Jordanian authorities have detained a man described by U.S. investigators as a senior figure in the cybercrime alliance behind last year’s Qantas customer-data leak, while the FBI said additional arrests in the sprawling extortion case are imminent.

Detention in Amman

Saif al-Din Khader, known online as Rey, was taken into custody in Jordan last week and is cooperating with the FBI, three people familiar with the matter told Reuters. The Sydney Morning Herald, which first reported the development Monday in Australia, said Khader is believed to be a key operator within ShinyHunters, a group that has claimed responsibility for mass data thefts and ransom demands against corporations worldwide.

Neither Jordan’s government nor the FBI has published a formal charge sheet tied to the Qantas breach. Reuters noted that researchers have linked the broader Scattered Lapsus$ Hunters coalition to the October 2025 dump of 5.7 million Qantas customer records on the dark web, but no law-enforcement agency has alleged Khader personally uploaded that dataset. Qantas has said it is assisting investigators while continuing notifications to affected travelers.

FBI widens the net

FBI Director Kash Patel wrote on X last week that teams were “working new leads RIGHT NOW” and that “more arrests are on the table.” The bureau declined to comment to Reuters on any arrest abroad but said it had already worked with partners to detain multiple subjects and would “spare no resource” in pursuing the rest.

Dutch police confirmed in September that a 24-year-old Amsterdam man was arrested in a parallel ShinyHunters investigation. Cybersecurity researchers have identified him as Pepijn van der Stap, who was convicted in the Netherlands in 2023 over earlier data thefts; the group has publicly distanced itself from him. The overlapping cases illustrate how extortion crews swap affiliates across borders, complicating attribution for corporate victims.

Stakes for Qantas and regulators

For Qantas, the leak remains a live regulatory matter in Australia. The airline disclosed that hackers accessed names, contact details and frequent-flyer numbers, though not passport or payment card data in the initial assessment. The Office of the Australian Information Commissioner has an open investigation, and class-action firms have advertised potential claims.

Monday’s detention does not by itself restore deleted records or identify every co-conspirator who handled the Qantas files. Security vendors tracking ShinyHunters say the group continues to advertise fresh breaches, keeping pressure on airlines and retailers that store loyalty-program data.

Australian customers, meanwhile, are still urged to rotate passwords and watch for phishing that cites the breach. A single arrest in Jordan may mark progress for investigators, but Patel’s public warning suggests the FBI expects more names—and more extradition paperwork—before the case is closed.