The news
The FBI says it has worked with partners to make multiple ShinyHunters arrests, a spokesperson told The Register in a report published October 5, 2026. Reuters reported that an alleged group member known online as Rey was detained in Jordan and is helping investigators.
Reuters, citing three people familiar with the matter, reported that Jordanian authorities detained Rey in late September, according to The Hacker News. The Register and The Hacker News put the date at September 29; The Record, also citing Reuters, gave September 28. Reuters reported that he is cooperating with the FBI and other agencies to identify and locate other members of the group.
Security journalist Brian Krebs identified Rey in November 2025 as one of three administrators of Scattered LAPSUS$ Hunters, a merger of the Scattered Spider, LAPSUS$ and ShinyHunters crews, The Hacker News reported. The outlet said Rey was earlier an administrator of the Hellcat ransomware group's leak site and, in 2024, took over as administrator of the hacking marketplace BreachForums. The Hacker News reported that he had been working with law enforcement since at least June 2025. Several outlets have published his name; because reports describe him as a teenager, Tech CEO Daily is not. None of the reports we reviewed said he has been charged.
In its statement, the FBI said it continues to investigate aggressively the recent cyber incident allegedly involving ShinyHunters and will spare no resource in bringing those responsible to justice. The spokesperson declined to give details about individual arrests, The Register reported. FBI Director Kash Patel wrote, "More arrests are on the table," according to SecurityWeek and The Hacker News.
That incident is the claimed breach of FBIJobs.gov, the bureau's recruiting portal, in late September. The Register reported that ShinyHunters claimed to have stolen personal details on current, former and prospective FBI employees. SecurityWeek reported that the group claimed to hold 2 to 3 terabytes of data and sent media a sample list of 5,000 FBI employees.
The Jordan detention comes after Dutch police arrested a 24-year-old Amsterdam man on September 15, The Register reported. Krebs and other outlets have identified him as an alleged ShinyHunters leader, and The Record reported that Krebs described a power struggle between the two men for control of the operation. Brett Leatherman, assistant director of the FBI's Cyber Division, said the group allegedly breached more than 140 organizations and took at least $70 million in extortion payments, The Hacker News reported. ShinyHunters did not respond to The Register's questions.
The numbers
- Organizations the group allegedly breached (FBI)
- More than 140
- Extortion payments allegedly collected (FBI)
- At least $70 million
- FBI employees on the sample list sent to media (SecurityWeek)
- 5,000
- Data the group claimed to hold from the FBI hack (SecurityWeek)
- 2 to 3 terabytes
- Age of suspect arrested in Amsterdam on September 15
- 24
Why CEOs should care
For general counsel and CISOs at companies the group has hit or extorted, a cooperating insider changes the timeline. Investigators may soon learn, or already know, which organizations were breached, what data left and whether ransoms were paid. Reports that he had worked with law enforcement since at least June 2025 suggest some of that may already be in hand. Expect contact from the FBI, keep incident records and evidence preserved, and make sure your account of the breach matches what a prosecutor might later lay out in court.
For boards and CFOs, prosecutions can reopen settled questions. Court filings could put a company's name, the size of the theft or a ransom payment on the public record, which may revive customer notices, regulator questions or class action claims. Public companies should ask counsel whether new facts could trigger a fresh materiality review under securities disclosure rules. Know now whether your company paid, how much, and who approved it.
For security teams, arrests do not take stolen data off the market. Copies may still sit with members who are not in custody, and the FBI's own count of more than 140 alleged victims shows how wide the group's reach has been. Keep monitoring for leaked company data, and keep the defenses that matter against this kind of crew, such as phishing-resistant multifactor authentication and tight control of help-desk password resets.
The bigger picture
The case shows how loosely organized these extortion crews are. Scattered LAPSUS$ Hunters is an alliance of three crews, and the teenager in Jordan and the 24-year-old in Amsterdam were reportedly rivals for control, according to Krebs as cited by The Record. The Record listed past victims linked to ShinyHunters, including Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line, 7-Eleven and ADT. The FBI has paired arrests with public pressure: Leatherman urged remaining members to cooperate, The Hacker News reported. If an alleged administrator is now talking, investigators may gain a map of how the group is run.
What’s next
Watch for formal charges or court filings in the United States, Jordan or the Netherlands, any FBI statement naming those arrested, and whether the group's leak site stays active. Companies on its victim list should also watch for law enforcement notifications as investigators work through what the suspects in custody provide.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







