What happened

A suspected member of the ShinyHunters extortion group has been detained in Jordan and is reported to be cooperating with the FBI. The suspect, Saif al-Din Khader, who used the online alias Rey, was taken into custody in late September. Reuters, citing three people familiar with the matter, reported that he is walking investigators through his electronic devices and digital correspondence. One source described his cooperation as critical to ongoing efforts to arrest other members of the group.

The FBI declined to comment on specific arrests, but said it continues to investigate aggressively the recent cyber incident allegedly involving ShinyHunters and has already worked with partners to arrest multiple subjects. Dutch police separately confirmed the arrest of a 24 year old man in Amsterdam. FBI Director Kash Patel said the bureau helped put an alleged leader of the group behind bars, and that more arrests are on the table.

The case follows ShinyHunters' claim that it breached the FBI's job applicant portal through an Oracle PeopleSoft zero day, taking files on current, former and prospective employees, including medical information. The group said the attack was retaliation for an FBI advisory urging victims not to pay ransom, and later said it never intended to publish the data, describing the episode as a marketing campaign rather than an extortion attempt.

Khader is not an unknown quantity to researchers. Brian Krebs identified him last year as one of the administrators of Scattered Lapsus$ Hunters, the umbrella group that includes ShinyHunters, and as a former operator of the Hellcat ransomware leak site and the successor to BreachForums. An FBI cyber division official, Brett Leatherman, said the group and its co-conspirators have allegedly breached more than 140 organisations and taken at least 70 million dollars in extortion payments, often by targeting third party vendors hosted in the cloud.

Why this is a GRC story

Enforcement is part of the risk model. A working assumption for years has been that extortion crews operating across borders face limited consequences. Arrests, seized infrastructure and cooperating insiders change the tempo of the threat, and they also change what an incident response team can say to a victim about likely next steps.

Third party entry keeps being the pattern. The FBI's own account points at vendors and cloud platforms as the way in. Where a supplier risk programme is still a questionnaire sent once a year, it is aimed at the wrong control.

Motive is not always money. This episode was driven by reputation and message control rather than a payment demand, which means a response plan built only around a ransom decision will miss part of the scenario, including who needs to be told and when.

What to watch

Watch whether the FBI confirms the volume and categories of data taken from its own systems, because that determines notification duties and the exposure that follows. Watch, too, whether the arrests produce indictments that name the infrastructure used, since those details are the ones that translate into detection rules for everyone else.

Attribution: Analysis based on Help Net Security and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News