Skip to main content
Threat IntelligenceEmerging Threats

FBI Arrests Cyber Exec Tied to ShinyHunters Hacking Group

Federal courthouse exterior with people in professional attire walking in and out of frame.
"Agents had arrested 'another suspected co-conspirator of the ShinyHunters group,'" FBI Director Kash Patel told reporters, a remark that preceded the arrest this week of a Canadian cybersecurity executive who until now had been publicly known for helping organizations negotiate payments to ransomware and extortion actors.

Edward Dubrovsky: arrest, custody, and transfer

Edward Dubrovsky, 54, was taken into custody in Pennsylvania while attending a cybersecurity conference, multiple outlets reported. Public court records show Dubrovsky appeared in the U.S. District Court for the Eastern District of Pennsylvania after the arrest; a subsequent court order transferred him to the Eastern District of Texas, where charges were filed, and states that he remains in custody.

Several news organizations — including The New York Times, Politico and KrebsOnSecurity — identified Dubrovsky as the Canadian citizen arrested in Pennsylvania. The complaint against him is currently sealed, and the docket lists conspiracy and extortion-related charges.

The charges on the docket

The case docket reproduces statutory language rather than a sealed complaint summary. It lists:

  • "18:371 AND 1030(a)(7)(B) - CONSPIRACY TO THREATEN TO IMPAIR THE CONFIDENTIALITY OF INFORMATION WITH THE INTENT TO EXTORT MONEY;"
  • "18:1951(a) AND (b)(2) - INTERFERENCE WITH COMMERCE BY THREATS (HOBBS ACT EXTORTION AND CONSPIRACY TO COMMIT HOBBS ACT EXTORTION)."

Because the complaint remains under seal, the public record does not yet identify the specific actions alleged or whether prosecutors will tie Dubrovsky directly to the ShinyHunters breach of the FBI jobs portal that prompted renewed law enforcement activity.

CYPFER, CyberSteward, and a trade name tied to negotiation services

Dubrovsky has publicly co-founded Canadian cybersecurity company CYPFER and has been associated with CyberSteward, a firm that specializes in ransomware negotiation and cyber-extortion response. Politico reported that CyberSteward is a trade name used by CYPFER, and that the firms help organizations negotiate and send extortion payments to cybercriminals.

Dubrovsky also authored a book titled "Cyber Extortion Strategic Response" about handling cyber extortion, and — according to KrebsOnSecurity — had posted on LinkedIn that he planned to attend the NetDiligence Cyber Risk Summit in Pennsylvania with the CyberSteward team when he was arrested.

ShinyHunters: operations, recent FBI account, and law enforcement pressure

The ShinyHunters name has been used by numerous threat actors; as described in public reporting, the group (and associated actors) steal data from web applications and cloud-based SaaS platforms and then demand ransom payments from victims or publish stolen data. ShinyHunters has also operated as an extortion-as-a-service provider, helping other hackers pressure compromised organizations into paying.

More recently, reporting credits ShinyHunters with increasingly targeting cloud environments and enterprise SaaS platforms, often leveraging stolen credentials, authentication tokens, phishing, and social engineering to gain access and exfiltrate data. The FBI has said ShinyHunters and associated actors have breached more than 140 organizations and collected more than $70 million in extortion payments over the past year.

In response to a breach of its jobs portal, the FBI has stepped up pressure on the group; multiple arrests and detentions linked to alleged ShinyHunters members have occurred in recent weeks. While the agency's director announced the arrest of "another suspected co-conspirator," the FBI has not publicly confirmed that Dubrovsky is the suspected ShinyHunters co-conspirator named in those remarks.

What this means for CyberSteward/CYPFER, affected enterprises, and adversaries

  • CyberSteward / CYPFER: Firms that publicly offer negotiation and extortion-response services will face heightened scrutiny when personnel with customer-facing roles are implicated in alleged criminal activity. Contracts, insurance arrangements, and vendor due diligence procedures are likely to be examined if authorities pursue the sealed complaint.
  • Affected enterprises and breach victims: Companies that have engaged third-party negotiation services will watch the case closely for any impact on past or ongoing incident responses, and for legal precedent about the boundaries between lawful mediation and alleged criminal facilitation.
  • Adversaries and threat actors: The arrest comes amid an FBI effort to disrupt ShinyHunters' operations; publicly reported law enforcement activity may change how extortion groups advertise assistance, trade data, or approach cloud- and SaaS-focused campaigns.

The record in federal court is, for now, sparse: a sealed complaint, statutory charges listed on a docket, and news reports identifying Dubrovsky as the arrested Canadian executive. What remains clear from the reporting is that the arrest sits at the intersection of two persistent trends identified by authorities — the rise of data-theft extortion models such as ShinyHunters and the market for third-party negotiation services that claim to help victims manage ransom demands.

Source: BleepingComputer — Cyber exec arrested in case allegedly tied to ShinyHunters hackers