← Back to Daily Briefing

ShinyHunters Hacker 'Rey' Detained in Jordan Following FBI Recruitment Portal Breach

Published October 3, 2026

Jordanian authorities detained Saif Khader ('Rey'), a core ShinyHunters member, following an FBI recruitment system breach. Attackers leveraged phishing lures via fbi-recruit.gov/login-verify and a custom SQL injection payload (UNION SELECT NULL,username,password FROM users) to exfiltrate applicant data. Post-exploitation utilized Cobalt Strike beacons (updateservice.cloud, statsapi.net) and Mimikatz for credential harvesting. The incident compromised PII for approximately 12,000 applicants, including clearance levels, necessitating multi-million dollar remediation. Khader is reportedly cooperating with the FBI to dismantle ShinyHunters' infrastructure.

  • Incident Overview: Transnational Law Enforcement Action
  • Saif Khader ('Rey') detained in Jordan in early October 2026.
  • Subject is a suspected core member of the ShinyHunters hacking collective.
  • Detention follows an FBI-led investigation into the compromise of recruitment databases.
  • Jordanian officials have initiated extradition proceedings to the United States.

  • Attack Vector: SQLi and Credential Harvesting

  • Initial access achieved via phishing lures targeting fbi-recruit.gov/login-verify.
  • Database exfiltration executed via custom SQLi: UNION SELECT NULL,username,password FROM users.
  • Post-exploitation utilized Mimikatz for credential dumping on internal servers.
  • Cobalt Strike beacons deployed for C2: updateservice.cloud, statsapi.net.

  • Impact Analysis: PII Exfiltration and Remediation

  • Exposure of ~12,000 applicant records (Names, DOB, email, phone, clearance levels).
  • Potential compromise of the integrity of government background checks.
  • Estimated remediation and notification costs in the low millions of USD.
  • Direct disruption of two ShinyHunters-operated data-sale forums.

  • Indicators of Compromise: Technical Artifacts

  • Malware SHA256: 3a7f1c2e9b4d6f8a1e5c9b2d4f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5, 9b8a7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f9a8b7.
  • C2 IP Addresses: 185.220.101.42, 45.76.12.57, 103.214.96.13.
  • C2 Domains: updateservice.cloud, statsapi.net.

  • Defensive Recommendations: Hardening Government Assets

  • Implement rigorous input validation to mitigate SQL injection vulnerabilities.
  • Enforce mandatory multi-factor authentication (MFA) on all recruitment portals.
  • Monitor network egress for unauthorized Cobalt Strike beaconing patterns.
  • Conduct continuous security audits for all third-party government-facing applications.

LINK COPIED TO CLIPBOARD