FBI arrests Edward Dubrovsky, co-founder of ransomware negotiation firm, amid ShinyHunters investigation

Published:

On October 8, the FBI arrested Edward Dubrovsky, co-founder of the Canadian cybersecurity firm CyberSteward, in Pennsylvania amid an investigation into the ShinyHunters hacking group. This group has been linked to the theft of sensitive data from the FBI, including information on thousands of agents. The arrest occurred during a cyber insurance conference, where Dubrovsky was reportedly present to discuss ransomware negotiations.

According to sources familiar with the investigation, Dubrovsky’s firm specializes in negotiating with cybercriminals, which raises questions about his potential involvement with ShinyHunters. The FBI has centralized its investigation into ShinyHunters at a field office in Texas, indicating a significant escalation in their efforts to dismantle the group.

Details of the Arrest

Federal court records indicate that Dubrovsky faces charges of cyber extortion and conspiracy. Although many of the documents related to his case are sealed, some details have emerged, including allegations of conspiracy to threaten the confidentiality of information with the intent to extort money. The case has been moved to the Eastern District of Texas, which is now the focal point of the ShinyHunters investigation.

Dubrovsky’s LinkedIn profile highlights his expertise in ransomware negotiations, and he is the author of a book titled Cyber Extortion Strategic Response. The book discusses strategies for organizations to respond to ransomware incidents, emphasizing that communication with criminals is distinct from negotiating payments.

ShinyHunters’ Modus Operandi

ShinyHunters is known for employing phishing techniques and stolen credentials to access corporate accounts, primarily within software-as-a-service companies. The group then threatens to publish the stolen data unless a ransom is paid. The FBI reports that ShinyHunters has extorted over $70 million from victims this year alone.

Following the arrest of a key member of ShinyHunters, Pepijn van der Stap, by Dutch authorities, another member, identified as “Rey,” took control of the group and taunted the FBI regarding data stolen from the agency’s recruitment portal. Rey, later identified as a teenager named Saif Al-din Khader, has since been detained and is cooperating with investigators.

The FBI’s ongoing investigation into ShinyHunters and its affiliates suggests that further legal actions against individuals involved in ransomware negotiations may be forthcoming. As the situation develops, the implications for cybersecurity firms and their roles in negotiating with cybercriminals will likely come under increased scrutiny.

For more details on the arrest and the ongoing investigation, see the report by KrebsOnSecurity here.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CrowdStrike partners with Anthropic to enhance AI-driven defenses for critical infrastructure security

In a significant move to bolster defenses for critical infrastructure, CrowdStrike has partnered with Anthropic to enhance AI-driven security measures. This collaboration aims to...

Prasan Nepal, leader of child sextortion group 764, pleads guilty to exploitation charges

A 21-year-old from North Carolina, Prasan Nepal, has pleaded guilty to conspiracy to commit sexual exploitation of a child, marking a significant development in...

Coast Guard orders four MQ-9B SeaGuardian drones for $248 million to enhance maritime surveillance capabilities

In a significant move to enhance its maritime surveillance capabilities, the U.S. Coast Guard has placed an order for four MQ-9B SeaGuardian drones, valued...

UK and international partners warn of China-linked Integrity Tech enabling global cyber threats

The UK’s National Cyber Security Centre (NCSC) and eight international partners have issued a stark warning regarding the activities of Integrity Technology Group, a...