Cybersecurity

ShinyHunters Suspect Rey Detained: What It Means for You

A ShinyHunters admin known as Rey is reportedly in custody and cooperating with the FBI. Here is what the arrest means for companies still exposed to data extortion.

Ravi Shanker SinghFounder & Odoo ConsultantPublished 4 min read
Share
ShinyHunters Suspect Rey Detained: What It Means for You
On this page

ShinyHunters suspect Rey detained is the headline this week, and it is the latest sign that the extortion group ShinyHunters is under real pressure, not just media attention. According to Reuters, as cited by The Hacker News, a suspect known online as "Rey" (real name Saif al-Din Khader) was detained on September 29, 2026. He is reportedly cooperating with the FBI to identify other members of the group. For business owners and IT leaders who have watched ShinyHunters-linked breaches pile up over the past two years, this matters less as crime drama. It matters more as a signal about how these groups operate and where your own exposure likely sits.

ShinyHunters Suspect Rey Detained: What Actually Happened

Rey, also known by the alias ReyXBF, was named in a November 2025 report by security journalist Brian Krebs. He was identified as one of three administrators of Scattered LAPSUS$ Hunters, a coalition widely seen as a merger of Scattered Spider, LAPSUS$, and ShinyHunters. He had prior roles running the leak site for the Hellcat ransomware crew. He later administered a revived version of BreachForums. Khader told Krebs he had been cooperating with law enforcement since at least June 2025.

This detention follows last week's arrest of a 24-year-old in Amsterdam, separately reported to be Pepijn van der Stap. He had been working as an offensive security lead at a Dutch security firm before his arrest. FBI Director Kash Patel and cyber division assistant director Brett Leatherman both signaled that more arrests are likely. Leatherman noted the group is believed to have breached more than 140 organizations and extracted at least $70 million in extortion payments since last year.

Why This Group Keeps Coming Back

Researchers at Sekoia and Beazley Security describe ShinyHunters as less a fixed group and more a brand and business model. It traces back to earlier crews like TheDarkOverlord and GnosticPlayers. The structure is modular: social engineers get initial access, other actors amplify and recruit, and monetization happens under a shared, recognizable name. That division of labor explains why individual arrests, even significant ones, rarely shut the operation down. Someone else picks up the leak site or the extortion negotiation within days.

This changes how you should think about defense. You are not defending against one adversary with one attack pattern. You are defending against a loose network that reuses techniques, buys access from brokers, and targets the weakest point in a supply chain rather than the strongest.

Why the Rey Arrest Matters for Your Business

Three details from this story should change how a CFO or IT director prioritizes budget this quarter.

  • Third-party and cloud platforms are the preferred entry point. Leatherman specifically called out that the group targets third-party vendors inside cloud platforms, then extorts the downstream customers whose data was exposed. If your CRM, SaaS helpdesk, or data warehouse vendor gets breached, your customer data can end up on a leak site even though your own systems were never touched.
  • Unpatched CMS and portal flaws are still the easy way in. The group reportedly hijacked a rival's darknet site by exploiting an unpatched Grav CMS flaw, and separately pulled data from a federal jobs portal. Patch cadence on public-facing web applications remains a basic, unglamorous control that keeps paying off.
  • Extortion is increasingly about leverage, not just money. ShinyHunters claims its FBI-related intrusion was about pressuring the agency over public statements, not a payout. That should worry companies that assume a "we don't negotiate" policy makes them a less attractive target. Reputational and political leverage can matter as much as ransom.

Concrete Steps to Take This Month

Companies do not need to wait for a breach notification to act on this news. A few practical moves:

  1. Inventory every third-party vendor with access to customer data, and ask each one directly about its patch cycle and breach history.
  2. Review access logs and offboarding procedures for cloud admin accounts. Social engineering and SIM swapping remain the group's preferred entry techniques.
  3. Confirm your incident response plan names a specific person authorized to engage law enforcement and legal counsel within hours, not days.
  4. Run a tabletop exercise assuming the breach originates from a vendor, not your own network.

If you are rebuilding parts of your stack after a vendor-related exposure, our cybersecurity services team can walk through hardening API and cloud access points without disrupting daily operations. For companies that rely on integrated platforms like Odoo for finance and customer data, our API integration services and Odoo ERP support services teams also handle access reviews and least-privilege configuration as part of ongoing support. ERP systems are often the richest single target in a company's stack, and a vendor review is a good moment to also check your Odoo consultancy services engagement for open integration points.

A Limitation Worth Naming

Arrests and cooperation deals generate headlines, but they rarely produce durable deterrence against a brand-based crime model like this one. Even if Rey's cooperation leads to more arrests, the "ShinyHunters" name and infrastructure can be picked up by new operators. BreachForums itself was revived more than once after prior takedowns. Treat this news as a temporary disruption, not a resolution. Keep your own controls as the primary defense rather than relying on law enforcement timelines.

What to Watch Next

Expect further disclosures tied to this investigation, including possible identification of additional Scattered LAPSUS$ Hunters members. There may also be clarification of the group's claimed links to The Com, the broader cybercrime collective associated with SIM swapping and physical-world extortion tactics. If your company handles sensitive customer or financial data through any cloud vendor, now is a reasonable time to request updated SOC 2 or penetration test evidence from that vendor rather than waiting for the next headline.

Share

Frequently asked questions

Who is the ShinyHunters suspect Rey that was reportedly detained?

Rey, whose real name is reported as Saif al-Din Khader, is a suspected administrator of Scattered LAPSUS$ Hunters, a coalition tied to ShinyHunters, LAPSUS$, and Scattered Spider. He previously ran leak infrastructure for the Hellcat ransomware group and a revived version of BreachForums.

Does the arrest mean ShinyHunters attacks will stop?

Not necessarily. Researchers describe ShinyHunters as a brand and business model with a modular structure, meaning other members or affiliates can continue operations even after key figures are arrested or cooperate with authorities.

What industries does ShinyHunters typically target?

The FBI has stated the group frequently targets third-party vendors operating on cloud-based platforms, then extorts the downstream companies whose customer data was exposed through that vendor relationship, rather than always attacking victims directly.

What should a company do right now in response to this news?

Review which vendors hold your customer or financial data in the cloud, confirm their patch and breach history, tighten cloud admin access controls, and make sure your incident response plan names who contacts law enforcement and counsel immediately after a suspected breach.

Is ShinyHunters primarily motivated by money?

Usually yes, with reports citing at least $70 million in extortion payments since last year, but the group has also claimed non-monetary motives in at least one case, using stolen data as leverage to pressure an agency over public statements rather than seeking payment.

Sources

About the author

Ravi Shanker Singh

Founder & Odoo Consultant

Founder of Tech After Me and Odoo consultant. Ravi implements, customises and supports Odoo ERP and builds web, mobile and data products for companies in Thailand, the USA and India, working from Bangkok, New York and Delhi NCR.

More from this author

Keep reading

Put what you read into practice

The team writing these guides is the same team that ships them. Tell us what you are working on.

Get new articles in your inbox

Get new articles in your inbox

Odoo guides and IT news that matter to your business. At most one email a week.