The net is tightening around the Shiny Hunters cybercrime group following the reported arrest of a second member.
On Saturday, Reuters said that 16 year-old Saif al-Din Khader had been arrested in Jordan and was in FBI custody. This follows the arrest earlier in September of another member in the Netherlands. Third party reports named him as 24 year-old Pepijn van der Stap, an offensive security lead at Dutch company Neo Security.
The FBI posted a message following the Dutch arrest warning other ShinyHunter members that it was coming for them next. Cyber Division Assistant Director Brett Leatherman hinted that people already taken into custody had been talking. Then he said:
“You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
According to security blogger Brian Krebs, Khader (who goes by the nickname ‘Rey’), was the technical operator and public face of Scattered LAPSUS$ Hunters, which he said was an amalgamation of three groups: Scattered Spider, LAPSUS$ and ShinyHunters.
Active since at least 2019, ShinyHunters focused on data theft and extortion. The group commonly uses social engineering to gain access to victims’ accounts on third-party services, but also exploits flaws in software.
Victims of the ShinyHunters group include Kodak, along with American healthcare and pharmaceuticals distributor McKesson. The gang also recently compromised rival cybercrime group Clop and defaced its leak site.
Shortly after the Clop attack, ShinyHunters hacked the FBI. The group said that this wasn’t financially motivated, but instead was a response to a May FBI advisory about its activities. That announcement followed ShinyHunters’ own cyberattack on Instructure, which runs the Canvas online educational system.
The FBI attack targeted the agency’s jobs site, and is said to have exploited a vulnerability in PeopleSoft, HR software owned by Oracle. The data breach, which ShinyHunters claimed amounted to Terabytes, is said to have included a wide array of information on employees, ranging from names, addresses, and phone numbers through to badge numbers, job titles, and information on spouses. Other information included fitness-for-work medical records along with blood and urine test results, and doctors’ notes.
This data is said to include sensitive information on agents investigating targets including Russia, China, and the drug cartels. It would be catastrophic for law enforcement efforts, national intelligence, and individuals if this information fell into the wrong hands.
ShinyHunters has said that it won’t release the data, arguing that the intrusion wasn’t financially motivated. It criticized the FBI for what it said was disinformation in the May advisory. The FBI had said that the group had harassed victims’ family members and threatened to release embarrassing pictures.
The FBI also removed an Accenture contractor this week after they failed to apply a security patch to third-party software that it had been using. Insiders identified this software as PeopleSoft.




