The founder of a Canadian cybersecurity firm has been arrested by the FBI on suspicion of assisting the notorious ShinyHunters hacking group, which has made headlines for its brazen theft of sensitive data from thousands of law enforcement agents. The arrest is the latest development in an ongoing investigation that has seen the group extort over $70 million from victims this year alone.
Edward Dubrovsky, co-founder of CyberSteward and a well-known expert in ransomware negotiations, was taken into custody on October 8 at a cyber insurance conference in Pennsylvania. Dubrovsky’s company specializes in handling ransomware negotiations with cybercrime groups, raising questions about the blurred lines between cybersecurity professionals and those who enable cybercrime.
According to court records, Dubrovsky is charged with conspiracy to threaten to impair the confidentiality of information with the intent to extort money, as well as interference with commerce by threats. The case has been centralized in an FBI field office in Texas, where investigators are poring over evidence seized from the arrest of Pepijn van der Stap, a convicted cybercriminal who was linked to ShinyHunters.
Dubrovsky’s arrest is particularly significant given his expertise in ransomware negotiations and his authorship of a book on the topic. His book, “Cyber Extortion Strategic Response”, promises to guide readers through the complex process of responding to ransom demands from cybercrime groups. However, experts warn that engaging with these groups can be a delicate balance between negotiating a payment and inadvertently committing to pay.
The ShinyHunters group has made headlines for its brazen theft of sensitive data from corporate accounts at software-as-a-service companies. The group threatens to publish the stolen data online unless a ransom demand is paid, often using phishing and stolen credentials to gain access to victim systems. With over $70 million extorted so far this year, ShinyHunters has become one of the most prolific cybercrime groups in recent memory.
The FBI’s investigation into ShinyHunters has been ongoing for months, with agents working tirelessly to track down those responsible and bring them to justice. The arrest of Dubrovsky is a significant development in this effort, and highlights the need for greater scrutiny of cybersecurity professionals who work with cybercrime groups.
For businesses and individuals alike, this case serves as a reminder that the world of cybersecurity can be a complex and often gray area. As experts like Dubrovsky navigate the intricacies of ransomware negotiations, it’s essential to stay vigilant and aware of the potential risks involved. By understanding the tactics used by cybercrime groups and staying informed about the latest developments in the field, we can all play a role in preventing these types of attacks from happening in the first place.
In practical terms, this case highlights the importance of due diligence when working with cybersecurity professionals or negotiating with cybercrime groups. It’s essential to carefully vet any individuals or companies involved in these processes and to be aware of the potential risks involved. By taking a proactive approach to cybersecurity and staying informed about the latest threats, we can all contribute to a safer and more secure online environment.
Source: Krebs on Security — 2026-10-10