The person behind the handle Rey covered part of an email address in a screenshot, but left a password visible. That small omission became a useful lead in Brian Krebs’s investigation. Krebs’s November 2025 profile
The latest ShinyHunters headlines concern detention and an alleged extortion attempt against Jeppesen ForeFlight. Behind them is a longer story of researchers following aliases, preserving online history and comparing clues across sources. The interesting work happened well before the arrest headlines: turning a shifting collection of online personas into identifiable people.
The Investigators Had a Head Start
In March 2025, threat intelligence company KELA published research linking Rey, previously known as Hikki-Chan, to a young person in Amman, Jordan. Its account describes infections by RedLine and Vidar information-stealing malware in February and March 2024. One infected machine appeared to be shared with a family member. The stolen data helped connect earlier aliases, including o5tdev, with the newer persona. KELA says it subsequently shared a fuller profile with law enforcement. KELA investigation
KELA’s research also illustrated a different route with another Hellcat operator, Pryx. Matching material across a technical guide, a video and a GitHub repository connected accounts that appeared separate. A reused email address, an identical file hash and an archived author name supplied further links. KELA investigation
This is the strength of patient identity research. Changing a display name changes one surface. Earlier posts, reused files and archived pages may preserve the relationships underneath it. A useful lead is something another source can corroborate, rather than simply an interesting resemblance.
A Screenshot Became a Bridge Between Identities
Krebs’s November 26, 2025 profile reconstructed another chain. Intel 471 linked Rey’s earlier Hikki-Chan account to a Telegram handle. That account had posted a screenshot of an automated extortion scam. The password left visible in the image gave Krebs a search lead in SpyCloud’s breach data, linking it to an email address. Intel 471 connected that address to another forum alias; archived defacements added historical context.
The stolen-device records pointed to a shared family computer in Amman. Details from those records and personal claims in chat helped connect the online activity to Saif al-Din Khader. Flashpoint’s chat history contributed to the reconstruction too.
Krebs then contacted Khader’s father. Within two hours, Khader contacted him on Signal and agreed to talk. That direct response added a human encounter to the digital trail. Krebs’s original profile
The reconstruction combined public posts, commercial intelligence, malware-derived records and a direct interview.
Following People as the Brand Changed Hands
By September 2026, the story had moved into a different phase. Krebs interviewed Pepijn van der Stap on September 9 about his claimed rehabilitation after an earlier cybercrime conviction. Van der Stap subsequently stopped answering messages. Krebs’s September 28 report used sources familiar with the matter to identify him as the person detained in the Dutch ShinyHunters investigation.
The reporting also followed Rey’s public activity and the appearance of imagery associated with Van der Stap’s former alias, Umbreon. Sources interpreted the imagery as an attempt to shift blame. The reuse itself was visible; the alleged motive came from sources.
On September 24, Krebs again contacted Rey’s father. He reports that Rey’s longtime X account disappeared hours later. Krebs’s September investigation
The timing made the disappearance worth documenting. It also shows why investigators need a record of what was visible before a subject deletes an account. An account’s disappearance is a development to investigate, rather than a substitute for the earlier evidence.
Police Had Another Kind of Trace: A Voice
The Dutch investigation included a more familiar detective tool. On September 7, police announced that a recording of a suspected Odido attacker would be broadcast on Opsporing Verzocht. The caller had impersonated an IT colleague to persuade a customer-service employee to grant access.
Police said a voice specialist assessed the recording as a real voice, rather than AI-generated audio. They hoped distinctive speech would be recognised by someone who knew the caller. The announcement does not establish that the recording identified Van der Stap. Dutch police appeal
A forum history can connect accounts. A recorded conversation can potentially connect a voice to a person. The two approaches illustrate how cybercrime investigations can draw on both digital records and ordinary human recognition.
From a Known Identity to Reported Detention
On October 3, Reuters reported that Jordanian authorities had detained Khader, citing three sources familiar with the matter. Two sources said he was helping investigators locate other alleged participants; one described him walking investigators through devices and digital correspondence. The FBI declined to discuss a specific foreign arrest while saying it had worked with partners to arrest multiple subjects. Reuters, republished by AOL
Reuters also explained why a known identity does not guarantee a quick arrest: sources described complications involving young suspects, informal groups and victims reluctant to help investigators. Reuters
That gap matters to the story. Researchers can identify a person and publish a compelling account. Authorities still need to investigate particular offences, work across jurisdictions and assemble a case. The public record does not reveal which lead caused which arrest, so the credit should reflect the work we can actually see.
The Aviation Connection Adds a New Chapter
Krebs’s October 7 report adds an alleged extortion attempt involving Jeppesen ForeFlight, a former Boeing business. Two sources said the attempt was underway when Rey was detained. Boeing told Krebs it was reviewing the actor’s claims with Jeppesen ForeFlight; the latter said its investigation had found no impact on operations or products to date.
The story also reconnects an earlier clue: records from the family computer indicated that Rey’s father used Royal Jordanian Airlines employee portals. Krebs reports that Rey had described his father as a pilot, although that specific occupation was not independently confirmed. The airline connection provides context, not an allegation that the father participated.
Krebs describes ShinyHunters as a name used by changing operators and affiliates. His sources said investigators were focusing on remaining participants supplying stolen credentials in return for a share of extortion proceeds. Krebs’s latest report
The achievement in this reporting is the reconstruction. KELA’s early research, the intelligence sources supporting Krebs’s work, direct interviews, police appeals and Reuters’s reporting each illuminate a different part of the case. Together, they let readers follow a trail that would be almost invisible in an arrest announcement alone.
Related Reading
- ShinyHunters Arrest in the Netherlands: What the Evidence Shows and What Defenders Should Check
- ShinyHunters Claims an FBI Breach: What the Jobs-Site Evidence Actually Shows
Sources
- KELA: Hellcat Hacking Group Unmasked — Investigating Rey and Pryx, originally March 27, 2025; updated November 27, 2025
- KrebsOnSecurity: Meet Rey, the Admin of Scattered Lapsus$ Hunters, November 26, 2025
- Dutch police: voice appeal in the Odido investigation, September 7, 2026
- KrebsOnSecurity: Dutch Police Arrest Reformed Hacker in Shiny Hunters Investigation, September 28, 2026
- Reuters, republished by AOL: detention in Jordan and reported cooperation, October 3, 2026
- KrebsOnSecurity: ShinyHunters Extorted Boeing Spin-off Prior to Arrests, October 7, 2026
Useful read?
Find us again on Google.
Add Hive Security as a preferred source for practical security research and analysis.
Add as a preferred source on GoogleChoose Hive Security in Google's source preferences.