threat_intelligence1672 wordsRead on Huntaegis

FBI Arrests Executive at Ransomware Negotiation Firm

Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested an executive at a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity. The New York Times reported today that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters. The Times story did not identify the man, nor did a statement on Twitter/X about the arrest from FBI Director Kash Patel. One source close to the investigation told KrebsOnSecurity the Canadian person arrested this week was visiting Pennsylvania for a cyber insurance conference, and that the suspect’s company specialized in handling ransomware negotiations with cybercrime groups. Another shared that control over the ShinyHunters investigation has been centralized at an FBI field office in Texas. An online search reveals the Cyber Risk Summit was held at the Loews Philadelphia Hotel between Oct. 5 and Oct. 7. The conference had several sponsors, but according to the summit’s website its biggest sponsor was a Canadian security company called Cypfer. According to LinkedIn, one of Cypfer’s “ex-founders” was Edward Dubrovsky, who is now associated with another Canadian security firm and sponsor called CyberSteward. In a post to LinkedIn approximately one month ago, Dubrovsky said he had plans to attend the Cyber Risk Summit with the rest of the CyberSteward team. [Update: Oct. 10, 9:58 a.m. ET: A spokesperson for Cypfer said Dubrovsky was not a founder or co-founder as his LinkedIn profile claims, but instead served as a managing director before resigning in November 2025]. “Looking forward to continuing conversations around strategy & compliant driven coercive (ransomware, extortion) advisory, negotiations and settlement services that are global and truly agnostic,” Dubrovsky wrote. Federal court records show that on October 8, an Edward Dobrovsky (note the slight misspelling of the last name) was arrested in Pennsylvania on cyber extortion and conspiracy charges. Several of those documents — including the core complaint — are now sealed. But a handful of them were indexed at Courtlistener.com, including a summary of the complaint, which charges the defendant with “conspiracy to threaten to impair the confidentiality of information with the intent to extort money,” and “interference with commerce by threats.” The inmate locator at the U.S. Bureau of Prisons website reports that a 54-year-old Edward Dubrovsky is currently being held at a federal facility in Philadelphia. But the court records indexed by CourtListener include a notice filed on October 9 that moved the case to the Eastern District of Texas, which sources say is now the epicenter of the FBI’s ShinyHunters investigation. The FBI declined to comment for this story. Dubrovsky’s LinkedIn profile states he is the author of Cyber Extortion Strategic Response, a 252-page book that promises to “take readers beyond the ransom note and into the decisions that determine how an organization responds, recovers, and protects what matters.” “At the heart of the book is a critical distinction: communicating with a criminal is not the same as negotiating a payment, and negotiating is not a commitment to pay,” reads an excerpt from the book’s listing on Amazon. “Engagement can serve other objectives, including testing claims, gathering information, creating time, and preserving options while the organization evaluates its next move.” Mr. Dubrovsky could not be immediately reached for comment. KrebsOnSecurity also sought comment from other executives at CyberSteward, and will update this post in the event they respond. The available court records in Dubrovsky’s case show that he does not currently have an attorney and has yet to be appointed a public defender by the courts. ShinyHunters typically uses phishing and stolen credentials to siphon data from corporate accounts at software-as-a-service companies, and then threatens to publish the stolen data online unless a ransom demand is paid. According to the FBI, the group has extorted more than $70 million from victims so far this year. Sources tell KrebsOnSecurity the FBI has been poring over devices that were seized last month when the Dutch police arrested the convicted cybercriminal Pepijn van der Stap in connection with the ShinyHunters investigation, and that charges against principals at other companies that specialize in ransomware negotiation may be forthcoming. Immediately after Van der Stap’s arrest, another member of ShinyHunters named “Rey” assumed control over the group and began taunting the FBI over data the group stole from the agency’s online recruitment portal, which included each’s person’s unit and specialization, as well as medical and psychiatric records. Last week, Reuters reported that Rey — identified as a teenager named Saif Al-din Khader — had been detained and was cooperating with FBI investigators. On October 7, we detailed how Rey was apprehended as the cybercrime group allegedly sought to extort a navigation and digital aviation unit that was divested by Boeing in late 2025. This is likely to be a fast-moving story. Updates will be noted along with timestamps. The irony here is hard to miss. The industry sells “communicating with a criminal isn’t the same as paying” as a clean distinction, but the line between negotiator and middleman gets blurry fast when the same people sit between victims and extortionists. Charges are only allegations at this point, but if the other firms Brian mentions get charged too, expect a lot more scrutiny of how ransomware negotiators operate and who they’re really accountable to. It’s worse than ironic, it’s sadly common these days in most fields. Once the commercial motive is introduced, there’s a *huge* incentive for the people involved to perpetuate the problem rather than solve it. I think I first ran into it in the early days of the anti-spam efforts, where working solutions were sidelined in favor of poorly functioning technologies that mostly served to give monopoly players control of deliverability. The email phishing that leads to ransomware gangs like Shiny Hunters simply *would not happen* if people just wised up to the fact that these trillion dollar companies aren’t giving you technology advice that works in *your* best interest. So the FBI got another low-level “dealer”. Great. Now let’s see how long it takes them to round up *anyone* from the Epstein-class “supplier” organizations. I love your articles. Great work. The very least the FBI could do would be to post these filth hackass addresses, bank information, family records, social securities, phone numbers and what not, so they end up eaten alive by the same annoyance they created. Die by the sword bastards. Somehow I doubt this government is providing any finders-fees for your work, keep up the good work Krebs. Also I can’t find the direct contact for you anymore, but the comment interface is pretty wonky on my phone, in that the submit button has some odd coloring on my phone, making it hard to see in light mode and almost impossible to see in dark mode. If you’d like some screenshots and further info on my device just email me. Any clue which companies the accused helped with negotiations for? investors.boeing.com/investors/news/press-release-details/2025/Boeing-to-Sell-Portions-of-Digital-Aviation-Solutions-to-Thoma-Bravo-for-10-55-Billion/default.aspx Am wondering what ransomware negotiations he was involved in. For example, was he involved in the United Healthcare/ChangeHealth ransomware incident? Arresting the *founder* rather than the negotiation firm itself is the detail that should worry operators the most. Individual accountability for running a negotiation service is essentially untested — the practice is legal in most jurisdictions as long as the customer is the victim of the incident rather than the perpetrator, and there’s no licensing or registration regime for it. That gap means an arrest is a signal, not a fix. Expect more of these services to move offshore or rebrand under new ownership, and expect the tooling that makes them profitable (leak-site monitoring, initial-access-broker contact lists, automated follow-up) to keep scaling regardless of who gets charged. The part I don’t see covered: how much of the value in this business is the *list* rather than the negotiation. If the negotiation contact itself is worth little to a criminal group — the customer already knows they’re breached — then arresting the negotiator mostly removes a service fee, not a capability. The durable asset is the broker/leak-site relationship feeding targets in. We’ve been writing about the ransomware-as-a-service supply chain here, including recent coverage of negotiation-related arrests and the FBI’s warnings to other groups. https://cyber.murati.net/posts/shinyhunters-leader-arrested-fbi-warns-others Well, Van der Stap also worked in the industry, doing offensive security while volunteering at the Dutch Institute for Vulnerable Disclosure, and it’s well-established that ShinyHunters actively sought to recruit insiders employed at key targets, particularly telecom providers (…while making it very clear they don’t target companies in Russia, Belarus, North Korea, and China… but sure, they are “purely financially motivated”). Fully expecting that as the FBI and European authorities dig deeper, quite a few more people will be found actively playing both sides of the fence. The line between ‘mediating’ an extortion attempt and actively facilitating a federal crime has always been razor-thin in this industry. If negotiators are taking a cut of the payout or coordinating directly with groups like ShinyHunters beyond strict incident response, it’s no longer advisory—it’s collusion. Expect cyber insurance carriers to drastically overhaul their IR vendor requirements after this. If we can’t trust our colleagues on the good side; where do, we go from here with insider threats? With privacy and data protection laws, how can we ferret out operatives that are dual-role actors? In espionage, the double agent? Integrity and trust become obsolete. There is an additional important question about the whole FBI leak affair that needs to be answered: Who in the FBI moved these sensitive personnel files to a server that could be penetrated by outsiders? My guess is that somebody in DOGE did it, in preparation for downloading the files to the DOGE network outside the FBI. This might also mean that private parties in the U.S. have had these files for a long time. Perhaps the next administration will want to get to the bottom of this and punish the perpetrators, if any. The Trump administration most certainly will not.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.