Cyber Extortion Expert Charged With Cyber Extortion Amid FBI Website Hack Manhunt | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Edward Dubrovsky has spent years telling companies how to handle criminals who steal their data and demand payment. Federal prosecutors now accuse the 54-year-old Canadian ransomware negotiator of conspiring to commit cyber extortion himself, and anonymous sources say his case is connected to ShinyHunters, the crew that defaced the FBI’s jobs site last month and demanded the bureau retract a May warning about the hacking group.

According to the federal docket in Philadelphia, which misspells his last name as “Dobrovsky,” Dubrovsky was arrested in Pennsylvania on Thursday. The complaint, which was filed in the Eastern District of Texas and remains under seal, charges him with conspiracy to threaten to impair the confidentiality of information with the intent to extort money, along with Hobbs Act extortion and conspiracy to commit Hobbs Act extortion. A magistrate judge in Philadelphia ordered him held and sent him to Texas for a detention hearing. Dubrovsky hasn’t been convicted or entered a plea, and Politico reported that he could not be reached for comment.

The public filings say nothing about ShinyHunters or the FBI, and FBI Director Kash Patel didn’t name the suspect when he announced a ShinyHunters-related arrest on Friday. “This is the latest arrest this FBI has made in a matter of days involving this network, as we work non-stop to dismantle the group, pursue new leads and evidence, and act quickly,” Patel wrote on X.

Two people with knowledge of the case told the New York Times that Dubrovsky was taken into custody on suspicion of being behind the breach that exposed sensitive data on thousands of FBI employees, and that federal authorities view him as a principal co-conspirator in ShinyHunters’ attack on the bureau. CNN also tied the defendant to the FBI hack through multiple people familiar with the investigation, and a law enforcement source told CBS News the Canadian suspect is believed to be directly involved.

Politico, however, reported that it’s unclear whether Dubrovsky’s case is connected to the FBI hack, though it noted that the timing of the two cases lines up. BleepingComputer also said the sealed complaint leaves open what he allegedly did and whether his case is tied to the breach. The charges listed on the docket center on extortion rather than the intrusion itself.

Who Is Edward Dubrovsky?

When Cypfer, a Toronto ransomware recovery firm, hired Dubrovsky as a managing director in 2022, its press release described a 30-year industry veteran with CISSP, OSCP, and PMP certifications and a seat on York University’s cybersecurity advisory board. “Clients who have been the victims of ransomware need to get up-and-running as soon as possible,” Dubrovsky said in the release.

His LinkedIn profile calls him Cypfer’s chief operating officer and an “ex-founder,” a label the company rejects. A Cypfer spokesperson told security journalist Brian Krebs that Dubrovsky was never a founder and served as a managing director before resigning last November. He’s now associated with CyberSteward, a ransom negotiation firm that litigation identified as a trade name for Cypfer, according to Politico.

One of Krebs’s sources said Dubrovsky was in Philadelphia for the Cyber Risk Summit, a cyber insurance conference that ended the day before his arrest and counted Cypfer as its biggest sponsor. “Looking forward to continuing conversations around strategy & compliant driven coercive (ransomware, extortion) advisory, negotiations and settlement services that are global and truly agnostic,” Dubrovsky wrote in a LinkedIn post about the event.

He has even shared a stage with the bureau now holding him: an InfraGard agenda from the RSA Conference in April 2025 lists him on two panels with agents from the FBI’s San Francisco cyber branch.

On September 24th, two days after ShinyHunters went public with the FBI hack, Dubrovsky self-published Cyber Extortion Strategic Response, a guide to ransomware negotiations.

The ShinyHunters FBI Jobs Site Hack

ShinyHunters’ fake seizure banner went up on FBIjobs.gov on September 22nd. Within two days, outlets reviewing a leaked spreadsheet of roughly 5,000 alleged FBI officials had found records that appeared to identify members of the FBI’s own hacking unit. By September 29th, an internal memo reviewed by the New York Times was telling staff to assume the worst. “We are operating under the premise that the threat actor is also exfiltrating [personally identifiable information] of all F.B.I. employees,” the memo reportedly said.

A day after Dutch police announced the arrest of an alleged ShinyHunters leader, whom Krebs identified as convicted cybercriminal Pepijn van der Stap, FBI Cyber Division Assistant Director Brett Leatherman posted a video addressed to the group’s remaining members. “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left,” Leatherman said. Van der Stap had been arrested around September 15th, before the FBI hack, and the group has denied any association with him. ShinyHunters has since walked back its implied threat to publish the data.

Jordanian authorities then detained Saif al-Din Khader, a suspected member known as “Rey,” who is reportedly cooperating with the FBI. On Monday, the bureau told The Register it had worked with partners to arrest “multiple subjects.” Leatherman also blamed a contractor who failed to apply a security patch to a third-party platform. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,” he said in a statement reported by ABC News.

The ShinyHunters name has been attached to data breaches since at least 2018, and the group has helped other hackers extort their victims as a service, according to BleepingComputer. Leatherman has said the group breached more than 140 organizations and extorted $70 million since last year, the New York Times reported.

In August 2025, ShinyHunters was linked to a wave of Salesforce database attacks that swept up Workday. In December, it used data from a breach of analytics vendor Mixpanel to extort Pornhub over Premium users’ viewing histories. A single voice phishing call in March gave it roughly 900,000 records from identity protection firm Aura, which it dumped online when Aura refused to pay. In May, students logging into Canvas during finals week found a ShinyHunters ransom note where their dashboards should have been.

Another Ransomware Fixer Charged

The day before Dubrovsky’s arrest, Zohar Pinhasi, owner of Florida-based MonsterCloud, was arraigned in Brooklyn on wire fraud charges in an unrelated case. Prosecutors allege his firm billed victims for a decryptor it didn’t have and quietly paid the hackers instead. They say hundreds of companies paid MonsterCloud more than $19 million while Pinhasi paid cybercriminals more than $8 million in ransoms. He pleaded not guilty.

The closer parallel is Angelo Martino, a former DigitalMint ransomware negotiator who pleaded guilty in April to working with the BlackCat/ALPHV ransomware gang. The attackers paid Martino for his clients’ confidential negotiating positions, and he teamed up with two other cybersecurity workers to deploy BlackCat against more victims, including one extorted for about $1.2 million in bitcoin. DigitalMint said it fired the employees involved.

In July, Martino was sentenced to 70 months in prison for conspiring to interfere with interstate commerce through extortion, the same Hobbs Act statute cited in Dubrovsky’s complaint. Sources told Krebs that the FBI has been sifting through devices seized when van der Stap was arrested in the ShinyHunters investigation, and that principals at other ransomware negotiation companies could soon face charges.



Click Here For The Original Source.

——————————————————–

..........

.

.