A second individual linked to the FBI's investigation into a major data breach has been apprehended, according to multiple sources within the bureau. Reuters reported on Saturday that Saif al-Din Khader was taken into custody in Jordan on September 28. The detainee is reportedly providing assistance to the FBI and partner law enforcement agencies in efforts to identify and apprehend additional members of ShinyHunters, the cybercriminal collective behind the FBI breach and numerous other attacks.

When asked about Khader's detention, the FBI declined to provide specifics but issued a statement emphasizing its commitment to the investigation. "Having already worked with partners to arrest multiple subjects … we will spare no resource in bringing each of the responsible individuals to justice," a spokesperson said. The agency also noted that it "continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters."

Cybersecurity journalist Brian Krebs had previously identified Khader as a prominent member of ShinyHunters in November of last year. Through his investigation, Krebs connected the online handle "Rey" and various hacker profiles to Khader, revealing that the individual was a 16-year-old resident of Amman, Jordan. After Krebs reached out to Khader's father, the teenager responded directly, claiming he had already been communicating with law enforcement authorities in Europe.

The FBI has not disclosed where Khader is currently being held or whether extradition proceedings are underway. Khader's apprehension comes shortly after another alleged ShinyHunters member was arrested. On September 29, the FBI and Dutch National Police jointly announced the detention of Pepijn van der Stap, a notorious hacker who had been released earlier this year following a previous prison sentence for hacking offences.

According to reporting by Krebs, van der Stap held a significant position within ShinyHunters and was allegedly engaged in a power struggle with Khader over leadership of the criminal enterprise. Khader is believed to have orchestrated dozens of major incidents targeting both European and American organizations.

Group resurfaces after leak site takedown

Law enforcement agencies took down the ShinyHunters leak site last week, but the group reappeared on Telegram on Monday. The collective announced plans to revive a defunct cybercriminal forum to serve as a successor to its previous leak platform.

ShinyHunters has claimed responsibility for dozens of major data thefts over recent months and has been the subject of FBI scrutiny for nearly a year. The group's targets have included major corporations such as Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line and 7-Eleven. The collective even conducted operations against other Russian cybercriminal groups before turning its attention to the FBI.

The breach of FBI systems exposed sensitive personal information on nearly every agent in the bureau, including names, residential addresses, phone numbers, Social Security numbers, email addresses and employee identification numbers. The incident also compromised thousands of records belonging to local law enforcement officers who collaborate with the FBI through task forces. The FBI distributed an internal notice to staff last week alerting them to the breach and warning of potential risks to themselves and their families.

In communications to news organizations, ShinyHunters stated that it would not publish the stolen data and expressed no desire to intensify its conflict with the FBI. The group attributed the initial confrontation to disagreement with an FBI advisory concerning their activities.