Security2 publishers2 min readPublished
Alleged ShinyHunters member detained in Jordan is reportedly helping the FBI find other members
Alleged ShinyHunters member Saif al-Din Khader, detained in Jordan on Tuesday, is helping the FBI find other members, two sources told Reuters. A new ShinyHunters leak site went up two days later, suggesting other members still run the extortion.
The Watch · Security desk
What happened
- One source told Reuters that Khader is walking investigators through his electronic devices and digital communications.
- ShinyHunters told BleepingComputer in September that it breached FBI systems through an alleged Oracle PeopleSoft zero-day and moved into FBI-managed AWS GovCloud.
- Dutch police arrested a 24-year-old Amsterdam man on September 15, named by KrebsOnSecurity and DataBreaches as Pepijn van der Stap, alias Umbreon.
- After an alleged affiliate shut down a messaging account on Tuesday, the group's leak site went offline and its main representative stopped answering reporters.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure If the Reuters sources are right, anyone whose handles or chats sit on Khader's devices is now within reach of the FBI and its international partners.
- constraint Organizations already holding ShinyHunters extortion demands still face publication, since the group had a working leak site again within two days.
- precedent Earlier arrests under the ShinyHunters name did not retire it, so the realistic expectation from one cooperating suspect is more arrests while the brand keeps operating.
- decision An arrest leaves the group's entry route, stolen third-party integration tokens into SaaS tenants, in place, so SaaS defenders' priority stays on which connected apps hold tokens to customer data.
Everything known about Khader's role comes from sources who spoke to Reuters without being named [2][3]. "His cooperation is critical to ongoing efforts to arrest these hackers," one of them told Reuters [5]. ShinyHunters did not respond when BleepingComputer asked about the detention [18].
The FBI has said in public how it expects one arrest to lead to the next. After the Amsterdam arrest, the bureau warned remaining members to turn themselves in and said investigators were still identifying who was involved [10]. "Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who's left," Brett Leatherman, assistant director of the FBI Cyber Division, said last week [11]. "I suggest you reach out first while the choice is still yours," he said [12].
The crackdown followed the group's attack on the bureau [23]. Most of what is known about that attack comes from ShinyHunters itself. The group said it took 2TB to 3TB, including records on current and former FBI employees and job applicants, plus medical and psychiatric information [7]. BleepingComputer has not verified the zero-day, the lateral movement or the volume [8]. The FBI has confirmed it is investigating claims of unauthorized activity but has not confirmed that data was stolen [8].
Van der Stap was not the group's public voice. The main representative kept writing to BleepingComputer after the Dutch arrest [13]. Whether this week's silence and shutdowns are tied to Khader is unclear, BleepingComputer reported [16].
The name has outlasted arrests before. Suspects connected to the Snowflake data thefts, the PowerSchool breach and the Breached v2 forum have been arrested in cases linked to ShinyHunters [22]. The group's usual method is to breach a third-party integration company and use its stolen authentication tokens to pull customer data from connected SaaS environments [20]. Recent campaigns centered on Salesforce and other cloud SaaS platforms, and breaches at Google, Cisco and PornHub have been linked to them [19]. In May, its data theft at Instructure Canvas caused platform outages. Instructure later reached an "agreement" with the attackers to keep data from a recent breach off the internet [21].
According to one source, the device review is meant to identify and locate Khader's alleged co-conspirators [4]. Nothing in the reporting mentions victim data.
What to watch
- Jordanian or US confirmation of Khader's detention, or charges or an extradition request naming him.
- Arrests that reach whoever runs the main representative account or the leak site that went up on Thursday.
- Any FBI statement confirming or denying data theft in the claimed PeopleSoft and AWS GovCloud intrusion.