# ShinyHunters: alleged leader 'Rey' (Saif al-Din Khader) detained in Jordan and reportedly cooperating with the FBI; Dutch suspect Pepijn van der Stap ('Umbreon') arrested

> The Record reports that Saif al-Din Khader, the Amman-based teenager who goes by 'Rey' and is described as a ShinyHunters / Scattered LAPSUS$ Hunters administrator, was detained in Jordan on 2026-09-28 and is reportedly cooperating with the FBI and other agencies to locate other members. Separately, Dutch police detained 24-year-old Pepijn van der Stap ('Umbreon'), with a Rotterdam court appearance on 2026-09-29, in an investigation tied to ShinyHunters extortion and the FBI jobs-portal breach.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2945
- **ID:** TL-2026-2945
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Actor:** ShinyHunters
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Law-enforcement development on an active data-theft and extortion collective. According to The Record (published 2026-10-05), Saif al-Din Khader, handle 'Rey', was detained in Jordan on 2026-09-28 and is reportedly assisting the FBI and other law-enforcement agencies in identifying other members of the group; he is described as responsible for dozens of significant incidents against European and American companies. Victims named in the report include Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line, 7-Eleven, ADT, Rockstar Games and the FBI itself. The report says the group's leak site was taken down the week before publication and that a Telegram channel resurfaced in October claiming to restart a defunct cybercriminal forum. The Record reports Khader allegedly had a power struggle with Pepijn van der Stap over control of the group.

Background on Rey: KrebsOnSecurity profiled him in November 2025 as the technical operator and public face of Scattered LAPSUS$ Hunters (SLSH, described as an amalgamation of Scattered Spider, LAPSUS$ and ShinyHunters), one of three administrators of the SLSH Telegram channel, a former administrator of the Hellcat ransomware leak site, and the 2024-2025 administrator of BreachForums. Krebs documented the handles @wristmug, o5tdev and Hikki-Chan, a Proton Mail address and a Telegram ID, and at that time described him as 15 years old and based in Amman; he claimed to have been cooperating with law enforcement since mid-2025 and to have stopped breaching and extorting in September 2025. Krebs also attributed the ShinySp1d3r ransomware-as-a-service (modified Hellcat source with AI enhancements) and a May 2025 Salesforce voice-phishing campaign to him.

Dutch arrest: The Hacker News and Security Affairs report that Dutch police arrested a 24-year-old Amsterdam man, identified as Pepijn van der Stap (alias 'Umbreon', on BreachForums since 2021), with a home search on 2026-09-15 and a Rotterdam District Court appearance on 2026-09-29. He was previously convicted in 2023 for data theft and extortion (four years, one suspended, plus three years' probation), was released in December 2025 and later worked as an offensive security lead at Neo Security. THN reports charges of a leadership role, 140+ breached organizations and roughly $70 million in extortion, plus a separate attempted-incitement-to-murder investigation; ShinyHunters publicly denied he was associated with them. Cybernews reports the arrest could be an elaborate frame job by a rival faction using his old 'Umbreon' alias in the dispute over control of the ShinyHunters name. Note the date discrepancy: the hunt skeleton (from The Record) gives 2026-09-29 as the arrest date, while THN/Security Affairs give 2026-09-15 for the arrest/search and 2026-09-29 for the court appearance.

The FBI breach: ShinyHunters claimed in late September 2026 to have stolen data on almost all FBI agents and job applicants from the FBI jobs portal (apply.fbijobs.gov); the FBI took the portal offline and confirmed an investigation. A ~5,000-agent sample reportedly contained names, home addresses, SSNs and assignments, and the group said it acted in response to the FBI's May 2026 PSA about the group. Mandiant is cited by Security Affairs as estimating nearly $100 million in extortion payments in 2026; Security Affairs also cites the Odido (Netherlands) breach affecting 6.2 million people.

Technical tradecraft evidenced across sources: voice phishing impersonating IT/helpdesk, adversary-in-the-middle phishing pages that capture credentials and TOTP codes in real time and relay them via Telegram/Socket.IO, SSO (Okta/Microsoft 365/Google/Slack) pivoting to Salesforce and other SaaS for bulk data theft, targeting of third-party cloud platform vendors, a reported Oracle PeopleSoft zero-day with URL-encoding WAF bypass (per THN), then leak-site extortion. No CVEs or new IOCs are published in the primary article; the indicators below come from supporting reporting. Defender relevance: expect possible group disruption, rebranding, retaliation or doxxing, and continued vishing/SSO-targeted SaaS intrusion regardless of the arrests.

## MITRE ATT&CK

- T1566.004 Spearphishing Voice
- T1078.004 Cloud Accounts
- T1199 Trusted Relationship
- T1190 Exploit Public-Facing Application
- T1583.001 Domains
- T1583.006 Web Services
- T1111 Multi-Factor Authentication Interception
- T1213 Data from Information Repositories
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft
- T1491.002 External Defacement

## Sources

- [Alleged ShinyHunters member reportedly detained in Jordan, assisting law enforcement (The Record)](https://therecord.media/alleged-shinyhunters-member-detained-jordan-fbi)
- [Meet Rey, the Admin of 'Scattered Lapsus$ Hunters' (KrebsOnSecurity)](https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/)
- [Dutch police arrest 24-year-old (The Hacker News)](https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html)
- [24-Year-Old Arrested in Dutch Investigation Into ShinyHunters (Security Affairs)](https://securityaffairs.com/?p=199979)
- [Former ShinyHunters hacker arrested in what could be an elaborate frame job in FBI hack (Cybernews)](https://cybernews.com/cybercrime/shinyhunters-dutch-hacker-arrest-fbi-frame-job/)
- [Dutch reformed hacker arrested in ShinyHunters investigation, police and ex-boss say (CTV News)](https://www.ctvnews.ca/sci-tech/article/dutch-reformed-hacker-arrested-in-shinyhunters-investigation-police-and-ex-boss-say/)
- [FBI investigates after ShinyHunters hackers claim theft of agents' personal data (Fox News)](https://www.foxnews.com/politics/fbi-investigates-shinyhunters-hackers-claim-theft-agents-personal-data.amp)
- [ShinyHunters claims FBI breach exposed employee and applicant data (Beinsure)](https://beinsure.com/news/shinyhunters-claims-fbi-breach-exposed-employee-and-applicant-data/)
- [FBI PSA: ShinyHunters Cyber Criminal Group Attacks Learning Management System](https://www.law.berkeley.edu/wp-content/uploads/2026/06/PSA-ShinyHunters-Cyber-Criminal-Group-Attacks-Learning-Management-System_5.15.2026.pdf)
- [Okta Warns Users of Custom Vishing Kits Potentially Affiliated with ShinyHunters (RH-ISAC)](https://rhisac.org/threat-intelligence/okta-warns-users-of-custom-vishing-kits-potentially-affiliated-with-shinyhunters/)
- [ShinyHunters / UNC6040 Voice-Phishing Campaign (OpenEFA advisory)](https://openefa.com/security-advisories/shinyhunters-vishing-campaign.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2945
