Home International ‘More arrests are on the table’: Qantas hack gang member nabbed

‘More arrests are on the table’: Qantas hack gang member nabbed

0
1
Advertisement
David Swan

A suspected key player in the hacking alliance behind the Qantas data breach has been detained in Jordan and is cooperating with the FBI.

Saif al-Din Khader, known online as Rey, was taken into custody by Jordanian authorities last week, three people familiar with the matter told Reuters.

Qantas was hacked in June 2025, when a caller posing as IT support persuaded a worker at an offshore call centre to connect a Salesforce customer platform to a malicious data-extraction tool.Australian Financial Review.

Khader is helping the FBI and police around the world track down other members of ShinyHunters, two of the sources told the news agency. ShinyHunters is the extortion gang that claimed last month to have stolen data on every FBI employee. One source said Khader was walking investigators through his electronic devices and digital correspondence.

In November last year, US security journalist Brian Krebs identified Khader as one of the administrators of Scattered Lapsus$ Hunters. It is a loose alliance of mostly English-speaking hacking gangs, including ShinyHunters.

Advertisement

Khader told Krebs at the time he had been trying to leave the group and had been working with law enforcement since June 2025. ShinyHunters continued its attacks into this year, claiming break-ins at Grand Theft Auto maker Rockstar Games and education platform Canvas.

Cybersecurity researchers linked Scattered Lapsus$ Hunters to the leak of 5.7 million Qantas customers’ personal details on the dark web last October. Neither Reuters nor any law enforcement agency has alleged Khader was personally involved in the Qantas attack.

The AFP and Qantas were contacted for comment.

The FBI declined to comment to Reuters on any arrest abroad, but said it had already worked with partners to arrest multiple subjects and would “spare no resource in bringing each of the responsible individuals to justice”. FBI director Kash Patel went further, signalling the investigation was widening. “FBI teams are working new leads RIGHT NOW,” he posted on X on Wednesday. “More arrests are on the table.”

Advertisement

Patel’s post followed confirmation by Dutch police that a 24-year-old Amsterdam man had been arrested in September in an investigation into ShinyHunters. He has been identified by Krebs and others as Pepijn van der Stap, a hacker convicted in the Netherlands in 2023 over a string of data thefts and extortions. ShinyHunters has said van der Stap had no association with the group.

The gang claimed on September 22 that it had hacked the FBI in retaliation for an advisory accusing it of exaggerating its access to victims’ systems. It gave the bureau a week to withdraw the advisory. Since then, its dark website has disappeared. In its most recent email to Reuters, the group said it wanted “no further escalation” with the FBI.

Police have struggled to prosecute members of related groups such as Lapsus$ and Scattered Spider, Reuters has reported. Many of the hackers are young, the groups are chaotic and informal, and victims often decline to help investigators.

Qantas was hacked in June 2025, when a caller posing as IT support persuaded a worker at an offshore call centre to connect a Salesforce customer platform to a malicious data-extraction tool. When Salesforce refused a ransom demand, the hackers published the data.

Privacy Commissioner Carly Kind. Nine
Advertisement

Most records held names, email addresses and frequent flyer details. About 1.7 million also included home or business addresses, dates of birth, phone numbers and meal preferences. Qantas said passport and credit card details were not on the system.

In July, Privacy Commissioner Carly Kind declined to open a formal investigation into the airline. She said the evidence did not support the likelihood that Qantas had breached privacy law.

Serious or repeated breaches of the Privacy Act can attract penalties of more than $50 million, and the watchdog has left the door open. “It is still open to the commissioner to commence an investigation of Qantas with respect to these or other practices,” Kind said.

Law firm Maurice Blackburn is also pursuing a proposed class action on behalf of customers whose personal information was stolen and published online. Maurice Blackburn was contacted for comment.

The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.

David SwanDavid Swan is the technology editor for The Age and The Sydney Morning Herald. He was previously technology editor for The Australian newspaper.Connect via X or email.

From our partners

Advertisement
Advertisement

Disclaimer : This story is auto aggregated by a computer programme and has not been created or edited by DOWNTHENEWS. Publisher: www.smh.com.au