Jordanian Authorities Detained Teen in Cyber Extortion Probe

A 16-year-old suspect is assisting the FBI in an ongoing investigation into the digital extortion group ShinyHunters.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration of a severe, heavy concrete building facade representing institutional power and the global cyber extortion investigation.
Jordanian authorities have detained a 16-year-old suspect linked to the ShinyHunters extortion group, who is now assisting the FBI with a major international investigation. AI Illustration. Upload story photo >

Live Poll

Should nations extradite suspected cybercriminals to face charges in other countries?

Jordanian authorities have detained 16-year-old Saif al-Din Khader, who is suspected of being a member of the digital extortion group ShinyHunters. Khader is currently assisting the FBI with an investigation into the group, which has been linked to data breaches at more than 140 organizations.

Why it matters

The case highlights the growing threat of sophisticated digital extortion groups that exploit misconfigured platforms to steal sensitive data and extort high-profile organizations. The FBI has attributed at least $70 million in ransom payments to the group's operations.

ShinyHunters compromised over 140 organizations by exploiting Oracle PeopleSoft software and pivoting to Amazon Web Services GovCloud. The group reportedly stole 2 terabytes of data from the FBI in a single intrusion.

The players

Saif al-Din Khader

He is a 16-year-old suspect accused of operating under the aliases Rey and ReyXB for the digital extortion group ShinyHunters.

ShinyHunters

This is a digital extortion organization known for targeting misconfigured or vulnerable platforms to steal data and demand ransom payments.

FBI

The Federal Bureau of Investigation is the primary U.S. law enforcement agency currently investigating the activities of the ShinyHunters group.

Hellcat

This is a ransomware group that allegedly utilized the suspect as an administrator during its extortion operations.

The details

Khader, known by the aliases Rey and ReyXB, allegedly participated in the disruption of Jaguar Land Rover and served as an administrator for the Hellcat ransomware group. Members of the organization gain initial access by performing voice phishing, where they impersonate employees to help desks.

Timeline

  1. 1995: The United States and Jordan signed an extradition treaty.

  2. August 2025: A cyber disruption targeted Jaguar Land Rover.

  3. September 15, 2026: A Dutch suspect was arrested in Amsterdam.

  4. September 22, 2026: ShinyHunters announced a successful hack against the FBI.

  5. September 30, 2026: Saif al-Din Khader was detained by Jordanian authorities.

The Tech Race

This arrest reflects the increasing difficulty global law enforcement agencies face in tracking decentralized digital extortion syndicates. These groups are systematically replacing traditional hacking methods with sophisticated voice phishing to bypass corporate security layers.

Users should be aware that organizations often fall victim to attackers who impersonate employees via phone to gain access to corporate systems. Companies are increasingly adopting multi-factor authentication and stricter help desk verification to mitigate these phishing risks.

The takeaway

Digital extortion groups rely on human vulnerabilities like voice phishing as much as technical flaws in software. Maintaining rigorous verification processes at corporate help desks is a critical defense against such attacks.

Further reading

For more information on current digital threats, visit our Cybersecurity section.

Source note: This article includes information reported by BankInfoSecurity.

Live Poll

Should nations extradite suspected cybercriminals to face charges in other countries?