Alleged Shiny Hunters Leader Arrested in Jordan
Alleged ShinyHunters Leader Arrested in Jordan A suspect linked to the ShinyHunters extortion group has been detained in Jordan and is assisting the FBI with its investigation.
The individual, identified as Saif al-Din Khader, also known by the alias Rey, is a young cybercriminal from Amman who has also been associated with the Scattered Lapsus$ Hunters collective. Authorities have not disclosed the exact location of his detention. The arrest occurred following the group’s recent breach of the FBI’s public job portal, FBIJobs.gov, which was defaced to assert the theft of 2-3 terabytes of data. ShinyHunters reportedly shared a sample list containing details of 5,000 FBI employees, claiming to possess personal and medical information for all current and former FBI personnel. In parallel, Dutch law enforcement apprehended a 24-year-old suspect in Amsterdam as part of the FBI’s probe into ShinyHunters. The FBI confirmed the arrest, stating the individual was implicated in hacking over 140 organizations and facilitating at least $70 million in extortion payments. While Dutch authorities and the FBI have not disclosed the suspect’s identity, independent reports indicate the person is Pepijn van der Stap, a hacker convicted in 2023 for cyberattacks and extortion. He was serving a three-year sentence before being released on supervised probation. Khader allegedly attributed the FBI breach to van der Stap by deploying a defacement image featuring the Pokémon character Umbreon, a nickname van der Stap used in prior extortion activities, as reported by investigative journalist Brian Krebs.
The investigation continues as law enforcement agencies work to dismantle the group’s operations and recover stolen data. Additional developments in the cybersecurity landscape include the disruption of the KillSec ransomware operation and the identification of an alleged teenage leader. Meanwhile, the U.S. Treasury has targeted a prominent ATM malware developer and his network. Other recent threats involve the exploitation of vulnerabilities in Fortinet FortiMail, Zimbra, and WatchGuard systems, with urgent patches recommended. A zero-day in Citrix NetScaler was exploited before public disclosure, and a critical flaw in Cisco Catalyst SD-WAN devices was addressed. Security professionals are also monitoring the expansion of SharePoint exploitation by the Warlock group, as well as AI-driven attacks leveraging zero-days in Zammad. Over 500,000 exposed credentials were discovered on GitHub, prompting warnings about insecure code practices. Updates to Chrome and Firefox have resolved more than 100 vulnerabilities, while a critical code injection flaw in WatchGuard Fireware was patched. In related news, the Trump administration has appointed Jay Clayton as the new national intelligence director to lead a federal AI task force. Meanwhile, cybersecurity firms are addressing emerging risks through advanced threat detection and proactive mitigation strategies.
