Key ShinyHunters Hacker Detained in Jordan as FBI Cooperation Proceeds
Saif al-Din Khader, a member of the ShinyHunters hacking group, is cooperating with the FBI following his detention in Jordan.
By Muhamed Porić
October 9, 2026 at 4:21 PM

Saif al-Din Khader, a member of the ShinyHunters hacking collective, was detained in Jordan this week. He is currently working with the FBI to identify other members of the group. His apprehension marks progress in the federal investigation into recent breaches targeting the bureau's internal systems.
"His cooperation is critical to ongoing efforts to arrest these hackers," a source familiar with the investigation said regarding the development.
Investigating the Breach
ShinyHunters previously claimed responsibility for infiltrating FBI networks. They alleged they successfully exfiltrated between 2 and 3 terabytes of sensitive data pertaining to bureau personnel. The group reportedly utilized a vulnerability within Oracle PeopleSoft software to gain unauthorized access to the systems.
In response to the incident, the FBI has intensified its cross-border pursuit of the individuals involved. The bureau confirmed it is leveraging international partnerships to secure arrests.
"The Bureau continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects, and we will spare no resource in bringing each of the responsible individuals to justice," the FBI said in a statement.
Broadening Global Enforcement
Khader’s detention follows the arrest of another suspected member, Pepijn van der Stap, who was taken into custody in the Netherlands on September 15. That arrest occurred prior to the public disclosure of the FBI breach, indicating a coordinated, multi-jurisdictional effort to dismantle the hacking operation.
Why This Matters for Cybersecurity
The ShinyHunters group has focused on data theft, targeting corporate and government databases to sell or leak information. By securing the cooperation of a core member like Khader, federal investigators gain access to the group's internal hierarchy, communication methods, and potential future targets. This shift from reactive defense to active prosecution changes how the U.S. government addresses organized cyber-criminal threats.
Muhamed Porić
Founder and Editor of Embers.
Newsletter
Get Embers in your inbox
The stories that actually moved something, delivered when there's something worth sending, not daily filler.