BREAKING NEWSBREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident
Monitoring active · Brevard County, Florida

A3E Cyber Blog

BREAKING: Alleged ShinyHunters Member Detained in Jordan, Reportedly Cooperating With FBI

An alleged ShinyHunters member has reportedly been detained in Jordan and is cooperating with the FBI as investigators pursue the cybercrime group following its claimed theft of sensitive FBI personnel data. Reuters reported the development on October 3, 2026, citing three people familiar with the matter.

What happened

Reuters identified the detained person as Saif al-Din Khader, who is alleged to use the online name “Rey.” Three sources told the news organization that Jordanian authorities detained Khader, while two said he was taken into custody on Tuesday.

Two sources said Khader is helping the FBI and international law-enforcement agencies locate other alleged members of ShinyHunters. One source told Reuters that he was walking investigators through electronic devices and digital communications.

What is confirmed

The FBI did not confirm Khader’s specific detention or discuss activity in Jordan. In a statement to Reuters, however, the bureau said it continues to investigate the recent cyber incident allegedly involving ShinyHunters, has worked with partners to arrest multiple subjects, and intends to pursue those responsible.

Reuters said three people familiar with the matter independently described the detention. BleepingComputer also reported the development based on the Reuters account.

What remains unverified

Jordanian authorities have not publicly announced the detention, and Reuters could not determine the circumstances of Khader’s custody or where he is being held. No criminal charges against Khader related to this reported detention were publicly identified in the reporting.

ShinyHunters has claimed it stole between 2 TB and 3 TB of data involving current and former FBI employees and job applicants after compromising FBI-related systems. The FBI previously confirmed that it was investigating unauthorized activity connected to FBIJobs.gov, but it has not publicly verified the group’s full description of the access method, the amount of data taken, or every claim about the affected systems.

Reuters reported that its review of a sample shared by the group found personally identifiable information, sensitive job-role details, and medical and psychiatric information. That sample does not independently establish the full size or origin of the claimed dataset.

A material follow-up to the FBIJobs.gov investigation

This detention is a significant new development in the ShinyHunters investigation. Earlier A3E Cyber coverage focused on the FBI’s investigation of the claimed FBIJobs.gov compromise and the uncertainty surrounding the group’s broader assertions. The reported detention and cooperation now indicate an active international law-enforcement effort targeting people allegedly connected to the operation.

The reported cooperation follows the recent detention in the Netherlands of another suspected ShinyHunters member. Reuters also reported disruption around the group, including a period when its dark-web site disappeared and its usual communications went quiet. A new site later appeared, so businesses should not assume the threat has ended.

Why businesses should pay attention

ShinyHunters has been associated with data-theft and extortion campaigns targeting cloud services, software integrations, customer platforms, and other systems that can hold large volumes of sensitive information. Arrests can disrupt an operation, but stolen credentials, access tokens, data, and infrastructure may remain available to other participants.

Organizations should continue to treat unusual login activity, unexpected multifactor-authentication prompts, third-party integration alerts, and extortion messages as active security concerns. The reported law-enforcement action does not eliminate the possibility of follow-on phishing, impersonation, or data-leak activity.

Practical defensive actions

Review cloud and third-party access

Audit active sessions, API keys, OAuth applications, service accounts, and third-party integrations for customer, human-resources, and support platforms. Revoke access that is no longer needed and rotate credentials or tokens associated with suspicious activity.

Strengthen identity protections

Require phishing-resistant multifactor authentication for administrators and other high-risk accounts. Monitor for impossible travel, unfamiliar devices, bulk downloads, new forwarding rules, unusual password resets, and changes to privileged accounts.

Prepare for targeted social engineering

Warn employees that attackers may use accurate personal or employment information to make phishing messages more convincing. Verify requests involving passwords, account recovery, payroll, wire transfers, or sensitive records through a separate trusted channel.

Preserve evidence and report incidents

Organizations that receive an extortion demand or identify suspicious access should preserve logs, messages, and affected system images. Engage incident-response and legal teams, notify relevant providers, and report criminal activity to the FBI or the appropriate national law-enforcement authority.

Sources

Reuters: ShinyHunters hacker detained in Jordan and reportedly cooperating with FBI

BleepingComputer: ShinyHunters hacker reportedly detained in Jordan

FBI: Statement on compromise of FBIJobs.gov portal and alleged impact to FBI employee PII

Next step

Want this checked on your own systems?

The assessment is free and the summary is yours to keep either way.

Leave a comment

Your email address will not be published. Required fields are marked *

Call now Book an assessment