ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
- ID
- 31576
- Status
- summarized
- Published
- 04 Oct 2026, 3:22 PM
- Fetched
- 05 Oct 2026, 5:04 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.5
- Created
- 05 Oct 2026, 5:05 PM
- Tags
- Audience
- developers
What happened
Reuters, citing three people familiar with the matter, reports that ShinyHunters suspect Saif al-Din Khader (alias "Rey" / ReyXBF) was detained in Jordan on September 29, 2026 and is cooperating with the FBI to identify other group members; Krebs had previously described him as an administrator of Scattered LAPSUS$ Hunters, Hellcat's leak site, and a 2024 incarnation of BreachForums. The article also notes a 24-year-old Amsterdam man arrested the prior week — independently reported as Pepijn van der Stap, an offensive security lead at Dutch firm Neo Security — which a ShinyHunters spokesperson denied, and cites FBI director Kash Patel saying more arrests are "on the table." The one technical detail in the text is that the crew hijacked Cl0p's darknet site by exploiting an unpatched flaw in Grav CMS, alongside a hack of the FBI's apply.fbijobs.gov portal.
Why it matters
For most builders this is law-enforcement news with no required change — arrests of threat-actor members don't alter your stack. The only actionable item is the named vector: if you run Grav CMS, the article says an unpatched flaw in it was exploited in this campaign, so verifying your Grav version and patch status is the concrete follow-up. There is no Malaysia-specific or AI/agent-specific implication in the text.
Discussion angle
Is it worth tracking named threat-actor arrests at all, or only the exploitation vector? Use the Grav CMS mention to check how many in the room actually run Grav and whether anyone would have caught that unpatched flaw in their own dependency review.