Cybersecurity · Sunday, 4 October 2026
A suspected ShinyHunters hacker is detained in Jordan and is helping the FBI find the rest of the gang
Jordan detained Saif al-Din Khader, known as Rey, a suspected member of the gang that says it stole data on almost every FBI agent. Sources say he is opening his devices to the FBI, and the gang's leak site went offline.
about 38,000
FBI staff the gang says it holds data on
An internal FBI memo says officials are working on the basis that every employee was exposed.
2
suspected members whose detention has been reported
One in the Netherlands on 15 September, one in Jordan on 29 September.
2-3 TB
of data ShinyHunters claims it took from the FBI
BleepingComputer, a security news site, has not been able to check that figure.
The lead story — what happened
-
Jordanian authorities detained Saif al-Din Khader, a suspected member of the ShinyHunters hacking gang, this week, three people told Reuters, the news agency.
[1] -
Two of them said he was taken into custody on Tuesday 29 September, and that he is now helping the FBI, the US federal police, find the gang's other members.
[1] -
One source said he is walking investigators through his devices and his messages to point them to the others.
[1] [2] -
Khader's alleged online name is Rey. Last year he told the journalist Brian Krebs that he had quit crime and was helping the police.
[1] -
ShinyHunters is a gang that steals company data and demands money not to publish it. In September it said it had taken data on almost every FBI agent.
[3] -
It said it attacked the FBI's jobs website to make the bureau withdraw a May warning about the gang. That warning is still online.
[3] [4] -
A Reuters check of a sample found personal details, job roles, and medical and psychiatric records of FBI staff.
[1] -
On Tuesday the account the gang used to talk to reporters went silent. On Wednesday its leak website went offline.
[1] -
A new ShinyHunters leak site went online on Thursday, which suggests other members are still running the gang.
[2] -
In its latest email to Reuters, the gang said it wants no further escalation with the FBI.
[1] -
Dutch police arrested a 24-year-old Amsterdam man in the same case on 15 September. They say his laptop held details of two murders planned abroad.
[6] [5] -
FBI Director Kash Patel wrote on Wednesday that his teams are working new leads and more arrests are on the table.
[1]
Who is involved
-
Saif al-Din Khader ("Rey")
a suspected ShinyHunters member; detained in Jordan, and sources say he is helping the FBI
-
ShinyHunters
a gang, mostly young English speakers, that steals company data and demands money; says it took data on almost all FBI agents
-
The FBI
the US federal police; investigating the break-in and asking gang members to come forward
-
Dutch police
the national police of the Netherlands; arrested a 24-year-old in the case on 15 September
How it unfolded
-
May The FBI publishes a warning about ShinyHunters.
[3] -
15 Sep Dutch police arrest Pepijn van der Stap, 24, who was on probation for earlier hacking crimes.
[7] [8] -
22 Sep ShinyHunters says it took data on almost all FBI agents.
[3] -
29 Sep Khader is detained in Jordan, sources say, and an FBI official tells members to come forward.
[1] [4] -
30 Sep The gang's leak website goes offline.
[3] -
3 Oct Reuters reports the detention and that Khader is helping the FBI.
[1]
Where this points
Watch whether Jordan or the FBI confirms Khader's detention, and whether the new arrests Kash Patel promised follow.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
Jordan detained a suspected ShinyHunters member, and sources say he is helping the FBI.
Google is testing a setting that would let its Gemini assistant open any file on a Mac.
Rejetto HFS, free file-sharing software, protected its logins with a number that could be worked out from outside.
Attacks on Rejetto HFS began the day after a researcher published the flaw.
The rest of the day
8 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
Flaw found with AI attacked the next day
Mythos, Anthropic's AI model for finding software flaws, helped a researcher at the security firm Horizon3 find a serious hole in Rejetto HFS.
[10] HFS is free software for sharing files from a computer over the web.[10] The researcher, Zach Hanley, published the find and a video of the steps on Wednesday.[10] VulnCheck, a firm that watches for attacks, saw the first attempts the next day, from an address in China aimed at servers in the US and Japan.[10] Version 3.2.1 fixes it.[10] Flaw and video publishedWedFirst attacks seenThuHow long it took for attackers to use the Rejetto flaw after the steps were made public. Why it matters — VulnCheck counts 286 flaws found so far by Mythos and the partners allowed to use it, and this is only the second known to be used in a real attack.
[10] Servers still running an older version are the ones being attacked.[10] -
03
Danish university loses records going back to 2003
The Technical University of Denmark (DTU) says a hacker used a stolen login to get into DTUBasen, the system that controls who can sign in to its services.
[11] The attacker downloaded a large amount of data, and DTU says it cannot tell exactly what was taken.[11] The system holds about 40,000 current users and about 160,000 former ones, going back to 2003.[11] For current users it holds Danish personal ID numbers, home addresses, and the names and phone numbers of next of kin.[11] - Current users40,000 · 20%
- Former users160,000 · 80%
Who is in DTU's sign-in system. Most of the up to 200,000 people had already left the university. Why it matters — DTU warns the ID numbers can be used for identity fraud and to make scam messages more convincing.
[11] It cannot reach every former student directly, so it has asked people to pass the warning on.[11] -
04
London police stop using a phone-copying tool
London's Metropolitan Police has paused its use of software from Oxygen Forensics and started a full review.
[12] Oxygen's software copies data off phones seized in investigations.[12] US prosecutors have accused its chief executive and a Russian partner of hiding that five Russians owned the company and that its code was written in Moscow.[12] The Met says it used the tool in under 0.2% of more than 23,000 forensic jobs in the past year.[12] Why it matters — US prosecutors do not say the software held harmful code, and the Met says it shares no case data with Oxygen.
[12] Romania has begun dropping Oxygen, Latvia's police have suspended it, and a London court refused bail to the Russian partner, Oleg Davydov.[12] -
05
Google tests letting Gemini run a Mac
Google is testing a setting that would let Gemini, its AI assistant, open any file on a Mac, use apps and browse the web, BleepingComputer reports.
[13] The setting was found hidden in the Gemini Desktop app; it is not switched on, and Google has not confirmed it.[13] With it on, Gemini could read, change or delete files anywhere and act through Mail and Messages without asking each time.[13] It would still ask before buying things, moving money or accepting legal terms.[13] Why it matters — It comes as Apple considers making it harder for AI helpers to read people's private files on a Mac.
[13] It is not known when Google plans to switch it on.[13] -
06
Meta's Muse keeps a page on everyone a user knows
A researcher, Karan Joshi, got Muse, Meta's new AI assistant, to share its own instructions, and passed them to Wired.
[14] One instruction tells Muse to build a page for every person in the user's life, updated every hour.[14] A page can hold where a friend lives, dates that matter, past arguments and what the relationship seems to need.[14] Meta says Muse gathers this from public information and from what users choose to share.[14] Why it matters — Meta says users can wipe Muse's memory and see a log of what it does.
[14] The friends and relatives these pages describe are not the people who installed Muse.[14] -
07
Fortra fixes three critical flaws in BoKS
Fortra has fixed eight flaws in BoKS, software that large organisations use to control who can log in to their Linux and Unix servers.
[15] Three of the flaws are rated critical.[15] In the worst one, BoKS made passwords for some service accounts from the time on the clock, so an attacker who could guess the time could rebuild a short list of possible passwords.[15] Fortra reported no attacks using any of them.[15] Why it matters — BoKS decides who may log in across a whole fleet of servers, so a flaw in it reaches all of them.
[15] The three critical ones are rated between 9.1 and 9.9 out of 10 for how severe they are.[15] -
08
Start-up raises $38m to fence in AI agents
doxx.net, a Miami company founded in 2025 by Barrett Lyon, has raised $38 million in a round led by the investment firm Andreessen Horowitz.
[16] It opened a test version of a private network for AI agents, the programs that browse and act on a person's behalf.[16] The network is meant to stop agents reaching known harmful websites, malware and fake login pages.[16] Why it matters — The company says agents act with their user's accounts but cannot always tell a safe page from an unsafe one.
[16] CyberScoop reports that AI agents breaking out of tests and into organisations went from unheard of to routine within weeks.[19] -
09
US agency lists two help-desk flaws as used in attacks
CISA, the US cyber-defence agency, has added two flaws in Zammad to its list of holes known to be used in attacks.
[17] Zammad is free software that organisations use to handle help-desk requests.[18] The two flaws were used together against DIVD, a Dutch volunteer group that reports security holes, in an attack it noticed on 24 September.[18] US federal agencies must now fix them ahead of less risky flaws.[17] Why it matters — DIVD asks everyone running Zammad to update to version 7 or take it offline.
[18] CISA urges every organisation, not only US agencies, to fix the holes on its list first.[17]
Open one person's phone and you reach everyone in it
A phone keeps the names and messages of the people its owner deals with, so whoever opens it can find them too.
The twist
The FBI did not have to break into the whole gang at once. It needed one member who would open his own devices, because they hold his messages with the others.
The picture
How it works
- A person's phone keeps their messages, contacts and notes about other people
- Those other people never chose where it is kept, or how well
- Someone opens that one phone or account: police, a thief, or a helper app
- Everyone recorded in it can now be found
- In a gang, one arrest leads to the next
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
DTU's stolen sign-in system
The system kept the names and phone numbers of staff members' next of kin, so one stolen login reached relatives who never had a DTU account.
-
Meta's Muse pages
Muse writes a page on each friend and relative of its user, so whoever opens a user's Muse also reaches people who never installed it.
-
Gemini's hidden Mac setting
Full access would let Gemini read every file and use Messages, and a Mac's messages hold what other people wrote to its owner.
Where you've seen this
Spy networks
spies are kept in small cells so that one captured agent can name only the few people he met
Medical files
a patient's family history describes parents and siblings who never saw that doctor
Group chats
one member's screenshot shows everyone else's messages too
The catch
It only works when the records are kept: groups that delete messages or use throwaway accounts leave less behind, and investigators still need someone to explain what they find.
And the whole of it
Your phone holds the numbers, birthdays and messages of people who never chose how well you guard it. Their phones hold yours in the same way.
What is really going on
ShinyHunters says it broke into the FBI's jobs website to force the bureau to withdraw a warning about the gang.
Who gains
-
The FBI
— A detained member walking investigators through his devices and messages can lead them to the others.
[1] -
Whoever is attacking old Rejetto HFS servers
— The attacks began the day after Horizon3 published the flaw and a video of the steps.
[10] -
Horizon3
— The AI security-testing firm has used Mythos since July and says it found many critical flaws with it; a public, named find shows that work.
[10] -
doxx.net
— It raised $38 million for a network that keeps AI agents off harmful sites, as agents straying into organisations becomes routine.
[16] [19] -
Meta
— Muse's pages on each person a user knows give Meta a record of who matters to that user and why.
[14]
Who pays
-
FBI staff and their families
— Samples of the stolen data hold agents' contact details, family members and duty assignments, and the gang holds them whether or not it publishes.
[9] [1] -
DTU's current and former users
— DTU warns their ID numbers can be used for identity fraud and more convincing scams.
[11] -
Owners of older Rejetto HFS servers
— Their servers have been attacked since Thursday.
[10] -
Police forces using Oxygen
— The Met has paused the tool for a full review, Romania is dropping it and Latvia's police have suspended it.
[12] -
Organisations running BoKS
— They must install fixes for three critical flaws in the system that controls logins to their servers.
[15] -
Friends and relatives of Muse users
— Muse writes pages about them that they never asked for.
[14]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Where Khader is held, and what he is accused of.
Reuters could not find out the circumstances or the place of his detention, and the FBI declined to comment on arrests abroad.
[1] -
02
Whether the FBI data will be published.
The gang says it will not, but a new ShinyHunters leak site went online on Thursday, so others are still running it.
[1] [2] -
03
Why the gang's old leak site went offline.
The gang blamed sabotage by rivals and an unrelated incident, and the FBI would not say whether it took the site down.
[1] [3] -
04
What was taken from DTU, and from how many people.
DTU says it cannot tell what was downloaded or how many people were affected.
[11] -
05
Who is attacking Rejetto HFS servers.
The first attempts came from an address in China, and later ones from US addresses that look like a relay hiding the real sender.
[10] -
06
Whether Oxygen's software ever sent anything to Russia.
US prosecutors do not say it held harmful code; their case is about who owned and built it, and the charges are allegations.
[12] -
07
When Google will switch on full Mac access for Gemini.
The setting is hidden, Google has not confirmed it, and neither the date nor the model behind it is known.
[13] -
08
Whether the people Muse writes pages about can see or remove them.
Meta says users can wipe Muse's memory; it has said nothing about the friends and relatives the pages describe.
[14]
Authorities in the Netherlands and in Jordan have each detained a suspect in the ShinyHunters case, and the gang wrote to Reuters that it wants no further escalation with the FBI.
Also true today
- Of the 286 software flaws that Anthropic's Mythos and its partners have found since April, only two are known to have been used in a real attack.
- Fortra fixed eight flaws in BoKS, three of them critical, and reported no attacks using them.
More from Cybersecurity
Across the beats