ShinyHunters Member Arrested in Jordan, Aiding FBI
Saif al-Din Khader, detained in Jordan, is cooperating with the FBI over a major breach linked to ShinyHunters, the second arrest in the group within a week.

An alleged ShinyHunters group member has been detained in Jordan and is cooperating with the FBI, according to reporting by The Record and SecurityWeek published Monday. The individual, Saif al-Din Khader, is reportedly assisting the bureau in response to a large-scale breach that exposed employee data. SecurityWeek describes Khader as an alleged leader of the group; The Record identifies him as a member.
This is the second arrest tied to ShinyHunters in less than a week. Dutch police arrested an alleged ShinyHunters leader on September 29, after which the FBI issued a public warning to remaining members to turn themselves in. Two arrests in different countries within days of each other is a pressure pattern, not coincidence.
What cooperation means in practice
Federal cooperation agreements in cybercrime cases are not general admissions. They require specific disclosures: identities of co-conspirators, infrastructure details, or access to accounts and systems. The fact that Khader is cooperating and not contesting the arrangement suggests the FBI had enough evidence to make cooperation the better option. Whether Khader’s information is operational or organizational depends on his actual role, which the public reporting does not confirm.
ShinyHunters has operated with distributed membership across multiple jurisdictions throughout 2026. The group’s activities have included the PeopleSoft exploitation campaigns we tracked through September, a series of high-volume data thefts targeting healthcare and financial services, and the claimed breach of FBI systems via an Oracle PeopleSoft zero-day that the bureau has neither confirmed nor denied. If Khader’s cooperation is tied to that incident, the investigation extends further than a single extortion case.
The arrest sequence
Law enforcement pressure on extortion groups tends to follow a recognizable arc: start with participants whose exposure is highest, use cooperation to surface others, move up. Operation KillSwitch’s takedown of KillSec infrastructure on October 2 followed the same pattern. ShinyHunters has absorbed individual arrests before without visible operational disruption. The Dutch arrest did not halt the group’s September campaigns; whether two arrests plus active cooperation changes the calculus depends on what Khader can actually provide.
ShinyHunters’ most recent public activity, per our coverage through late September, involved continued PeopleSoft exploitation and victim extortion. Any disruption to those operations would likely show up in reduced victim communications or shifts in the group’s leak-site activity over the coming weeks.
No charges have been publicly filed in connection with the Jordan arrest as of this writing. The Record and SecurityWeek are the sourcing basis for this report. This story is developing.
Found this useful? Share it.


