Ransomware Negotiation Firm Co-Founder Charged With Conspiracy to Extort
Edward Dubrovsky, 54, a Canadian cybersecurity executive and co-founder and former chief operating officer of CYPFER — a firm that negotiates with ransomware operators on behalf of breach victims — was arrested on federal extortion charges in the Philadelphia, Pennsylvania area in early October 2026, according to CyberScoop. Dubrovsky was reportedly in town for the Cyber Risk Summit at the Loews Philadelphia Hotel, where CYPFER was listed as the event's largest sponsor, when he was taken into custody. He appeared in federal court in Philadelphia, where a magistrate judge appointed a federal public defender, and the case has since been transferred to the Eastern District of Texas for a detention hearing. The timing of the arrest coincides with an active federal investigation into ShinyHunters' breach of FBI IT systems, though publicly available records do not establish that Dubrovsky has been charged specifically in connection with that hack — the underlying criminal complaint remains sealed.
Incident Details
| Attribute | Value |
|---|---|
| Individual charged | Edward Dubrovsky, 54, Canadian national |
| Role | Co-founder and former COO, CYPFER; also associated with CyberSteward, a Toronto-based ransom-negotiation trade name reportedly used by CYPFER |
| Arrest location | Philadelphia-area, Pennsylvania (while attending the Cyber Risk Summit) |
| Arrest timeframe | Early October 2026; case reported October 9-10, 2026 |
| Charges | Conspiracy to threaten the confidentiality of information to extort money (18 U.S.C. §§ 371, 1030(a)(7)(B)); conspiracy to commit Hobbs Act extortion (18 U.S.C. § 1951(a), (b)(2)) |
| Current jurisdiction | Transferred to the Eastern District of Texas for a detention hearing |
| Case status | Underlying complaint sealed; full scope of allegations not publicly confirmed |
| Possible connection | Timing aligns with DOJ/FBI action following ShinyHunters' breach of FBI IT systems |
What Happened
Dubrovsky co-founded CYPFER, a firm whose business is helping ransomware victims communicate with, and in many cases pay, the criminal groups holding their data or systems hostage. He has also been linked to CyberSteward, which Politico has reported is a trade name used by CYPFER for the same line of work, and he recently published a book on ransomware negotiation tactics — positioning him publicly as an expert on the defender's side of extortion incidents rather than a perpetrator. According to CyberScoop's reporting, federal agents arrested him while he was in the Philadelphia area for the Cyber Risk Summit, an industry cyber-insurance conference at the Loews Philadelphia Hotel where CYPFER was the event's top sponsor.
The specific conduct underlying the charges has not been made public. The criminal complaint against Dubrovsky remains sealed, and court filings reviewed by reporters describe the charges in statutory terms — conspiracy to threaten the confidentiality of information in order to extort money, a federal computer-fraud violation, and conspiracy to commit Hobbs Act extortion, which covers using threats to obstruct or affect interstate commerce for financial gain — without detailing the victims, amounts, or specific acts alleged. A magistrate judge in Philadelphia appointed Dubrovsky a federal public defender before the case was moved to the Eastern District of Texas, where he is due for a detention hearing.
The ShinyHunters Connection
The arrest surfaced in the same window as a broader federal push against the extortion group ShinyHunters, which breached FBI IT systems and exposed personal data belonging to bureau employees. That intrusion reportedly traced back to an unpatched vulnerability in a third-party platform used by an Accenture contractor supporting FBI systems. FBI Director Kash Patel posted on social media that the bureau had arrested "another suspected co-conspirator" of ShinyHunters, without naming the individual publicly. The New York Times separately confirmed that a Canadian national had been arrested in Pennsylvania in connection with the ShinyHunters investigation — a description consistent with Dubrovsky's arrest, though neither the FBI nor the unsealed court record has explicitly tied his charges to the FBI breach itself.
ShinyHunters has been one of the most active extortion crews of 2026, previously claiming attacks tied to Salesforce-connected data theft campaigns, Snowflake-linked breaches, Instructure, and McKesson. Other individuals connected to the group's recent activity include a 24-year-old Dutch suspect and a teenager identified as Saif Al-din Khader, both detained separately. Because Dubrovsky's complaint is sealed, it remains unclear whether prosecutors allege he personally dealt with ShinyHunters, acted as an intermediary in extortion payments, or is accused of conduct connected to a different incident entirely that happened to surface during the same investigative window.
Why This Matters
- Ransom-negotiation firms sit at a uniquely exposed trust position. Companies that broker payments between victims and extortion groups handle sensitive victim data, cryptocurrency flows, and direct lines of communication with criminal actors — any allegation of misconduct in that role raises hard questions about oversight of an industry that operates with little formal regulation.
- The charges, standing alone, are allegations — not findings of guilt. The complaint against Dubrovsky is sealed and the specific conduct unconfirmed; organizations and individuals should avoid treating this as a confirmed account of what happened until charging documents are unsealed or a plea/trial resolves the matter.
- The ShinyHunters FBI breach continues to generate downstream fallout. A breach of internal government systems via a third-party contractor vulnerability is producing an expanding set of arrests and investigative threads well beyond the original intrusion, underscoring how a single supply-chain weakness can cascade into a sprawling, multi-defendant federal case.
- Victim organizations should scrutinize who is on the other end of a ransom negotiation. Breach victims relying on third-party negotiators should ask about vetting, conflicts of interest, and chain-of-custody controls over extortion communications and payments — not just claimed success rates.
- Federal computer-fraud and Hobbs Act extortion statutes remain the primary tools against cyber-extortion facilitators. The specific charges here reflect a now-familiar prosecutorial pattern for cyber-extortion cases, applicable whether the defendant is an attacker, an intermediary, or someone alleged to have abused a trusted negotiator role.
- Expect more names to surface as the ShinyHunters investigation matures. With a Dutch national, a teenage suspect, and now a cybersecurity industry executive all drawn into related proceedings, the case illustrates how extortion ecosystems can span attackers, facilitators, and — if allegations bear out — even figures nominally working on the defense side.