BleepingComputer reported on 3 October that Reuters says Jordan detained a suspected ShinyHunters member known as "Rey" this week. Reuters named him as Saif al-Din Khader. Two sources put the date at Tuesday. They said he is helping the FBI and other agencies find other group members, including by going through his devices and messages.
The detention rests on two unnamed sources. On Tuesday, a suspected affiliate closed a messaging account. The group's leak site, where it posts stolen data, then went offline, and its main spokesperson stopped answering reporters. BleepingComputer says it is unclear whether this is linked to the detention. On Thursday a new leak site appeared. ShinyHunters has not replied to BleepingComputer's questions about it.
BleepingComputer says the group often breaks into firms that connect to cloud software, then uses stolen login tokens to reach customer data. A token is a digital key an app receives after a user signs in, so it works without a password or a second login step. One vendor often holds tokens for many customers, so one breach can reach many. An arrest does not remove that exposure, since the new leak site suggests others are still working. Ask your vendors: which integrations hold tokens, what can each token reach, and how fast can it be cut off?