FBI arrests cybersecurity executive and ransomware expert in major hack on agents’ data | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The FBI arrested a Canadian cybersecurity executive and ransomware expert as part of the investigation of a damaging hack that exposed the sensitive data of current and former FBI employees, according to court documents and people familiar with the investigation.

Video above: FBI Director Kash Patel defends policies during congressional hearing

Edward Dubrovsky was arrested in the Philadelphia area in recent days and appeared in federal court there Thursday, where a magistrate judge appointed a federal public defender to represent him. Dubrovsky is facing charges related to extortion and making threats. He has been transferred to Texas’s Eastern District for a scheduled detention hearing, according to court records and a law enforcement official.

FBI Director Kash Patel announced the arrest on Friday but did not disclose where it occurred or what role the man is suspected of playing in the hack. Patel also didn’t name Dubrovsky, but CNN confirmed the defendant is believed to be tied to the FBI hack through multiple people familiar with the investigation.

“Earlier this week, our agents in the field arrested another suspected co-conspirator” of the cybercriminal group believed to be responsible for the hack, Patel said on Friday.

A federal law enforcement official confirmed the spelling of Dubrovsky’s name. In original court documents, his last name was misspelled.

An investigation is ongoing into other people believed to be involved in the hack, the sources said.

Dubrovsky did not immediately respond to a request for comment on Friday night, nor did the public defender’s office in Philadelphia.

A LinkedIn profile under Dubrovsky’s name lists years of experience in the Canadian cybersecurity industry and describes Dubrovsky as a “globally recognized cybersecurity expert.” An Ed Dubrovsky is also the author of a book on handling ransomware negotiations with cybercriminals.

The arrest comes after one of the most serious breaches of the bureau’s data in years. A prolific cybercriminal group known as ShinyHunters last month claimed responsibility for breaking into an FBI jobs portal and gaining access to the personal data on thousands of current and former FBI employees. The identities of FBI personnel working in sensitive units on China and Russia were exposed, according to people who have seen the data.

Independent journalist Brian Krebs earlier reported Dubrovsky’s alleged connection to the investigation into the hack of the FBI.

The FBI declined to comment on Friday night when CNN asked about Dubrovsky’s arrest.

The FBI has pursued other suspects in the investigation. Last week, the FBI announced that Dutch authorities arrested “one of the alleged leaders” of ShinyHunters.

Aftermath of the FBI hack

ShinyHunters used their dark-web site to demand that the FBI amend a previous advisory issued about the group, before the hack, saying it was “offended” over how the agency described its alleged tactics for extorting victim organizations. Many in the cybersecurity industry took the demand as a tacit threat that ShinyHunters would leak the stolen data. The hackers later claimed that was never their intention.

Some FBI employees felt underwhelmed by the security resources being offered to victims of the breach, CNN previously reported.

Amid the internal criticism and media scrutiny, Patel and a senior FBI cyber official, Brett Leatherman, put out a series of public statements and video messages with updates on the investigation. Some were addressed to the cybercriminals.

“Arrests have a way of changing who is willing to talk and seized infrastructure has a way of showing us who is left,” Leatherman said in a video posted after the arrest by Dutch authorities.

“The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”

There has also been an inquest at the FBI over how such a critical security lapse happened. The FBI determined that a contractor managing the bureau’s jobs portal failed to update software “explicitly issued to secure the platform,” Leatherman said last week. The FBI has “removed the contractor,” he said.

The software in question is a human-resources platform made by Oracle, ShinyHunters has said.

The hackers previously used a flaw in the software to attack targets in the education sector in May and June, according to Google’s Threat Intelligence Group. But months later, the FBI contractor apparently still had not applied a security patch that was available for the software.

——————————————————-


Click Here For The Original Source.