A suspected member of the ShinyHunters extortion group has been detained in Jordan and is cooperating with the FBI, according to Reuters. The man, identified as Saif al-Din Khader and known online as Rey, was taken into custody on Tuesday, two sources told Reuters. He is now helping the FBI and international law enforcement agencies find other members of the group, the sources said.

One source said Khader is walking investigators through his electronic devices and digital communications to identify and locate his alleged co-conspirators. That source described his cooperation as critical to efforts to arrest the hackers. The reported detention follows an FBI crackdown on ShinyHunters after the group attacked the bureau.

In September, ShinyHunters told BleepingComputer it broke into FBI systems using an alleged Oracle PeopleSoft zero-day vulnerability and then moved laterally into FBI-managed AWS GovCloud systems. The group claimed it stole between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, medical and psychiatric records, and internal service records. BleepingComputer said it could not independently verify the zero-day, the lateral movement or the volume of data. The FBI previously confirmed it was investigating claims of unauthorized activity but did not confirm data was stolen.

Dutch police arrested a 24-year-old Amsterdam man on September 15 as part of an investigation into ShinyHunters. KrebsOnSecurity and DataBreaches identified him as Pepijn van der Stap, who had used the alias Umbreon. After that arrest, the FBI publicly urged other ShinyHunters members to surrender, saying investigators were still identifying those involved. FBI Cyber Division Assistant Director Brett Leatherman said arrests change who is willing to talk and seized infrastructure reveals who remains, adding that the bureau knows how to find those still in the group.

The main ShinyHunters representative kept communicating with BleepingComputer after van der Stap's arrest, indicating he was not operating that account. On Tuesday, the same day Khader was reportedly detained, signs of disruption appeared in the ShinyHunters operation. Its data leak site later went offline, and the group's main representative stopped answering questions from media outlets including BleepingComputer and Reuters. It is unclear whether the silence and shutdown are connected to Khader's reported detention. On Thursday, a new ShinyHunters data leak site went online, suggesting other members continue running the extortion operation. BleepingComputer said it contacted ShinyHunters about Rey's reported detention and received no response.

ShinyHunters has long targeted organizations worldwide with large-scale data theft and extortion. In recent years the gang has focused on Salesforce and other cloud SaaS environments, with campaigns linked to breaches at Google, Cisco and PornHub. The group commonly breaches third-party integration companies and uses stolen authentication tokens to reach connected SaaS environments and steal customer data. It was also behind a May data-theft attack on Instructure Canvas that caused significant platform outages; the company eventually reached an agreement with the threat actors to keep the stolen data from being leaked online.

More cybersecurity news from TechManNews.