Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

ShinyHunters' Web of Deceit: Unraveling the Complexities of a Notorious Cybercrime Group




ShinyHunters, a notorious cybercrime group, has been at the center of a high-stakes game of cat and mouse with law enforcement agencies worldwide. The group's alleged mastermind, "Rey," has been detained by authorities in Jordan, and his cooperation is believed to be critical to ongoing efforts to arrest other members of the group. This article provides a detailed look at the ShinyHunters saga, its origins, and its complex web of deceit, as well as the ongoing efforts of law enforcement agencies to bring the group to justice.

  • ShinyHunters, a digital extortion group, has been linked to high-profile cyberattacks, including the hijacking of a darknet website and the theft of sensitive data from the FBI's portal.
  • The group's mastermind, Rey, was detained by authorities in Jordan in cooperation with the FBI and law enforcement to identify other members.
  • Rey, also known as ReyXBF, was previously identified as one of the administrators of Scattered LAPSUS$ Hunters (SLH or SLSH) and Hellcat, a ransomware group.
  • The arrest of a ShinyHunters member in Amsterdam led to the arrest of another suspect, Pepijn van der Stap, a reformed hacker.
  • The FBI is actively working to obtain and execute more leads in the ongoing investigation, with more arrests on the table.
  • ShinyHunters has been linked to over 140 organizations breached and at least $70 million in extortion payments.
  • The group's tactics have evolved from data leaks to extortion and SIM swapping, with a focus on targeting third-party vendors in cloud-based platforms.
  • The ShinyHunters brand has become a self-renewing group that has absorbed indictments, arrests, and forum seizures without going quiet for long.



  • ShinyHunters, a digital extortion group notorious for its brazen cybercrimes, has been at the center of a high-stakes game of cat and mouse with law enforcement agencies worldwide. The group, whose members operate under the radar of international law enforcement, has been linked to a string of high-profile cyberattacks, including the hijacking of a fellow cybercriminal outfit's darknet website and the theft of sensitive data from the FBI's "apply.fbijobs[.]gov" portal. At the heart of this complex web of deceit lies a mastermind known only by his online alias, "Rey," whose real name is Saif al-Din Khader.

    According to sources, Rey was detained by authorities in Jordan on September 29, 2026, in cooperation with the U.S. Federal Bureau of Investigation (FBI) and law enforcement to identify other members of the group. Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody cooperating with the FBI and law enforcement to identify other members of the group. "His cooperation is critical to ongoing efforts to arrest these hackers," a source told the news agency.

    Rey, who also went by the online alias ReyXBF, is not an unknown face. In a report published in November 2025, independent security journalist Brian Krebs labeled him as one of the three administrators of Scattered LAPSUS$ Hunters (SLH or SLSH), a group that's assessed to be an amalgamation of Scattered Spider, LAPSUS$, and ShinyHunters. "Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024," Krebs noted at the time. "Also in 2024, Rey would take over as administrator of the most recent incarnation of BreachForums." Khader also told Krebs that he had been cooperating with law enforcement since at least June 2025.

    The development is the latest action in the ShinyHunters saga, which also saw the arrest of a 24-year-old Amsterdam man last week for their involvement in the threat actor's malicious cyber operations. Although his identity has not been disclosed, independent reports revealed that it was Pepijn van der Stap, a reformed hacker who has been employed as an offensive security lead at the Dutch company Neo Security. A ShinyHunters spokesperson subsequently denied having any connections with van der Stap.

    Following the arrest, FBI director Kash Patel said, "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest." In a follow-up X post, Patel said, "FBI teams are working new leads RIGHT NOW. More arrests are on the table."

    In recent weeks, the prolific hacking crew has come under the spotlight for hijacking the darknet website of a fellow cybercriminal outfit, Cl0p, by exploiting an unpatched flaw in Grav CMS and its hack of the FBI's "apply.fbijobs[.]gov" portal, stealing around three terabytes of sensitive data. ShinyHunters insisted that it's not seeking a monetary payoff in the FBI case, but rather apply pressure on the FBI to amend what it said were false allegations about the group and challenge claims made by the agency about its connections with The Com, a loose-knit cybercrime collective notorious for social engineering, phishing, SIM swapping, extortion, sextortion, swatting, kidnapping, and physical violence.

    "Since last year, this cybercriminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Brett Leatherman, assistant director of the FBI's cyber division, said in a recorded statement. "They often target third-party vendors in cloud-based platforms, stealing sensitive data and extort victims with threats to publish it."

    Leatherman, who described van der Stap as an alleged leader of the group, also urged other members to speak out and said that they can no longer hide behind perceived international anonymity and evade detection. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left. The longer you stay in this, the more we learn about you," Leatherman added. "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours."

    In a deep-dive report tracing ShinyHunters' origins and their tactical evolution, cybersecurity companies Sekoia and Beazley Security said its lineage goes back to two progenitor hacking groups, TheDarkOverlord and GnosticPlayers, that specialized in extortion and data leak operations. The ShinyHunters brand emerged publicly around April or May 2020.

    "Six years on, ShinyHunters is less a group than a brand and business model that has outlived its founders," researchers Enzo Saez and Robert (Bobby) Venal said. "What began in 2020 as a small crew trading stolen databases on RaidForums has become a persistent, self-renewing group that has absorbed indictments, arrests, and forum seizures without ever going quiet for long."

    "That resilience is the real story. It doesn't come from any single leader or cell, but from a division of labor that has become almost modular: initial access from social engineers, amplification and recruitment from adjacent actors, and monetization under a shared, recognizable brand."



    Related Information:
  • https://www.ethicalhackingnews.com/articles/ShinyHunters-Web-of-Deceit-Unraveling-the-Complexities-of-a-Notorious-Cybercrime-Group-ehn.shtml

  • https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html

  • https://cybersecuritynews.com/shinyhunters-hacker-helping-fbi/


  • Published: Sun Oct 4 03:14:40 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us