Threat reportThreat IntelligenceTL-2026-2945

ShinyHunters: alleged leader 'Rey' (Saif al-Din Khader) detained in Jordan and reportedly cooperating with the FBI; Dutch suspect Pepijn van der Stap ('Umbreon') arrested

mediumACTIVE

ShinyHunters (TL-2026-2945), also tracked as Rey arrest, is a medium-severity tracked intrusion set, first published 2026-10-05. It is attributed to ShinyHunters with medium confidence, affects Various SSO and SaaS tenants (Okta, Microsoft 365, Google Workspace, maps to 11 MITRE ATT&CK techniques (T1078.004, T1111, T1190), and is covered by 9 detection rules and 16 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
11MITRE ATT&CK
Actors
1ShinyHunters
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-2945

Threat ID
TL-2026-2945
Also known as
Rey arrest, Umbreon arrest
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution
ShinyHunters
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, telecoms, retail, education, government administration, entertainment, hospitality, finance
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
16

Malware and tooling in ShinyHunters

Malware and tooling: Morpheus, ShinySp1d3r, scattered lapsus$ hunters, telegram, Umbreon

How ShinyHunters works

The Record reports that Saif al-Din Khader, the Amman-based teenager who goes by 'Rey' and is described as a ShinyHunters / Scattered LAPSUS$ Hunters administrator, was detained in Jordan on 2026-09-28 and is reportedly cooperating with the FBI and other agencies to locate other members. Separately, Dutch police detained 24-year-old Pepijn van der Stap ('Umbreon'), with a Rotterdam court appearance on 2026-09-29, in an investigation tied to ShinyHunters extortion and the FBI jobs-portal breach.

Law-enforcement development on an active data-theft and extortion collective. According to The Record (published 2026-10-05), Saif al-Din Khader, handle 'Rey', was detained in Jordan on 2026-09-28 and is reportedly assisting the FBI and other law-enforcement agencies in identifying other members of the group; he is described as responsible for dozens of significant incidents against European and American companies. Victims named in the report include Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line, 7-Eleven, ADT, Rockstar Games and the FBI itself. The report says the group's leak site was taken down the week before publication and that a Telegram channel resurfaced in October claiming to restart a defunct cybercriminal forum. The Record reports Khader allegedly had a power struggle with Pepijn van der Stap over control of the group.

Background on Rey: KrebsOnSecurity profiled him in November 2025 as the technical operator and public face of Scattered LAPSUS$ Hunters (SLSH, described as an amalgamation of Scattered Spider, LAPSUS$ and ShinyHunters), one of three administrators of the SLSH Telegram channel, a former administrator of the Hellcat ransomware leak site, and the 2024-2025 administrator of BreachForums. Krebs documented the handles @wristmug, o5tdev and Hikki-Chan, a Proton Mail address and a Telegram ID, and at that time described him as 15 years old and based in Amman; he claimed to have been cooperating with law enforcement since mid-2025 and to have stopped breaching and extorting in September 2025. Krebs also attributed the ShinySp1d3r ransomware-as-a-service (modified Hellcat source with AI enhancements) and a May 2025 Salesforce voice-phishing campaign to him.

Dutch arrest: The Hacker News and Security Affairs report that Dutch police arrested a 24-year-old Amsterdam man, identified as Pepijn van der Stap (alias 'Umbreon', on BreachForums since 2021), with a home search on 2026-09-15 and a Rotterdam District Court appearance on 2026-09-29. He was previously convicted in 2023 for data theft and extortion (four years, one suspended, plus three years' probation), was released in December 2025 and later worked as an offensive security lead at Neo Security. THN reports charges of a leadership role, 140+ breached organizations and roughly $70 million in extortion, plus a separate attempted-incitement-to-murder investigation; ShinyHunters publicly denied he was associated with them. Cybernews reports the arrest could be an elaborate frame job by a rival faction using his old 'Umbreon' alias in the dispute over control of the ShinyHunters name. Note the date discrepancy: the hunt skeleton (from The Record) gives 2026-09-29 as the arrest date, while THN/Security Affairs give 2026-09-15 for the arrest/search and 2026-09-29 for the court appearance.

The FBI breach: ShinyHunters claimed in late September 2026 to have stolen data on almost all FBI agents and job applicants from the FBI jobs portal (apply.fbijobs.gov); the FBI took the portal offline and confirmed an investigation. A ~5,000-agent sample reportedly contained names, home addresses, SSNs and assignments, and the group said it acted in response to the FBI's May 2026 PSA about the group. Mandiant is cited by Security Affairs as estimating nearly $100 million in extortion payments in 2026; Security Affairs also cites the Odido (Netherlands) breach affecting 6.2 million people.

Technical tradecraft evidenced across sources: voice phishing impersonating IT/helpdesk, adversary-in-the-middle phishing pages that capture credentials and TOTP codes in real time and relay them via Telegram/Socket.IO, SSO (Okta/Microsoft 365/Google/Slack) pivoting to Salesforce and other SaaS for bulk data theft, targeting of third-party cloud platform vendors, a reported Oracle PeopleSoft zero-day with URL-encoding WAF bypass (per THN), then leak-site extortion. No CVEs or new IOCs are published in the primary article; the indicators below come from supporting reporting. Defender relevance: expect possible group disruption, rebranding, retaliation or doxxing, and continued vishing/SSO-targeted SaaS intrusion regardless of the arrests.

MITRE ATT&CK techniques used in TL-2026-2945

Initial Access

T1078.004 Cloud Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.004 Spearphishing Voice

Credential Access

T1111 Multi-Factor Authentication Interception

Collection

T1213 Data from Information Repositories

Impact

T1491.002 External Defacement; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Domains; T1583.006 Web Services

Affected products and versions in ShinyHunters

  • Various — SSO and SaaS tenants (Okta, Microsoft 365, Google Workspace, Salesforce, Slack)
    Vulnerable versions: Tenants without phishing-resistant MFA or helpdesk verification controls
  • FBI — FBI jobs portal (apply.fbijobs.gov)
    Vulnerable versions: Compromised per group claim and FBI investigation

Remediation for ShinyHunters

Immediate actions

  • Do not pay or engage with ShinyHunters extortion demands, per the FBI May 2026 PSA
  • Enforce callback verification for any helpdesk/IT call requesting credential, MFA, or passkey enrollment actions
  • Review SSO and Salesforce/SaaS logs for anomalous logins, new MFA enrollments, and bulk API/report exports

Workarounds

  • Block or alert on newly registered lookalike domains containing company name with 'internal' or 'my' prefixes
  • Alert on traffic to free hosting platforms (e.g., onrender.com) from corporate login flows

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/passkeys) for SSO and SaaS admin accounts
  • Restrict SaaS API/connected-app access and monitor bulk data exports
  • Treat insider-recruitment solicitations as a threat and brief staff and helpdesk

Timeline of ShinyHunters

  • Approximate (month precision): 'Hikki-Chan' (Rey) makes first BreachForums post sharing CDC data, per KrebsOnSecurity
  • Approximate (month precision): Salesforce voice-phishing campaign against corporate environments, attributed by Krebs to the SLSH ecosystem
  • FBI seizes BreachForums domains, per KrebsOnSecurity
  • KrebsOnSecurity publishes 'Meet Rey, the Admin of Scattered Lapsus$ Hunters', identifying Saif al-Din Khader of Amman, Jordan
  • Okta warns of custom vishing kits with real-time credential/TOTP relay, potentially affiliated with ShinyHunters
  • FBI issues PSA on ShinyHunters attacks and advises victims not to pay extortion demands
  • Dutch police search Pepijn van der Stap's Amsterdam residence and seize devices (THN/Security Affairs); The Record gives 2026-09-29 for the arrest
  • FBI takes its jobs portal offline and investigates after ShinyHunters claims theft of data on nearly all agents and applicants
  • Saif al-Din Khader ('Rey') detained in Jordan; reportedly cooperating with FBI and other agencies
  • Pepijn van der Stap appears before the Rotterdam District Court; The Record reports his arrest on this date
  • The Record reports Khader's detention and cooperation; notes ShinyHunters leak site taken down the prior week and a Telegram channel resurfacing in October

Sources cited for ShinyHunters

Detection coverage for TL-2026-2945

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2945 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats