The landscape of international cybercrime shifted significantly on September 29, 2026, when authorities in Jordan apprehended Saif al-Din Khader, a central figure in the notorious digital extortion collective known as ShinyHunters. Operating under the online aliases "Rey" and "ReyXBF," Khader’s arrest marks a pivotal success for the U.S. Federal Bureau of Investigation (FBI) and its international partners. Sources familiar with the investigation confirm that Khader is currently cooperating with law enforcement, providing critical intelligence intended to dismantle the operational hierarchy of one of the world’s most persistent hacking syndicates.
The Rise and Fall of a Cybercriminal Architect
Khader’s detention is not merely the removal of a single actor but the neutralization of a strategic bridge between disparate criminal factions. According to independent security research conducted by Brian Krebs in late 2025, Khader served as one of the three primary administrators for the "Scattered LAPSUS$ Hunters" (SLH)—an umbrella organization formed through the merger of Scattered Spider, LAPSUS$, and ShinyHunters.
This consolidation represented a new evolution in cybercrime: a "merger" of resources, social engineering tactics, and technical capabilities. Before his tenure at the helm of SLH, Khader’s digital footprint was expansive. He was instrumental in managing the data leak infrastructure for "Hellcat," a ransomware group that emerged in late 2024, and he previously held administrative control over the final iteration of BreachForums, a notorious hub for stolen data. His decision to cooperate with the FBI, which reportedly began as early as June 2025, underscores the mounting pressure felt by high-level cybercriminals as federal authorities prioritize the infiltration of these groups from the inside out.
A Chronology of Escalation
The arrest of Khader follows a period of unprecedented activity by ShinyHunters, which has seen the group oscillate between brazen attacks on government infrastructure and internal power struggles with rival extortion gangs.
- April–May 2020: The ShinyHunters brand surfaces, initially operating as a small crew trading stolen databases on the now-defunct RaidForums.
- Late 2024: The "Hellcat" ransomware group emerges, with Khader serving as a key administrator.
- June 2025: According to reports, Khader initiates secret cooperation with federal law enforcement agencies.
- November 2025: Investigative reporting identifies Khader as a central administrator of the Scattered LAPSUS$ Hunters.
- September 2026: A 24-year-old Dutch national, identified as Pepijn van der Stap, is arrested in Amsterdam for his alleged leadership role in ShinyHunters.
- September 21, 2026: ShinyHunters claims a tactical victory by hijacking the darknet infrastructure of the rival Cl0p ransomware gang.
- Late September 2026: ShinyHunters conducts a high-profile breach of the FBI’s "apply.fbijobs.gov" portal, exfiltrating three terabytes of data.
- September 29, 2026: Saif al-Din Khader is taken into custody in Jordan.
Strategic Implications of the FBI Portal Breach
The recent breach of the FBI’s job application portal stands as a landmark event in the ongoing friction between state intelligence and criminal entities. By exfiltrating three terabytes of sensitive data, ShinyHunters attempted to leverage the information to force the FBI into retracting public statements regarding the group’s ties to "The Com." The Com, a loose-knit but highly dangerous collective, is known for a broad spectrum of illegal activities, including kidnapping, swatting, and sophisticated social engineering.

While ShinyHunters maintained that the breach was an act of "pressure" rather than a quest for financial gain, the event demonstrated a dangerous escalation in the group’s willingness to target state institutions directly. FBI leadership, however, viewed the act as a desperate reach by a cornered organization. In a public statement, FBI Director Kash Patel emphasized that the agency is actively tracking leads generated by these recent incursions, noting that "more arrests are on the table."
The Evolution of the ShinyHunters Business Model
In a comprehensive analysis, cybersecurity firms Sekoia and Beazley Security have characterized ShinyHunters not as a monolithic organization, but as a resilient "business model." Unlike traditional hacker groups that rely on a central command structure, ShinyHunters functions as a modular brand.
This structure allows the group to survive despite significant setbacks, such as the arrest of alleged leader Pepijn van der Stap—a former offensive security lead at a Dutch firm who had reportedly turned to black-hat activities. When individual members are captured, the "brand" remains, and the division of labor—ranging from initial access brokers to data monetizers—is simply redistributed among the remaining participants.
Researchers Enzo Saez and Robert Venal noted that this "self-renewing" capability is the core reason for the group’s longevity. By absorbing the impact of forum seizures and international indictments, the collective has successfully transformed itself from a simple data-trading site into a persistent, multi-faceted threat actor capable of breaching more than 140 organizations in a single year, resulting in an estimated $70 million in extortion payments.
Official Responses and the Deterrence Strategy
The message from U.S. law enforcement is one of calculated ultimatum. Brett Leatherman, assistant director of the FBI’s cyber division, has moved beyond traditional warnings, instead issuing a direct invitation for criminal participants to defect.
"Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left," Leatherman stated. "The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

This "defector-first" strategy marks a shift in how federal agencies manage global cyber threats. By highlighting the cooperation of figures like Khader and the ongoing investigations into figures like van der Stap, the FBI is attempting to foster an environment of paranoia within the ranks of these criminal collectives. The implication is clear: the perceived safety of anonymity behind international borders is no longer a guaranteed protection against the reach of federal cyber units.
Broader Impact on Cybersecurity
The arrest of key administrators is expected to have a cascading effect on the underground market. As these individuals are removed from the digital ecosystem, the coordination required to manage massive data dumps, maintain extortion infrastructure, and facilitate ransom payments becomes increasingly fractured.
However, industry experts warn that the modular nature of the "ShinyHunters" model suggests that the void left by these arrests will likely be filled by emerging actors eager to adopt the proven, high-profit tactics of their predecessors. The challenge for international law enforcement remains the sheer pace at which these groups adapt. While the arrest of Khader is a tactical win, the strategic reality is that as long as the underlying vulnerabilities—such as the unpatched Grav CMS flaw exploited in the Cl0p site hijacking—persist, the environment remains fertile for the next iteration of organized digital extortion.
Moving forward, the success of the FBI’s mission will be measured not only by the number of high-profile arrests but by the ability of the agency to disrupt the "division of labor" that allows these groups to function. By targeting the administrators and the infrastructure that connects these disparate actors, the FBI aims to turn the very resilience of these groups against them, eventually rendering the ShinyHunters brand too toxic and too high-risk for the criminal underground to sustain.
