Jordan Detains Suspected ShinyHunters Hacker Who Is Cooperating With the FBI

Reuters’ analysis of a sample provided by ShinyHunters found personally identifiable information, sensitive job-role details, and psychiatric and medical information about FBI employees.
The alleged theft has been compared with the 2015 Office of Personnel Management intrusion, which compromised sensitive information about millions of Americans vetted for security clearances.
Earlier reporting said attackers defaced the FBI jobs site with a fake seizure notice, after which the FBI took its application service and Special Agent Applicant Portal offline while investigating unauthorized activity.
ShinyHunters alleged it exploited an undisclosed Oracle PeopleSoft flaw to gain access to FBI-managed AWS GovCloud systems and download two to three terabytes of data; Oracle, AWS, and the FBI have not confirmed that account of the attack.
Jordanian authorities have detained Saif al-Din Khader, a suspected member of the ShinyHunters hacking group, according to PCMag. The suspect, known online as Rey, is cooperating with the FBI and international law enforcement to identify other members of the group. The detention marks a significant development following ShinyHunters' claim that it stole sensitive data on every FBI employee.
Reuters analysis of data samples from the alleged breach revealed personally identifiable information, sensitive job-role details, and psychiatric and medical records belonging to FBI staff. ShinyHunters claims it exploited an undisclosed Oracle PeopleSoft vulnerability to access FBI systems and download two to three terabytes of data, though Oracle, AWS, and the FBI have not confirmed this account.
ShinyHunters alleged it breached FBI systems and accessed sensitive employee records. The group claimed it exploited a flaw in Oracle PeopleSoft software to reach FBI-managed AWS GovCloud systems. Cybernews reports the breach allegedly yielded two to three terabytes of data. The FBI has launched an investigation with international partners but has not independently confirmed the group's claims or the extent of any breach.
The stolen information included personally identifiable information and psychiatric and medical records of FBI employees, Reuters confirmed by analyzing a data sample. The breach has drawn comparisons to the 2015 Office of Personnel Management intrusion, which compromised sensitive information on millions of Americans cleared for security clearances. The FBI took its jobs application site and Special Agent Applicant Portal offline after attackers posted a fake seizure notice.
PCMag reports that Saif al-Din Khader was detained in Jordan on suspicion of ShinyHunters membership. His online alias is Rey. The suspect is now cooperating with the FBI and other law-enforcement agencies to help locate and identify other alleged group members. His exact whereabouts and detention circumstances remain unclear.
Security Affairs states that Khader is assisting the FBI in tracking down other members of the ShinyHunters group. The FBI said it has already helped arrest multiple suspects linked to ShinyHunters through work with international partners. The cooperation suggests authorities are pursuing a wider investigation into the hacking group's operations and membership.
ShinyHunters claims it exploited an undisclosed Oracle PeopleSoft vulnerability to compromise FBI systems. The group says it used this flaw to access FBI-managed AWS GovCloud infrastructure. However, Oracle, AWS, and the FBI have not publicly confirmed this technical account or verified the attack method.
The discrepancy between ShinyHunters' claims and official confirmations leaves key questions unanswered. It remains unclear whether the vulnerability was real, how access was actually gained, or the true scope of any data exfiltration. The FBI's investigation with international partners is ongoing, but public details about the attack's mechanics remain limited.
Publishers
17
Articles
37
Reach
54