Back to Intelligence

Alleged ShinyHunters Leader 'Rey' Arrested in Jordan: What the Takedown Means for Cloud Extortion Defense

SA
Security Arsenal Team
October 5, 2026
10 min read

Law enforcement has reportedly arrested the individual known as Rey, believed to be a central figure in the ShinyHunters extortion collective, in Jordan. According to reporting first published by SecurityWeek, the suspect is allegedly assisting the FBI in identifying and locating other members of the group. ShinyHunters has been one of the most prolific data-theft and extortion operations of the past several years, with its name attached to breaches affecting hundreds of millions of records across telecommunications, retail, education, and financial services victims.

If your first reaction to this headline is relief, stop. I've worked enough post-takedown engagements to know that arrests disrupt, but rarely eliminate, an extortion ecosystem. The operators who aren't in custody still have the infrastructure, the stolen data, the affiliate relationships, and — most importantly — the playbooks. In the weeks following a high-profile arrest, we consistently see one of two things: remaining members go quiet and burn their infrastructure, or they accelerate operations to monetize access before law enforcement closes in. Both scenarios have defensive implications for your organization right now.

What ShinyHunters Actually Does — and Why It Matters to Your SOC

ShinyHunters is not a ransomware group in the classic encryption sense. Their model is pure data extortion: gain access to large datasets, exfiltrate them quietly, then monetize through direct extortion of the victim organization or by selling the data on criminal marketplaces. The operational details that matter for defenders:

  • Initial access via stolen credentials. The group's most damaging campaigns — most notably the 2024 wave of attacks against Snowflake customers that impacted organizations including Ticketmaster and Santander — did not rely on zero-days. They relied on credentials harvested by infostealer malware, used against SaaS tenants that lacked MFA enforcement and had no network restrictions. This is the single most important lesson: they walked through the front door.
  • Cloud-native exfiltration. Once inside a cloud data platform, the group runs bulk export operations (e.g., large SELECT result sets staged to external storage, or COPY INTO operations to attacker-controlled storage locations) that can move hundreds of gigabytes in minutes. Traditional DLP and perimeter controls see little of this because it all happens inside the SaaS trust boundary.
  • Credential stuffing at scale. ShinyHunters has historically leveraged massive credential dumps against corporate portals, ticketing systems, and developer platforms. If your users reuse passwords and your SSO doesn't enforce phishing-resistant MFA, you are in their target profile.
  • Extortion and leak infrastructure. Victims who don't pay have data posted to leak sites or sold. The "Rey" persona was reportedly central to the group's public-facing brand and marketplace operations — which is precisely why FBI cooperation from this individual is operationally significant for law enforcement and for understanding affiliate networks.

Exploitation status: This is not a vulnerability story — there is no CVE here. This is a tradecraft story. The techniques ShinyHunters uses are unpatched by design because they abuse legitimate functionality: authentication, query engines, and export features. That means your detection and identity controls are the patch.

Why the Arrest Raises Your Risk in the Short Term

Three tactical realities defenders should internalize:

  1. Splintering and reconstitution. When a brand-name group loses its leadership, affiliates don't retire. They rebrand, join competing crews, or go independent. Expect the same TTPs to surface under new names within weeks. Your detections should be behavior-based, not name-based.
  2. Credential market churn. Law enforcement seizures and operator arrests often trigger panic-selling of stolen credential caches and access broker inventories. We've seen credential dumps flood the market after major arrests as actors cash out. If your threat intel team isn't monitoring for your domains in fresh dumps this month, they should be.
  3. Copycat extortion waves. Arrests generate headlines, and headlines generate opportunists. Expect an uptick in extortion emails claiming ShinyHunters affiliation from actors with no real access — alongside a smaller number of genuine incidents from affiliates monetizing existing access before it's burned.

Detection & Response

Because ShinyHunters' access vector is credential abuse against cloud/SaaS platforms and their impact mechanism is bulk data export, detection must focus on authentication anomalies and mass data movement, not on malware artifacts. The rules below target the exact behaviors associated with this group's documented tradecraft.

Sigma Rules

YAML
---
title: Suspicious Bulk Data Export to External Cloud Storage
description: Detects bulk copy/export operations from cloud data platforms (e.g., Snowflake-style COPY INTO) to external storage locations, consistent with ShinyHunters-style mass exfiltration from SaaS data platforms.
status: experimental
id: 9f2c7a41-3b8e-4d21-a6c5-7e1f8b2d4c90
author: Security Arsenal
date: 2026/04/06
references:
  - https://attack.mitre.org/techniques/T1567/002/
  - https://attack.mitre.org/techniques/T1530/
tags:
  - attack.exfiltration
  - attack.t1567.002
  - attack.t1530
logsource:
  product: snowflake
  service: audit
detection:
  selection_query:
    QUERY_TEXT|contains:
      - 'COPY INTO'
      - 'UNLOAD'
    QUERY_TEXT|contains:
      - 's3://'
      - 'azure://'
      - 'gcs://'
      - 'storage.googleapis.com'
      - 'blob.core.windows.net'
  filter_internal:
    QUERY_TEXT|contains:
      - 'internal-backup-bucket'
      - 'corp-data-warehouse-stage'
  condition: selection_query and not filter_internal
falsepositives:
  - Legitimate scheduled ETL and backup jobs to external stages
level: high
---
title: Multiple Failed Cloud Logons Followed by Successful Authentication
description: Detects credential stuffing patterns where numerous failed logon attempts from a single source are followed by a successful authentication, consistent with ShinyHunters' use of breached credential caches against SaaS tenants lacking MFA.
status: experimental
id: 4b1e9d52-8c3f-4a67-b2e8-1d5c7f903a2e
author: Security Arsenal
date: 2026/04/06
references:
  - https://attack.mitre.org/techniques/T1110/004/
  - https://attack.mitre.org/techniques/T1078/004/
tags:
  - attack.credential_access
  - attack.t1110.004
  - attack.t1078.004
logsource:
  category: authentication
detection:
  selection_failed:
    action: failure
  condition: selection_failed | count(TargetUserName) by SourceIp >= 10
timeframe: 10m
falsepositives:
  - Misconfigured service accounts
  - Password spray testing by internal red teams
level: medium

KQL — Microsoft Sentinel / Defender

This hunt queries Entra ID sign-in telemetry for successful authentications from IP addresses with a high recent failure rate and no MFA claim — the exact profile of the Snowflake campaign intrusions. It also flags large anomalous data access patterns surfaced via Defender for Cloud Apps.

KQL — Microsoft Sentinel / Defender
// Hunt for credential-stuffing success: high-failure source IPs with a non-MFA success
let window = 24h;
let failureThreshold = 20;
let suspiciousIPs = SigninLogs
    | where TimeGenerated > ago(window)
    | where ResultType != 0
    | summarize FailureCount = count(), DistinctUsers = dcount(UserPrincipalName) by IPAddress
    | where FailureCount >= failureThreshold and DistinctUsers >= 3;
SigninLogs
| where TimeGenerated > ago(window)
| where ResultType == 0
| where IPAddress in (suspiciousIPs | project IPAddress)
| extend MfaUsed = tostring(AuthenticationDetails[0]["authenticationMethod"])
| where AuthenticationRequirement != "multiFactorAuthentication"
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName,
          Location, DeviceDetail, MfaUsed, AuthenticationRequirement, CorrelationId
| order by TimeGenerated desc;

Velociraptor VQL

ShinyHunters affiliates frequently stage exfiltration from compromised endpoints and jump boxes using generic tooling — cloud CLIs, rclone, and archive utilities. This hunt surfaces interactive command shells spawned from unexpected parent processes and common exfil tool execution on servers that shouldn't have them.

VQL — Velociraptor
-- Hunt for exfiltration tooling and anomalous shell execution on servers
SELECT Pid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Exe =~ '(?i)rclone|aws(.exe)?$|az(.exe)?$|gsutil|s3cmd|7z(.exe)?$|winrar|rar(.exe)?$'
   OR CommandLine =~ '(?i)copy\\s+.*\\\\|sync\\s+.*remote:|--transfers|--checksum|archive.*compress'
ORDER BY CreateTime DESC

Remediation Script

The following PowerShell audits your Entra ID tenant for the precise gaps ShinyHunters exploits: users without MFA registration, legacy authentication protocol usage, and service principals with no credential expiry. Run it with an account holding at least Reports Reader and Directory Readers roles (Microsoft Graph PowerShell SDK required).

PowerShell
# ShinyHunters-Exposure-Audit.ps1
# Requires: Install-Module Microsoft.Graph.Reports, Microsoft.Graph.Users
Connect-MgGraph -Scopes "User.Read.All","AuditLog.Read.All","Reports.Read.All" -NoWelcome

# 1) Find users with NO strong authentication methods registered
$noMfa = Get-MgReportAuthenticationMethodUserRegistrationDetail -All |
    Where-Object { -not $_.IsMfaRegistered }
Write-Host "[CRITICAL] Users without MFA registered: $($noMfa.Count)" -ForegroundColor Red
$noMfa | Select-Object UserPrincipalName, IsMfaRegistered |
    Export-Csv .\NoMFA_Users.csv -NoTypeInformation

# 2) Detect legacy auth sign-ins in the last 7 days (basic auth bypasses MFA entirely)
$legacy = Get-MgAuditLogSignIn -All -Filter "createdDateTime ge $((Get-Date).AddDays(-7).ToString('yyyy-MM-ddTHH:mm:ssZ'))" |
    Where-Object { $_.ClientAppUsed -in @('Exchange ActiveSync','IMAP','POP3','SMTP','Other clients') -and $_.Status.ErrorCode -eq 0 }
Write-Host "[WARN] Successful legacy-auth sign-ins (7d): $($legacy.Count)" -ForegroundColor Yellow
$legacy | Select-Object CreatedDateTime, UserPrincipalName, IPAddress, ClientAppUsed |
    Export-Csv .\LegacyAuth_SignIns.csv -NoTypeInformation

# 3) Verify Conditional Access MFA coverage exists
$policies = Get-MgIdentityConditionalAccessPolicy -All
$mfaPolicies = $policies | Where-Object { $_.State -eq 'enabled' -and $_.GrantControls.BuiltInControls -contains 'mfa' }
if (-not $mfaPolicies) {
    Write-Host "[CRITICAL] No enabled Conditional Access policy enforces MFA. Remediate immediately." -ForegroundColor Red
}

# 4) Flag credentials older than 90 days on users with privileged directory roles
Write-Host "Audit complete. Review exported CSVs and remediate MFA gaps before anything else."

Remediation & Hardening Priorities

ShinyHunters' model succeeds because of gaps, not exploits. Prioritize in this order:

  1. Enforce phishing-resistant MFA universally — including service and break-glass paths. The Snowflake campaign victims fell because single-factor access to a data platform was permitted. FIDO2/passkeys or certificate-based auth for administrators; at minimum, enforced MFA for every user on every externally reachable SaaS tenant. Audit with the script above.
  2. Kill legacy authentication protocols. IMAP, POP3, SMTP basic auth, and EAS bypass conditional access entirely. Block them tenant-wide in Entra ID and your IdP equivalents.
  3. Apply network access controls on SaaS data platforms. Snowflake network policies, IP allowlists, and private connectivity (PrivateLink/Private Endpoints) would have prevented the majority of this group's successful intrusions, which came from commercial VPN and hosting-provider IPs.
  4. Detect mass export behavior. Alert on COPY INTO / UNLOAD operations to non-approved external stages, on query result volumes an order of magnitude above a user's baseline, and on first-time-seen source IPs accessing your data warehouse.
  5. Rotate credentials exposed in infostealer dumps. Subscribe your domains to credential-leak monitoring. ShinyHunters' access came from credentials stolen months to years earlier by infostealer infections on employee and contractor machines. Historical credential exposure is a present-tense risk.
  6. Hunt proactively this month. Given the arrest and expected affiliate churn, run focused hunts for: dormant accounts with recent successful logons, new OAuth grants on data platforms, and export jobs created outside change windows. If you find evidence of bulk access, treat it as an extortion precursor and invoke your IR retainer — don't wait for the extortion email.
  7. Prepare your extortion playbook. Tabletop the scenario where data has already left and the threat is publication, not encryption. Legal counsel, breach notification obligations (state AG timelines, HIPAA if applicable, PCI-DSS reporting), and law enforcement coordination with the FBI — which is actively working ShinyHunters cases — should be pre-decided, not improvised.

If your organization was a prior ShinyHunters victim or appears in any of their historical leak postings, the reported FBI cooperation from Rey may yield victim notifications. Engage with the FBI's victim notification channels and your sector ISAC now rather than waiting.

Executive Takeaways

  • The arrest disrupts ShinyHunters' leadership but not the affiliate ecosystem or the stolen-credential economy that feeds it.
  • This group wins through identity gaps: no MFA, legacy auth, unrestricted SaaS access. None of that requires a patch — it requires configuration discipline you can implement this week.
  • Expect short-term churn: panic-sold credential dumps, rebranded affiliates, and copycat extortion claims. Increase monitoring sensitivity on authentication anomalies and bulk data movement for the next 60–90 days.
  • Detection must live in your identity plane and your SaaS audit logs, not just on endpoints. If you can't see a 500 GB COPY INTO from your data warehouse, you can't see ShinyHunters.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.