A Canadian cybersecurity executive has been arrested in Pennsylvania in a case multiple reports link to the FBI’s ongoing investigation into the ShinyHunters extortion group. Edward Dubrovsky, 54, held senior roles at firms that help data breach and ransomware victims negotiate with cybercriminals.
FBI Director Kash Patel announced the arrest of “another suspected co-conspirator of the ShinyHunters group,” though the Bureau has not publicly named the suspect. The New York Times reported the individual is a Canadian citizen arrested in Pennsylvania believed to be a primary co-conspirator in the recent ShinyHunters hack of an FBI jobs portal. Politico and KrebsOnSecurity later identified the suspect as Dubrovsky, who was reportedly attending a cybersecurity conference in the state at the time.
Court records show Dubrovsky appeared in the Eastern District of Pennsylvania before being transferred to the Eastern District of Texas, where the charges were filed. He remains in custody. The complaint itself is sealed, but the docket lists charges including conspiracy to threaten to impair the confidentiality of information with intent to extort money, along with Hobbs Act extortion and conspiracy to commit Hobbs Act extortion.
Ties to ransomware negotiation industry
Dubrovsky co-founded Canadian cybersecurity firm CYPFER and has also been associated with CyberSteward, a ransomware negotiation and cyber-extortion response firm. According to Politico, CyberSteward operates as a trade name under CYPFER, and both firms assist organizations in negotiating and sending extortion payments to threat actors. Dubrovsky recently authored a book on cyber extortion response and had posted on LinkedIn about plans to attend the NetDiligence Cyber Risk Summit in Pennsylvania with the CyberSteward team.
ShinyHunters crackdown intensifies
ShinyHunters is known for stealing data from web applications and SaaS platforms and extorting victims under threat of public leaks. The name has been used by multiple threat actors globally, and the group has also run an extortion-as-a-service operation for other hackers. The FBI says ShinyHunters and associated actors have breached more than 140 organizations and collected over $70 million in extortion payments over the past year, increasingly by abusing stolen credentials, authentication tokens, phishing, and social engineering against cloud and enterprise environments.
Since the breach of the FBI’s own jobs portal, the Bureau has escalated pressure on the group with multiple recent arrests and detentions of suspected members. Because the complaint against Dubrovsky remains sealed, it is not yet clear exactly what conduct he is accused of or whether the case ties directly to the FBI portal breach.
