Thehackernews ShinyHunters Suspect Rey Detained in Jordan, Assisting FBI Investigation
Article Content
- •Saif al-Din Khader, alias 'Rey', detained in Jordan and assisting FBI investigations.
- •ShinyHunters breached the FBI Jobs portal, stealing 2TB to 3TB of sensitive data.
- •FBI confirms ongoing investigations and multiple arrests related to ShinyHunters.
Saif al-Din Khader, known as 'Rey', a suspected member of the ShinyHunters hacking group, was detained in Jordan on September 29, 2026. He is reportedly cooperating with the FBI to identify other group members following a significant breach involving the theft of sensitive FBI personnel data. The breach, which occurred in September 2026, involved the FBI Jobs portal, where ShinyHunters claimed to have stolen between 2TB and 3TB of data, including personally identifiable information and medical records. The FBI has confirmed ongoing investigations and has previously arrested multiple suspects linked to ShinyHunters. Khader's involvement with the group has been documented since at least November 2025, and he has been publicly taunting law enforcement. The FBI has not confirmed the full extent of the data breach but has instructed staff to assume potential exposure of all employees.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track HellCat, FBI and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data was stolen in the breach?
What is the current status of the investigation?
How has the FBI responded to the breach?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…