NEWS

Cyber Exec Arrested in Case Allegedly Tied to ShinyHunters Hackers

Canadian cybersecurity exec Edward Dubrovsky, a CYPFER co-founder, was arrested on extortion charges multiple outlets link to the FBI's ShinyHunters probe.

Dylan H.

News Desk

October 10, 2026
5 min read
Cyber Exec Arrested in Case Allegedly Tied to ShinyHunters Hackers

Incident-Response Exec Charged Over Alleged Ties to ShinyHunters Extortion

Edward Dubrovsky, a 54-year-old Canadian cybersecurity executive and co-founder of ransomware-negotiation firm CYPFER, was arrested by FBI agents in Pennsylvania on October 8, 2026, on federal conspiracy and extortion charges. According to BleepingComputer, the arrest has been linked by multiple outlets to the FBI's ongoing crackdown on the ShinyHunters hacking group, though the criminal complaint against Dubrovsky remains sealed and the Bureau has not publicly named him.


Incident Details

AttributeValue
NameEdward Dubrovsky, 54
RoleCo-founder and former COO, CYPFER; also linked to CyberSteward (CYPFER trade name)
Arrest locationPhiladelphia, Pennsylvania — during the NetDiligence Cyber Risk Summit
Arrest dateOctober 8, 2026 (Thursday)
Initial appearanceU.S. District Court, Eastern District of Pennsylvania, before Magistrate Judge Scott W. Reid
Transferred toEastern District of Texas, where charges were filed
ChargesConspiracy and substantive counts under 18 U.S.C. sections 371 and 1030(a)(7)(B) (conspiracy to threaten to impair the confidentiality of information with intent to extort money); 18 U.S.C. section 1951(a) and (b)(2) (Hobbs Act extortion and conspiracy to commit Hobbs Act extortion)
Alleged connectionReported, but not officially confirmed, tie to the ShinyHunters group's breach of FBI IT systems
Case statusDetained; complaint under seal as of October 10, 2026

What Happened

Dubrovsky built his career on the other side of the ransomware fight. He co-founded CYPFER, a Canadian firm that helps breach victims and ransomware targets negotiate with cybercriminals and arrange extortion payments, and was more recently associated with CyberSteward, a Toronto-based entity that operates as a CYPFER trade name offering similar cyber-extortion advisory and settlement services. He also authored a book titled Cyber Extortion Strategic Response, positioning himself publicly as an expert on managing exactly the kind of criminal extortion schemes he now stands accused of conspiring in.

Federal agents took Dubrovsky into custody on October 8 while he was in Pennsylvania attending the NetDiligence Cyber Risk Summit at the Loews Philadelphia Hotel — an industry conference where CYPFER was listed as a sponsor. Court records show he appeared before a magistrate judge in the Eastern District of Pennsylvania under Rule 40, the procedure used when a defendant is arrested outside the district where the case originated, and was ordered detained. On October 9, he was transferred to the Eastern District of Texas, where the underlying charges were filed and where, according to media reports, the FBI has centralized significant parts of its ShinyHunters investigation.

The docket cites two sets of federal charges: conspiracy to threaten the confidentiality of information with intent to extort money, a computer-fraud-adjacent statute, and conspiracy to commit Hobbs Act extortion — using threats to obstruct or affect interstate commerce to obtain money. Neither the publicly available docket entries nor the sealed complaint have yet detailed the specific factual allegations against Dubrovsky, and neither Dubrovsky nor CYPFER had responded to media requests for comment as of this writing.

The ShinyHunters link comes from timing and circumstance rather than an on-the-record FBI statement. FBI Director Kash Patel posted on social media that the Bureau had arrested "another suspected co-conspirator" of ShinyHunters without naming the individual, and outlets including CyberScoop, Politico, and KrebsOnSecurity connected that statement to Dubrovsky's arrest based on overlapping timing, jurisdiction, and case details. The broader investigation traces back to September 2026, when ShinyHunters told BleepingComputer it had breached FBI systems by exploiting an alleged Oracle PeopleSoft zero-day and then moved laterally into FBI-managed AWS GovCloud infrastructure, claiming to have exfiltrated between 2TB and 3TB of data — including records on current and former FBI employees, job applicants, and sensitive medical and psychiatric files. ShinyHunters, which operates in overlapping orbit with Scattered Spider and other extortion-focused crews, has been linked to over $70 million in extortion proceeds from more than 140 organizations. As of publication, public records do not establish that Dubrovsky has been charged specifically in connection with the FBI jobs-portal hack itself.

Why This Matters

  1. Privileged access cuts both ways. Ransomware-negotiation and incident-response firms sit inside victim organizations during their most sensitive moments, often with direct lines of communication to threat actors — a position that, if abused, could blur the line between "negotiator" and "co-conspirator."
  2. The extortion economy has a legitimate-industry seam. CYPFER and similar firms exist precisely because victims need help paying off criminals; this case raises hard questions about how that industry is vetted, audited, and held accountable.
  3. The ShinyHunters crackdown keeps widening. Dubrovsky's arrest follows a string of FBI actions against suspected ShinyHunters associates, suggesting investigators are working outward from the group's core membership toward its broader support network.
  4. A sealed complaint means caution is warranted. Until the factual allegations become public, the ShinyHunters connection remains media-sourced inference rather than confirmed charge language — organizations should track official filings rather than headlines alone.
  5. Vet your incident-response vendors. Enterprises that retain ransomware-negotiation or breach-response firms should confirm those vendors' internal controls, conflict-of-interest policies, and chain-of-custody practices around extortion communications and payments.

Sources