A Ransomware Negotiator Accused of Working for the Extortionists
KrebsOnSecurity has identified the previously unnamed Canadian national arrested by the FBI in Pennsylvania this week as Edward Dubrovsky, 54 — co-founder of the Canadian ransomware-negotiation firm Cypfer and a figure also associated with a second Canadian security firm, CyberSteward. Dubrovsky was arrested on October 8, 2026, while attending the Cyber Risk Summit at the Loews Philadelphia Hotel (October 5–7) — an event Cypfer sponsored as its largest backer. He is currently held at a federal facility in Philadelphia, according to the Bureau of Prisons inmate locator.
The arrest ties directly into the FBI's ongoing investigation of ShinyHunters, the extortion group that breached the bureau's own recruitment portal, FBIjobs.gov, exposing sensitive data on more than 5,000 FBI personnel and job applicants — including unit assignments, specializations, and medical and psychiatric records. FBI Director Kash Patel announced the arrest on X without naming the suspect, describing it as "the latest arrest this FBI has made in a matter of days" as the bureau works "non-stop to dismantle the group." That unnamed announcement matches the Pennsylvania arrest CosmicBytez Labs previously reported — Krebs' reporting now puts a name to it.
The Twist: A Negotiator Allegedly Working the Other Side
What makes this arrest notable isn't simply another ShinyHunters-linked name — it's the role investigators allege Dubrovsky played. Ransomware negotiation firms exist to represent victims: they broker ransom payments down, buy time, and liaise with extortion gangs on a client's behalf. Prosecutors allege Dubrovsky instead used that position to assist ShinyHunters directly, rather than solely defend the organizations paying for his services.
| Attribute | Value |
|---|---|
| Suspect | Edward Dubrovsky (listed in court filings as "Edward Dobrovsky"), 54 |
| Nationality | Canadian |
| Firms | Co-founder, Cypfer; also associated with CyberSteward |
| Arrested | October 8, 2026, Philadelphia, Pennsylvania |
| Charges | Conspiracy to threaten to impair confidentiality of information with intent to extort money; interference with commerce by threats |
| Case venue | Moved October 9, 2026, to the Eastern District of Texas |
| Custody | Federal facility, Philadelphia (per BOP inmate locator) |
Krebs notes the case's move to the Eastern District of Texas — now described as the hub of the FBI's broader ShinyHunters investigation — and flags that it raises the prospect of further charges against other ransomware-negotiation-firm principals, not just Dubrovsky.
The FBI's Own Breach, Recapped
ShinyHunters first disclosed its access to FBI systems in September 2026, claiming to have exploited an Oracle PeopleSoft zero-day on the bureau's jobs portal before pivoting into FBI-managed AWS GovCloud infrastructure. According to FBI Cyber Division Assistant Director Brett Leatherman, the root cause traced back to a third-party-managed platform: a contractor — reportedly Accenture — failed to apply a security patch the FBI had issued, and was subsequently removed from the bureau's work as a result.
ShinyHunters has extorted more than $70 million from victims across 2026, and the FBIjobs.gov breach has been compared in severity to the 2015 Office of Personnel Management (OPM) hack for the scale of sensitive personnel data exposed.
Other Arrests Tied to the Case
- Pepijn van der Stap ("Umbreon"), 24 — arrested by Dutch police in Amsterdam, September 29, 2026
- Saif al-Din Khader ("Rey") — a teenager detained in Jordan, reported to be cooperating with the FBI as of early October 2026
- Edward Dubrovsky — arrested in Pennsylvania, October 8, 2026 (this report)
The RCMP has confirmed it is aware of "the arrest of a Canadian in the US in connection with the ShinyHunters hack." No public statement has been issued by Dubrovsky, Cypfer, or CyberSteward.
Why This Matters for Security Teams
- Vet your incident-response and negotiation vendors as rigorously as any other third party with breach-time access. A ransomware negotiator sits in an extraordinarily sensitive position — in direct contact with extortion groups, often privy to a victim's full exposure and willingness to pay. An allegedly compromised or complicit negotiator can actively work against the client that hired them.
- "Who represents you during a ransomware incident" is itself a supply-chain-risk question. Due diligence on negotiation and IR firms — ownership, affiliations, and any history of irregular outcomes — deserves the same scrutiny organizations apply to software vendors.
- Third-party patch management keeps resurfacing as the root cause of major breaches. The underlying FBI breach again traces to an unpatched, contractor-managed platform — a pattern that should inform how organizations structure patch SLAs and audit rights with vendors managing internet-facing systems.
- Expect the ShinyHunters investigation to keep widening. With the case now centered in the Eastern District of Texas and prosecutors reportedly eyeing other negotiation-firm principals, this is unlikely to be the final arrest connected to the case.