---
title: "ShinyHunters suspect 'Rey' reportedly held in Jordan, helping the FBI"
description: "An alleged ShinyHunters member known as 'Rey' has reportedly been arrested in Jordan and is said to be helping the FBI identify his accomplices. If confirmed, it hits one of the most prolific extortion crews of recent years, behind data thefts at a long list of organizations."
canonical: https://inyourgeek.com/en/articles/2026-10-05-shinyhunters-un-membre-presume-arrete-en-jordanie-aiderait-le
type: article
author: "Sébastien Soulier"
publisher: "InYourGeek"
language: en
datePublished: 2026-10-05
dateModified: 2026-10-05
section: "Security"
tags: ["shinyhunters", "fbi", "extorsion", "arrestation"]
---
# ShinyHunters suspect 'Rey' reportedly held in Jordan, helping the FBI
> An alleged ShinyHunters member known as 'Rey' has reportedly been arrested in Jordan and is said to be helping the FBI identify his accomplices. If confirmed, it hits one of the most prolific extortion crews of recent years, behind data thefts at a long list of organizations.
October 5, 2026 · Security · 3 min
## What Reuters is reporting

The story, published on October 3, 2026 by [Bleeping Computer](https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/), is based on reporting by Reuters and has not been officially confirmed. For now, treat it as a "reportedly" story. According to two of the news agency's sources, Jordanian authorities detained a man on Tuesday, September 29, who is presented as "Rey", a handle that has been tied to a long string of data theft and extortion attacks for the past two years.

The same sources say the suspect is now helping the FBI and other international police forces track down the rest of the group. One of them says he is walking investigators through his electronic devices and digital communications. No group chat ever wants an outsider to get that kind of guided tour. A source quoted by Reuters calls his cooperation "critical to ongoing efforts to arrest these hackers".

## A group under pressure since it went after the FBI

The detention is part of an FBI offensive against ShinyHunters, launched after an attack on the bureau itself. Poking the FBI is rarely a sound long-term career plan. In September, the group told Bleeping Computer it had broken into FBI systems through an alleged zero-day flaw in Oracle PeopleSoft, then moved into AWS GovCloud environments run by the bureau. The group claims to have stolen between 2 and 3 TB of data. It says the haul includes information on current and former agents and on applicants, along with medical and psychiatric records. Bleeping Computer could not verify these claims, and the FBI has only confirmed that it is investigating unauthorized activity.

On September 15, Dutch police had already arrested a 24-year-old man in Amsterdam as part of the investigation. The FBI then publicly invited the remaining members to turn themselves in. Brett Leatherman, deputy head of its cyber division, summed up the approach: "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left." Put another way, handcuffs loosen tongues, and a seized server hands over a list of the people still on it.

## A week of silence, then a new site

On Tuesday, September 29, the day of the alleged detention, the cracks started to show. A suspected affiliate of the group, who had contacted the press about the FBI attack, closed their messaging account. ShinyHunters' leak site then went offline, and its main spokesperson stopped answering both Bleeping Computer and Reuters. For a crew that usually can't stop talking to journalists, that's practically a vow of silence.

So far, nothing links that silence to the arrest. More importantly, a new leak site for the group went live on Thursday, October 1, so other members are clearly still in the extortion business. The Amsterdam arrest went the same way: the main spokesperson kept talking afterwards, which suggests the Dutch suspect wasn't the one running that account.

## A playbook that doesn't get arrested along with a suspect

ShinyHunters specializes in SaaS environments, Salesforce above all, with campaigns linked to intrusions at Google, Cisco and PornHub. Its usual method is to compromise third-party integration companies. It then reuses their stolen authentication tokens to get into the connected SaaS environments and pull out customer data. Why pick the lock when the locksmith has already handed you a spare key? In May, the group also carried out a massive data theft against Instructure Canvas, which caused major outages on the platform.

The ShinyHunters name has been linked to plenty of arrests over the years, notably over the Snowflake data thefts, PowerSchool and the Breached v2 forum. The group has survived every one of them. Cut off one head, and a new leak site grows back.

An arrest can take down accomplices, but it doesn't revoke a single integration token that has already been stolen. If your organization relies on these platforms, auditing those tokens is a job the FBI won't do for you.
## Sources
- [ShinyHunters hacker reportedly detained in Jordan, aiding FBI](https://www.bleepingcomputer.com/news/security/shinyhunters-hacker-reportedly-detained-in-jordan-aiding-fbi/) — bleepingcomputer.com
_Article written with AI assistance from the cited sources, reviewed and approved by a human before publication._

---

Equivalent HTML page : https://inyourgeek.com/en/articles/2026-10-05-shinyhunters-un-membre-presume-arrete-en-jordanie-aiderait-le
Published by InYourGeek — https://inyourgeek.com/en/a-propos
Method and safeguards : https://inyourgeek.com/en/methode
All articles : https://inyourgeek.com/en/archives
