JORDAN— A suspected member of the ShinyHunters hacking group linked to major corporate data breaches has been detained by authorities and is reportedly cooperating with the FBI as investigators expand their efforts to identify other members.
The suspect, Saif al-Din Khader, is known online as “Rey” and was detained in Jordan last week, according to people familiar with the matter.
The development could add momentum to an international investigation into the hacking network, which has been associated with the theft of data from several major organisations.
Qantas (QF) was among the companies affected after a cyberattack in June 2025 exposed data belonging to 5.7 million customers.

ShinyHunters Investigation Expands
Khader is reportedly assisting the FBI and other international law enforcement agencies in identifying additional members of ShinyHunters.
One source said investigators were examining his electronic devices and digital communications as part of efforts to map the group and locate other suspected hackers.
The FBI has not confirmed Khader’s detention or commented specifically on activity in Jordan. However, the bureau said it had already worked with international partners to arrest multiple suspects and would use all available resources to bring those responsible for the cyberattacks to justice.
The latest development follows the arrest in the Netherlands of a 24-year-old Amsterdam man suspected of involvement with ShinyHunters. FBI Director Kash Patel subsequently said investigators were pursuing new leads and warned that further arrests remained possible.

Qantas Data Breach
The Qantas cyberattack began when a caller posing as IT support persuaded an employee at an offshore call centre to connect the airline’s Salesforce customer platform to a malicious data-extraction tool.
The incident allowed hackers to access a large volume of customer information before the airline responded to the breach.
Qantas later confirmed that 5.7 million unique customer records had been compromised. Most affected records contained names, email addresses and frequent-flyer information, while around 1.7 million records also included details such as addresses, dates of birth, telephone numbers and meal preferences.
The airline said passport and credit-card information was not stored on the affected system. Cybersecurity researchers subsequently linked the wider Scattered Lapsus$ Hunters network to the release of millions of Qantas customer records on the dark web.

More Arrests Possible
Khader was previously identified by security journalist Brian Krebs as an administrator of Scattered Lapsus$ Hunters, a loose alliance involving several hacking groups, including ShinyHunters.
Khader had reportedly told Krebs that he wanted to leave the hacking community and had been cooperating with law enforcement since June 2025.
Neither Reuters nor law enforcement authorities have alleged that Khader personally participated in the Qantas cyberattack.
His reported cooperation could nevertheless provide investigators with information about the structure, communications and activities of the wider network.
ShinyHunters has continued to attract international attention after claiming attacks against organisations including Rockstar Games and education platform Canvas,
The group also recently claimed to have stolen information relating to FBI employees, while its dark-web website subsequently went offline after the FBI refused to meet its demands, The Sydney Morning Herald flagged.
Stay tuned with us. Further, follow us on social media for the latest updates.
Join us on Telegram Group for the Latest Aviation Updates. Subsequently, follow us on Google News
