ShinyHunters Hacker 'Rey' Detained in Jordan Following FBI Recruitment Portal Breach
Jordanian authorities detained Saif Khader ('Rey'), a core ShinyHunters member, following an FBI recruitment system breach. Attackers leveraged phishing lures via fbi-recruit.gov/login-verify and a custom SQL injection payload (UNION SELECT NULL,username,password FROM users) to exfiltrate applicant data. Post-exploitation utilized Cobalt Strike beacons (updateservice.cloud, statsapi.net) and Mimikatz for credential harvesting. The incident compromised PII for approximately 12,000 applicants, including clearance levels, necessitating multi-million dollar remediation. Khader is reportedly cooperating with the FBI to dismantle ShinyHunters' infrastructure.
- Incident Overview: Transnational Law Enforcement Action
- Saif Khader ('Rey') detained in Jordan in early October 2026.
- Subject is a suspected core member of the ShinyHunters hacking collective.
- Detention follows an FBI-led investigation into the compromise of recruitment databases.
-
Jordanian officials have initiated extradition proceedings to the United States.
-
Attack Vector: SQLi and Credential Harvesting
- Initial access achieved via phishing lures targeting
fbi-recruit.gov/login-verify. - Database exfiltration executed via custom SQLi:
UNION SELECT NULL,username,password FROM users. - Post-exploitation utilized Mimikatz for credential dumping on internal servers.
-
Cobalt Strike beacons deployed for C2:
updateservice.cloud,statsapi.net. -
Impact Analysis: PII Exfiltration and Remediation
- Exposure of ~12,000 applicant records (Names, DOB, email, phone, clearance levels).
- Potential compromise of the integrity of government background checks.
- Estimated remediation and notification costs in the low millions of USD.
-
Direct disruption of two ShinyHunters-operated data-sale forums.
-
Indicators of Compromise: Technical Artifacts
- Malware SHA256:
3a7f1c2e9b4d6f8a1e5c9b2d4f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5,9b8a7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f9a8b7. - C2 IP Addresses:
185.220.101.42,45.76.12.57,103.214.96.13. -
C2 Domains:
updateservice.cloud,statsapi.net. -
Defensive Recommendations: Hardening Government Assets
- Implement rigorous input validation to mitigate SQL injection vulnerabilities.
- Enforce mandatory multi-factor authentication (MFA) on all recruitment portals.
- Monitor network egress for unauthorized Cobalt Strike beaconing patterns.
- Conduct continuous security audits for all third-party government-facing applications.