Skip to content
TECH CEO Daily

FBI confirms multiple ShinyHunters arrests as alleged member Rey reportedly aids probe

Reuters reported that a teenager known as Rey was detained in Jordan and is helping the FBI, which says the extortion group allegedly hit more than 140 organizations.

By · Editor

· 4 min read · Fact-checked

The 60-second brief

  • 1An FBI spokesperson said the bureau has worked with partners to arrest multiple subjects in its ShinyHunters investigation.
  • 2Reuters reported that Rey, an alleged ShinyHunters member, was detained in Jordan in late September and is cooperating with the FBI.
  • 3The FBI says the group allegedly breached more than 140 organizations and collected at least $70 million in extortion payments.

The news

The FBI says it has worked with partners to make multiple ShinyHunters arrests, a spokesperson told The Register in a report published October 5, 2026. Reuters reported that an alleged group member known online as Rey was detained in Jordan and is helping investigators.

Reuters, citing three people familiar with the matter, reported that Jordanian authorities detained Rey in late September, according to The Hacker News. The Register and The Hacker News put the date at September 29; The Record, also citing Reuters, gave September 28. Reuters reported that he is cooperating with the FBI and other agencies to identify and locate other members of the group.

Security journalist Brian Krebs identified Rey in November 2025 as one of three administrators of Scattered LAPSUS$ Hunters, a merger of the Scattered Spider, LAPSUS$ and ShinyHunters crews, The Hacker News reported. The outlet said Rey was earlier an administrator of the Hellcat ransomware group's leak site and, in 2024, took over as administrator of the hacking marketplace BreachForums. The Hacker News reported that he had been working with law enforcement since at least June 2025. Several outlets have published his name; because reports describe him as a teenager, Tech CEO Daily is not. None of the reports we reviewed said he has been charged.

In its statement, the FBI said it continues to investigate aggressively the recent cyber incident allegedly involving ShinyHunters and will spare no resource in bringing those responsible to justice. The spokesperson declined to give details about individual arrests, The Register reported. FBI Director Kash Patel wrote, "More arrests are on the table," according to SecurityWeek and The Hacker News.

That incident is the claimed breach of FBIJobs.gov, the bureau's recruiting portal, in late September. The Register reported that ShinyHunters claimed to have stolen personal details on current, former and prospective FBI employees. SecurityWeek reported that the group claimed to hold 2 to 3 terabytes of data and sent media a sample list of 5,000 FBI employees.

The Jordan detention comes after Dutch police arrested a 24-year-old Amsterdam man on September 15, The Register reported. Krebs and other outlets have identified him as an alleged ShinyHunters leader, and The Record reported that Krebs described a power struggle between the two men for control of the operation. Brett Leatherman, assistant director of the FBI's Cyber Division, said the group allegedly breached more than 140 organizations and took at least $70 million in extortion payments, The Hacker News reported. ShinyHunters did not respond to The Register's questions.

The numbers

Organizations the group allegedly breached (FBI)
More than 140
Extortion payments allegedly collected (FBI)
At least $70 million
FBI employees on the sample list sent to media (SecurityWeek)
5,000
Data the group claimed to hold from the FBI hack (SecurityWeek)
2 to 3 terabytes
Age of suspect arrested in Amsterdam on September 15
24

Why CEOs should care

For general counsel and CISOs at companies the group has hit or extorted, a cooperating insider changes the timeline. Investigators may soon learn, or already know, which organizations were breached, what data left and whether ransoms were paid. Reports that he had worked with law enforcement since at least June 2025 suggest some of that may already be in hand. Expect contact from the FBI, keep incident records and evidence preserved, and make sure your account of the breach matches what a prosecutor might later lay out in court.

For boards and CFOs, prosecutions can reopen settled questions. Court filings could put a company's name, the size of the theft or a ransom payment on the public record, which may revive customer notices, regulator questions or class action claims. Public companies should ask counsel whether new facts could trigger a fresh materiality review under securities disclosure rules. Know now whether your company paid, how much, and who approved it.

For security teams, arrests do not take stolen data off the market. Copies may still sit with members who are not in custody, and the FBI's own count of more than 140 alleged victims shows how wide the group's reach has been. Keep monitoring for leaked company data, and keep the defenses that matter against this kind of crew, such as phishing-resistant multifactor authentication and tight control of help-desk password resets.

The bigger picture

The case shows how loosely organized these extortion crews are. Scattered LAPSUS$ Hunters is an alliance of three crews, and the teenager in Jordan and the 24-year-old in Amsterdam were reportedly rivals for control, according to Krebs as cited by The Record. The Record listed past victims linked to ShinyHunters, including Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line, 7-Eleven and ADT. The FBI has paired arrests with public pressure: Leatherman urged remaining members to cooperate, The Hacker News reported. If an alleged administrator is now talking, investigators may gain a map of how the group is run.

What’s next

Watch for formal charges or court filings in the United States, Jordan or the Netherlands, any FBI statement naming those arrested, and whether the group's leak site stays active. Companies on its victim list should also watch for law enforcement notifications as investigators work through what the suspects in custody provide.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

ShinyHuntersFBIScattered LAPSUS$ HuntersData extortion

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.