Skip to main content
Emerging ThreatsData Breaches

FBI Arrests Cybersecurity Executive in Extortion Case Tied to ShinyHunters Breach

Law enforcement scene with blurred FBI emblem in background and single figure in foreground.

"another suspected co-conspirator," FBI Director Kash Patel wrote on social media — words that, according to court records and contemporaneous reporting, describe the arrest this week of a Canadian cybersecurity executive in Pennsylvania.

The formal allegations against Edward Dubrovsky

Federal court records posted Friday show Edward Dubrovsky, 54, a Canadian and the former chief operating officer and founder of CYPFER, was arrested on Thursday in Pennsylvania on charges that include conspiring to threaten the confidentiality of information in order to extort money — described in the records as a violation of federal computer fraud law — and conspiring to commit Hobbs Act extortion, which involves using threats to obstruct or affect interstate commerce to obtain money. Other details of the case remain sealed in the court file.

How the arrest fits the ShinyHunters investigation

The court filing did not publicly tie Dubrovsky by name to the ShinyHunters group, but multiple public signals link the arrest to the broader probe. The case "appears to align with actions taken in the wake of the ShinyHunters’ attack on the FBI’s IT systems," CyberScoop reported. Director Kash Patel’s social media post said the FBI had arrested "another suspected co-conspirator" of ShinyHunters, though he did not name the suspect. The New York Times similarly reported that a Canadian man was arrested in Pennsylvania in connection with the attack.

The FBI breach drew attention because it exposed personal data about thousands of bureau employees. Brett Leatherman, the FBI’s assistant director for cyber, told reporters that a review found the breach resulted from a third‑party platform where a contractor had not installed a security patch issued for the system; Reuters reported that the contractor worked for Accenture.

CYPFER, CyberSteward and Dubrovsky’s public profile

Dubrovsky’s LinkedIn profile, as noted in the public reporting, lists him as founder and former chief operating officer of CYPFER and shows an affiliation with CyberSteward, which LinkedIn describes as a Toronto-based firm that helps breach victims negotiate ransom payments. Last month Dubrovsky published a book "covering how to deal with ransomware negotiations," according to the same reporting. Neither Dubrovsky nor CYPFER responded to requests for comment from CyberScoop.

Other arrests and investigative threads tied to ShinyHunters

The ShinyHunters cluster of incidents has prompted multiple actions by international and domestic authorities. Reuters and other outlets have reported several detentions since the FBI disclosure: in September Dutch authorities arrested a 24‑year‑old suspected of an affiliation with ShinyHunters, and Reuters reported a teenager identified as Saif Al‑din Khader had been detained and was cooperating with investigators. The group has a recent history of targeting major cloud platforms, healthcare organizations, universities, technology companies, retailers and education service providers; victims cited this year include Instructure, Salesforce, Snowflake and McKesson.

How federal prosecutors have proceeded: transfer to the Eastern District of Texas

Dubrovsky’s docket states the case has been moved to the Eastern District of Texas, where he will be detained until a detention hearing is scheduled. The move places the next public milestone — the detention hearing in the Eastern District of Texas — at the center of any immediate judicial developments in the matter.

What this means for ransomware negotiators, federal investigators, and third‑party contractors

  • Ransomware negotiators and firms used by breach victims: The arrest of a professional associated with firms that advertise negotiation support may sharpen scrutiny of the role third parties play in post‑breach interactions, especially where federal criminal statutes are implicated.
  • Federal investigators and the FBI: The bureau’s public statements and the relocation of the case to a federal district court demonstrate an active criminal response tied to the larger ShinyHunters inquiry and to cross‑border leads reported by international partners.
  • Third‑party contractors and vendors: Public reporting that attributed the FBI breach in part to a failure to apply a patch on a contractor‑run platform — Reuters said the contractor worked for Accenture — underscores the prosecutorial and operational consequences when unpatched systems are implicated in breaches.

The immediate, concrete next step is the detention hearing in the Eastern District of Texas. Until that hearing and any subsequent filings or public remarks, the public record consists of sealed case details, the formal charges in the posted docket, director‑level comments that an arrest has been made, and the broader investigative context linking the action to the ShinyHunters incidents.

Source: CyberScoop