and extortion campaigns. The bureau declined to comment on specific arrests, including that of Saif al-Din Khader, a suspected ShinyHunters member who has reportedly been detained in Jordan since 29 September.

Khader, who goes by the alias Rey and was described by security journalist Brian Krebs as the “technical operator and public face” of the group Scattered LAPSUS$ Hunters, is said to be cooperating with the FBI. Security researcher Kevin Beaumont noted that “Rey got picked up finally” and was “one of the kids who got into JLR.”

The JLR breach, which took place in late August 2025, disrupted the carmaker’s IT systems and halted manufacturing operations for months. It shut down dealer systems, led to cancelled or delayed supplier orders, and resulted in the theft of personal payroll data for thousands of employees. The attack was attributed to Scattered LAPSUS$ Hunters, a group with which ShinyHunters is closely linked.

Khader’s detention came two weeks after Dutch National Police arrested a 24-year-old man whom the FBI described as “one of the alleged leaders of ShinyHunters.” While Dutch authorities have not named the suspect, reports identify him as Pepijn van der Stap, who was convicted in 2023 for hacking and extortion and was on supervised release. Van der Stap had been working as a software engineer at cybersecurity startup Hadrian and volunteered with the Dutch Institute for Vulnerability Disclosure.

In a video message following the Dutch arrest, Brett Leatherman, assistant director of the FBI’s Cyber Division, addressed remaining members of the group: “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”

ShinyHunters has claimed responsibility for hacking the FBIJobs.gov portal in late September, stealing personal details of current, former and prospective FBI employees. In an exclusive interview, a spokesperson for the group said the breach was “fundamentally a public relations and marketing initiative for our business” and that it was not financially motivated. The group demanded the FBI correct statements it said contained “substantial false allegations.”

§

Analysis

Why This Matters

  • The arrests signal intensifying international cooperation against cybercriminal enterprises, potentially deterring future high-impact extortion campaigns.
  • ShinyHunters has demonstrated ability to disrupt critical infrastructure (JLR) and compromise sensitive law enforcement systems, raising concerns about both corporate and government security.
  • The involvement of a suspect who was reportedly cooperating while also being a former convict on supervised release highlights gaps in rehabilitation and monitoring of cybercriminals.

Background

The group known as ShinyHunters has been active since at least 2020, gaining notoriety for large-scale data breaches and extortion. It is closely associated with Scattered LAPSUS$ Hunters, a collective that has targeted major corporations and government agencies. The JLR attack was one of the most costly cyber incidents in UK history, causing months of operational disruption. The group’s hack of FBIJobs.gov marked an escalation in targeting federal systems, and the FBI’s public message to remaining members suggests a strategic push to dismantle the network.

Key Perspectives

FBI: The bureau emphasises its aggressive pursuit of the group and willingness to use arrests and seized infrastructure to pressure offenders. Assistant Director Leatherman’s statement directly invites surrender. ShinyHunters: The group frames its FBIJobs.gov breach as a PR move to challenge what it considers false allegations, indicating a mix of criminal motive and ideological or reputational goals. Security researchers: Observers such as Kevin Beaumont and Brian Krebs have provided key identification of suspects and linked the group to specific attacks, underscoring the role of independent analysts in cyber investigations.

What to Watch

  • Whether Saif al-Din Khader’s cooperation leads to further arrests of high-ranking group members.
  • The outcome of legal proceedings in the Netherlands for the suspect arrested there, and any extradition requests from the United States.
  • Potential retaliation or shift in tactics by ShinyHunters members still at large, particularly targeting law enforcement infrastructure.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.