A suspected member of ShinyHunters, the cybercrime group that claimed responsibility last month for defacing the FBI’s jobs website, was detained in Jordan on Tuesday and is cooperating with American investigators, U.S. officials said.

Jordanian authorities picked up Saif al-Din Khader, according to two U.S. officials and another person with knowledge of the matter. Reuters, which first reported the arrest, said it could not confirm the exact circumstances or where Mr. Khader is being held. Two sources told Reuters he is helping the FBI and international law enforcement track down the rest of the group, and one said he has been showing investigators his own devices and digital communications so they can identify his former associates.

The FBI declined to comment on the arrest but said in a statement that “the Bureau continues to aggressively investigate the recent Cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice.”

In messages posted on the dark web and in exchanges with news outlets last month, ShinyHunters said it had stolen 2 to 3 terabytes of data relating to FBI employees by exploiting a new vulnerability in Oracle PeopleSoft, a human resources management program. It has claimed, without public verification, to hold data on every FBI employee. An earlier Reuters analysis found that the sample the group leaked contained detailed personal information, sensitive job-related data and psychiatric and medical records, and some have compared the episode to the 2015 breach of the Office of Personnel Management, in which a China-linked attack exposed security clearance files on millions of Americans.

Mr. Khader is at least the second suspect in custody. A 24-year-old man from Amsterdam was arrested on Sept. 15 on suspicion of belonging to the group, Dutch National Police and the FBI have said, days before the jobs-site hack was first reported by 404 Media on Sept. 22. Dutch police did not name him, but people familiar with the case identified him to CBS News as Pepijn van der Stap. ShinyHunters itself told Reuters that Mr. van der Stap had “no association” with the group and dismissed the Dutch police as incompetent.

Reporting by the security journalist Brian Krebs complicates that denial. Mr. van der Stap used the online handle “Umbreon” and Pokemon imagery on a hacking forum as early as 2021, and the art left on the defaced FBI site featured the same character. Sources told Krebs the imagery may have been planted by the group’s current leader, a teenager from Amman known as Rey, to pin the hack on Mr. van der Stap, with whom he had feuded over control of the group’s name and data. In November 2025, after examining stolen-data logs and speaking with the man over Signal, Krebs reported that Rey was Mr. Khader, and that Rey had told him he had been quietly cooperating with law enforcement since June.

The group’s own infrastructure has wavered since the detention. Reuters lost contact with its usual communication account on Tuesday, its dark web leak site went offline by Wednesday and a new site was back up by Thursday. An FBI Cyber Division official said last week that arrests tend to make people more willing to talk, and that seized servers can point to suspects still at large. “FBI teams are working new leads RIGHT NOW. More arrests are on the table,” FBI Director Kash Patel wrote on X.