Interestana
Home/News/Teen Hacker 'Rey' Detained, Cooperates With FBI
Krebs on Security••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Teen Hacker 'Rey' Detained, Cooperates With FBI

Teen Hacker 'Rey' Detained, Cooperates With FBI

A teenager from Amman, Jordan, identified by the hacker handle “Rey” and suspected of leading the prolific data theft and extortion group ShinyHunters, has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity learned that the suspect, whose real name is Saif Al-din Khader, was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing. This business unit is Jeppesen ForeFlight, which Boeing divested last year. Notably, the employer of Rey’s father, Royal Jordanian Airlines, uses Boeing aircraft, creating a potential conflict of interest or leverage point. Reuters cited three unnamed sources on October 3, confirming that a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity had previously identified Rey as Khader in a November 2025 profile, where the young man admitted to working with multiple ransomware groups. Rey was also featured in a September 28 exclusive report detailing the Dutch police's arrest of 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding in data thefts and extortions by ShinyHunters. The September 28 report indicated that immediately following Van Der Stap’s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand. He publicly boasted about stealing highly sensitive data from the FBI and extorting the ransomware group Cl0p. Rey taunted both the FBI and Cl0p with memes posted to his Twitter/X account. In an apparent attempt to frame Van Der Stap, Rey simultaneously included images of the avatar used by Van Der Stap’s former hacker alias, “Umbreon,” in these taunting posts. The September 28 report also noted that ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability identified as CVE-2026-35273 in the PeopleSoft enterprise software. This vulnerability is a critical security flaw that allowed unauthorized access to sensitive information. The detention of Rey and his reported cooperation with the FBI represent a significant development in the ongoing efforts to dismantle sophisticated cybercriminal organizations like ShinyHunters, which have been responsible for numerous high-profile data breaches and extortion schemes.

Original source — read the full reporting at the publisher:

Read on Krebs on Security

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next