The person behind the handle Rey covered part of an email address in a screenshot, but left a password visible. That small omission became a useful lead in Brian Krebs’s investigation. Krebs’s November 2025 profile

The latest ShinyHunters headlines concern detention and an alleged extortion attempt against Jeppesen ForeFlight. Behind them is a longer story of researchers following aliases, preserving online history and comparing clues across sources. The interesting work happened well before the arrest headlines: turning a shifting collection of online personas into identifiable people.

The Investigators Had a Head Start

In March 2025, threat intelligence company KELA published research linking Rey, previously known as Hikki-Chan, to a young person in Amman, Jordan. Its account describes infections by RedLine and Vidar information-stealing malware in February and March 2024. One infected machine appeared to be shared with a family member. The stolen data helped connect earlier aliases, including o5tdev, with the newer persona. KELA says it subsequently shared a fuller profile with law enforcement. KELA investigation

KELA’s research also illustrated a different route with another Hellcat operator, Pryx. Matching material across a technical guide, a video and a GitHub repository connected accounts that appeared separate. A reused email address, an identical file hash and an archived author name supplied further links. KELA investigation

This is the strength of patient identity research. Changing a display name changes one surface. Earlier posts, reused files and archived pages may preserve the relationships underneath it. A useful lead is something another source can corroborate, rather than simply an interesting resemblance.

A Screenshot Became a Bridge Between Identities

Krebs’s November 26, 2025 profile reconstructed another chain. Intel 471 linked Rey’s earlier Hikki-Chan account to a Telegram handle. That account had posted a screenshot of an automated extortion scam. The password left visible in the image gave Krebs a search lead in SpyCloud’s breach data, linking it to an email address. Intel 471 connected that address to another forum alias; archived defacements added historical context.

The stolen-device records pointed to a shared family computer in Amman. Details from those records and personal claims in chat helped connect the online activity to Saif al-Din Khader. Flashpoint’s chat history contributed to the reconstruction too.

Krebs then contacted Khader’s father. Within two hours, Khader contacted him on Signal and agreed to talk. That direct response added a human encounter to the digital trail. Krebs’s original profile

The reconstruction combined public posts, commercial intelligence, malware-derived records and a direct interview.

Following People as the Brand Changed Hands

By September 2026, the story had moved into a different phase. Krebs interviewed Pepijn van der Stap on September 9 about his claimed rehabilitation after an earlier cybercrime conviction. Van der Stap subsequently stopped answering messages. Krebs’s September 28 report used sources familiar with the matter to identify him as the person detained in the Dutch ShinyHunters investigation.

The reporting also followed Rey’s public activity and the appearance of imagery associated with Van der Stap’s former alias, Umbreon. Sources interpreted the imagery as an attempt to shift blame. The reuse itself was visible; the alleged motive came from sources.

On September 24, Krebs again contacted Rey’s father. He reports that Rey’s longtime X account disappeared hours later. Krebs’s September investigation

The timing made the disappearance worth documenting. It also shows why investigators need a record of what was visible before a subject deletes an account. An account’s disappearance is a development to investigate, rather than a substitute for the earlier evidence.

Police Had Another Kind of Trace: A Voice

The Dutch investigation included a more familiar detective tool. On September 7, police announced that a recording of a suspected Odido attacker would be broadcast on Opsporing Verzocht. The caller had impersonated an IT colleague to persuade a customer-service employee to grant access.

Police said a voice specialist assessed the recording as a real voice, rather than AI-generated audio. They hoped distinctive speech would be recognised by someone who knew the caller. The announcement does not establish that the recording identified Van der Stap. Dutch police appeal

A forum history can connect accounts. A recorded conversation can potentially connect a voice to a person. The two approaches illustrate how cybercrime investigations can draw on both digital records and ordinary human recognition.

From a Known Identity to Reported Detention

On October 3, Reuters reported that Jordanian authorities had detained Khader, citing three sources familiar with the matter. Two sources said he was helping investigators locate other alleged participants; one described him walking investigators through devices and digital correspondence. The FBI declined to discuss a specific foreign arrest while saying it had worked with partners to arrest multiple subjects. Reuters, republished by AOL

Reuters also explained why a known identity does not guarantee a quick arrest: sources described complications involving young suspects, informal groups and victims reluctant to help investigators. Reuters

That gap matters to the story. Researchers can identify a person and publish a compelling account. Authorities still need to investigate particular offences, work across jurisdictions and assemble a case. The public record does not reveal which lead caused which arrest, so the credit should reflect the work we can actually see.

The Aviation Connection Adds a New Chapter

Krebs’s October 7 report adds an alleged extortion attempt involving Jeppesen ForeFlight, a former Boeing business. Two sources said the attempt was underway when Rey was detained. Boeing told Krebs it was reviewing the actor’s claims with Jeppesen ForeFlight; the latter said its investigation had found no impact on operations or products to date.

The story also reconnects an earlier clue: records from the family computer indicated that Rey’s father used Royal Jordanian Airlines employee portals. Krebs reports that Rey had described his father as a pilot, although that specific occupation was not independently confirmed. The airline connection provides context, not an allegation that the father participated.

Krebs describes ShinyHunters as a name used by changing operators and affiliates. His sources said investigators were focusing on remaining participants supplying stolen credentials in return for a share of extortion proceeds. Krebs’s latest report

The achievement in this reporting is the reconstruction. KELA’s early research, the intelligence sources supporting Krebs’s work, direct interviews, police appeals and Reuters’s reporting each illuminate a different part of the case. Together, they let readers follow a trail that would be almost invisible in an arrest announcement alone.

Sources