A Canadian cybersecurity executive who built a career advising companies on how to handle ransomware demands is now in federal custody facing extortion charges, an arrest that comes as the FBI escalates a sweeping crackdown on the ShinyHunters hacking group.
Edward Dubrovsky, 54, was taken into custody Thursday in the Philadelphia area, according to federal court documents. The docket in the Eastern District of Pennsylvania lists charges including conspiracy to threaten the confidentiality of information with intent to extort money and interference with commerce, though the underlying complaint remains sealed in the Eastern District of Texas.
A magistrate judge in Philadelphia ordered Dubrovsky held pending a detention hearing, and a subsequent order directed the U.S. Marshals Service to transport him to Texas for further proceedings. The Federal Bureau of Prisons lists him as detained at the Federal Detention Center in Philadelphia with no release date specified.
FBI Director Kash Patel announced Friday on X that agents had arrested “another suspected co-conspirator of the ShinyHunters group,” the network believed responsible for breaching the bureau’s jobs website last month. Patel did not name the suspect, and authorities have not publicly confirmed whether Dubrovsky is that individual.
Two people with knowledge of the case told the New York Times that federal authorities view Dubrovsky as a principal co-conspirator in the ShinyHunters attack on the FBI. CNN also tied the defendant to the breach through multiple sources familiar with the investigation. Politico, however, reported that it remains unclear whether the case is connected to the FBI hack, noting only that the timing lines up.
The charges listed on the docket center on extortion rather than the intrusion itself, leaving open the question of what specific conduct triggered the prosecution.
A Career Built on Negotiating With Attackers
Dubrovsky’s professional identity has long been intertwined with the ransomware economy. His LinkedIn profile describes him as a specialist in negotiating with cybercriminals over ransom payments and lists an affiliation with CyberSteward, a firm advertising services in threat actor engagement, cyber extortion, and settlement facilitation.
When Toronto-based ransomware recovery firm Cypfer hired him as a managing director in 2022, its press release described a 30-year industry veteran holding CISSP, OSCP, and PMP certifications along with a seat on York University’s cybersecurity advisory board. “Clients who have been the victims of ransomware need to get up-and-running as soon as possible,” Dubrovsky said in the release at the time.
A Cypfer spokesperson told security journalist Brian Krebs that Dubrovsky was never a founder of the company, despite his LinkedIn profile describing him as an “ex-founder,” and that he served as a managing director before resigning last November. Litigation has identified CyberSteward as a trade name for Cypfer, according to Politico.
Dubrovsky was in Philadelphia for the Cyber Risk Summit, a cyber insurance conference that ended the day before his arrest and counted Cypfer as its biggest sponsor. Two days after ShinyHunters went public with the FBI breach, he self-published a guide titled “Cyber Extortion Strategic Response.”
His ties to law enforcement extended beyond the current investigation. An InfraGard agenda from the RSA Conference in April 2025 lists Dubrovsky on two panels alongside agents from the FBI’s San Francisco cyber branch.
The ShinyHunters Breach
ShinyHunters defaced FBIjobs.gov with a fake seizure banner on September 22, claiming to have stolen information on nearly every FBI employee. Within days, journalists reviewing a leaked spreadsheet of roughly 5,000 alleged FBI officials found records appearing to identify members of the bureau’s own hacking unit.
By September 29, an internal memo reviewed by the New York Times told staff to assume the worst. “We are operating under the premise that the threat actor is also exfiltrating [personally identifiable information] of all F.B.I. employees,” the memo reportedly said.
FBI Cyber Division Assistant Director Brett Leatherman has said the group breached more than 140 organizations and extorted $70 million since last year. In a video addressed to ShinyHunters’ remaining members, he warned: “Arrests have a way of changing who is willing to talk, and seized infrastructure has a way of showing us who’s left.”
The bureau has blamed a contractor for failing to apply a security patch to a third-party platform that hosted the jobs site. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,” Leatherman said in a statement.
A Widening Crackdown
The arrest of Dubrovsky is the latest in a series of actions against individuals linked to ShinyHunters and the broader ransomware negotiation industry.
| Individual | Role | Status |
|---|---|---|
| Pepijn van der Stap | Alleged ShinyHunters leader | Arrested in Netherlands around Sept. 15 |
| Saif al-Din Khader | Suspected member known as “Rey” | Detained in Jordan, reportedly cooperating |
| Edward Dubrovsky | Ransomware negotiator | Arrested Oct. 9 in Philadelphia |
| Angelo Martino | Former DigitalMint negotiator | Sentenced to 70 months in July |
| Zohar Pinhasi | Owner of MonsterCloud | Arraigned Oct. 8 on wire fraud charges |
Note: Van der Stap’s arrest predates the FBI breach; ShinyHunters has denied any association with him.
A day before Dubrovsky’s arrest, Zohar Pinhasi, owner of Florida-based MonsterCloud, was arraigned in Brooklyn on wire fraud charges in an unrelated case. Prosecutors allege his firm billed victims for a decryptor it did not have and quietly paid hackers instead. They say hundreds of companies paid MonsterCloud more than $19 million while Pinhasi paid cybercriminals more than $8 million in ransoms. He pleaded not guilty.
The closer parallel is Angelo Martino, a former DigitalMint ransomware negotiator who pleaded guilty in April to working with the BlackCat/ALPHV ransomware gang. The attackers paid Martino for his clients’ confidential negotiating positions, and he teamed up with two other cybersecurity workers to deploy BlackCat against additional victims. In July, he was sentenced to 70 months in prison for conspiring to interfere with interstate commerce through extortion — the same Hobbs Act statute cited in Dubrovsky’s complaint.
Sources told Krebs that the FBI has been sifting through devices seized when van der Stap was arrested and that principals at other ransomware negotiation companies could soon face charges.
The ShinyHunters name has been attached to data breaches since at least 2018. In August 2025, the group was linked to a wave of Salesforce database attacks that swept up Workday. In December, it used data from a breach of analytics vendor Mixpanel to extort Pornhub over Premium users’ viewing histories. A single voice phishing call in March gave it roughly 900,000 records from identity protection firm Aura, which it dumped online when the company refused to pay.
ShinyHunters has since walked back its implied threat to publish the FBI data.
Click Here For The Original Source.
