On October 8, the FBI arrested Edward Dubrovsky, co-founder of the Canadian cybersecurity firm CyberSteward, in Pennsylvania amid an investigation into the ShinyHunters hacking group. This group has been linked to the theft of sensitive data from the FBI, including information on thousands of agents. The arrest occurred during a cyber insurance conference, where Dubrovsky was reportedly present to discuss ransomware negotiations.
According to sources familiar with the investigation, Dubrovsky’s firm specializes in negotiating with cybercriminals, which raises questions about his potential involvement with ShinyHunters. The FBI has centralized its investigation into ShinyHunters at a field office in Texas, indicating a significant escalation in their efforts to dismantle the group.
Details of the Arrest
Federal court records indicate that Dubrovsky faces charges of cyber extortion and conspiracy. Although many of the documents related to his case are sealed, some details have emerged, including allegations of conspiracy to threaten the confidentiality of information with the intent to extort money. The case has been moved to the Eastern District of Texas, which is now the focal point of the ShinyHunters investigation.
Dubrovsky’s LinkedIn profile highlights his expertise in ransomware negotiations, and he is the author of a book titled Cyber Extortion Strategic Response. The book discusses strategies for organizations to respond to ransomware incidents, emphasizing that communication with criminals is distinct from negotiating payments.
ShinyHunters’ Modus Operandi
ShinyHunters is known for employing phishing techniques and stolen credentials to access corporate accounts, primarily within software-as-a-service companies. The group then threatens to publish the stolen data unless a ransom is paid. The FBI reports that ShinyHunters has extorted over $70 million from victims this year alone.
Following the arrest of a key member of ShinyHunters, Pepijn van der Stap, by Dutch authorities, another member, identified as “Rey,” took control of the group and taunted the FBI regarding data stolen from the agency’s recruitment portal. Rey, later identified as a teenager named Saif Al-din Khader, has since been detained and is cooperating with investigators.
The FBI’s ongoing investigation into ShinyHunters and its affiliates suggests that further legal actions against individuals involved in ransomware negotiations may be forthcoming. As the situation develops, the implications for cybersecurity firms and their roles in negotiating with cybercriminals will likely come under increased scrutiny.
For more details on the arrest and the ongoing investigation, see the report by KrebsOnSecurity here.


