Back to Newsroom
Threat Intel

ShinyHunters Suspect Detained in Jordan, Now Cooperating With FBI

A suspect linked to the ShinyHunters extortion crew was taken into custody in Jordan and is reportedly helping investigators identify other members, as the FBI signals more arrests are coming.

ShinyHunters Suspect Detained in Jordan, Now Cooperating With FBI

A suspected administrator of the ShinyHunters extortion crew, known online as "Rey," has been detained in Jordan and is reportedly cooperating with the FBI to help identify other members of the group.

What happened

According to multiple sources familiar with the matter, the individual — who also went by the alias ReyXBF — was taken into custody in Jordan in late September 2026 and is now said to be working with U.S. federal investigators. The suspect has previously been linked to roles inside several high-profile extortion operations, including administering a ransomware group's leak site in 2024 and later helping run one of the best-known stolen-data marketplaces. Independent researchers have also tied the alias to a broader alliance that fuses together several well-known extortion-focused crews, and the suspect is reported to have been quietly cooperating with law enforcement since mid-2025.

The detention follows the arrest, just a week earlier, of another individual connected to the same network — reportedly a security professional with a past in the hacking scene who has since denied any current involvement with the group.

U.S. officials have been vocal about the momentum. The FBI has indicated that more arrests are expected as it works through leads generated by recent detentions, and a senior bureau official detailed the network's toll: more than 140 organizations breached and upwards of $70 million taken in extortion payments since last year alone, largely by compromising third-party vendors hosted on cloud platforms.

Why it matters

Extortion brands like this one don't rely on a single leader — they function as a loose, modular supply chain, where social engineers obtain initial access, other actors handle amplification and recruitment, and a separate layer manages monetization. That structure is exactly why arrests alone rarely shut a brand down; this one has absorbed indictments, detentions, and forum takedowns for years without going quiet for long.

For organizations, the headline isn't "one hacker was caught" — it's that cloud-hosted third-party platforms remain the preferred entry point for this ecosystem, and cooperation from detained members can expose infrastructure, tooling, and partner relationships that were previously hidden, potentially accelerating enforcement against the group's remaining operators.

What to do

  • Audit third-party and SaaS integrations. Crews tied to this network have repeatedly targeted cloud-hosted platforms and vendor integrations rather than attacking victims directly — review which third parties can touch your data and tighten access scopes.
  • Assume credential and session reuse. Review conditional access policies, rotate API tokens for cloud platform integrations, and enforce MFA everywhere a vendor connection touches sensitive data.
  • Watch for extortion attempts referencing stolen data, even without a prior breach notification — groups in this ecosystem are known to pressure victims directly before any public leak.
  • Monitor threat intelligence feeds for indicators tied to this network as law enforcement pressure increases — cooperating suspects often trigger a wave of rapid infrastructure changes among the remaining members.
SHARE