A suspected associate of the ShinyHunters hacking group has been detained in Jordan, reportedly aiding the FBI in identifying other linked hackers. According to sources cited by Reuters, Saif al-Din Khader, who allegedly goes by the online alias ‘Rey,’ was taken into custody on September 29.
Jordanian authorities reportedly detained Khader, with two sources suggesting he is assisting global law enforcement efforts to locate other group members. Reuters has not confirmed the reasons for his detention or his current location, and attempts to reach Khader or his family were unsuccessful.
The FBI has refrained from confirming any specific arrests or overseas operations. However, they emphasized their ongoing investigation into recent cyber incidents tied to ShinyHunters, noting prior arrests in collaboration with international partners. The bureau remains committed to holding all responsible parties accountable.
Unverified Claims of FBI Data Breach
The detention aligns with ShinyHunters’ assertion of having stolen data on every FBI employee, a claim that remains unproven. Khader’s reported cooperation does not clarify his involvement or validate the group’s claims of breaching FBI systems.
Previously, ShinyHunters allegedly compromised the FBI’s job portal, apply.fbijobs.gov, defacing it with a fake notice. The portal and the Special Agent Applicant Portal were taken offline during the investigation into unauthorized activities impacting recruitment processes.
The hackers claimed to exploit a flaw in Oracle PeopleSoft, allegedly allowing access to FBI-managed AWS GovCloud systems where they purportedly downloaded two to three terabytes of data. Neither Oracle, AWS, nor the FBI has confirmed these claims.
Impact and Verification Challenges
ShinyHunters provided journalists with a sample of 5,000 purported FBI employee records. Reuters verified partial matches in 10 cases, though this did not confirm the records originated from FBI systems. Access to a public website does not necessarily equate to infiltration of an agency’s broader network.
Forensic analysis, including server logs, account activity, and data transfer records, is crucial to understand the attackers’ entry point and what data, if any, was extracted. If true, the compromised records could facilitate phishing scams, identity theft, or harassment against FBI personnel and their relatives.
Ongoing Investigations and Future Outlook
The detention in Jordan follows a similar arrest in the Netherlands, where a 24-year-old suspect was apprehended in Amsterdam with FBI support. ShinyHunters denied any association with the suspect, and allegations remain unconfirmed.
ShinyHunters is described as a group of young, English-speaking hackers focused on data theft and extortion. Khader’s cooperation could potentially help authorities link digital identities to real individuals. However, Reuters has not disclosed what specific information he has provided.
Key questions linger regarding Khader’s legal situation, the extent of his cooperation, and the scope of the alleged FBI data breach. The investigation continues as authorities seek to distinguish verified facts from the group’s statements and unverified claims.
