Cybersecurity Negotiator Arrested Amid Ongoing ShinyHunters Investigation
The FBI has made a significant arrest in its ongoing investigation into the notorious hacking group ShinyHunters. Agents have taken into custody Edward Dubrovsky, co-founder of Canadian cybersecurity firm CyberSteward and former co-founder of Cypfer, a company that specialized in handling ransomware negotiations with cybercrime groups.
Dubrovsky’s role in facilitating ransomware negotiations has raised eyebrows in the cybersecurity community, particularly given his involvement in the ShinyHunters investigation. According to court records, Dubrovsky was visiting Pennsylvania for a cyber insurance conference when he was arrested on October 8th. He is now being held at a federal facility in Philadelphia and faces charges of conspiracy to threaten to impair the confidentiality of information with the intent to extort money.
ShinyHunters has made headlines this year due to its brazen tactics, which involve phishing and stolen credentials to siphon data from corporate accounts at software-as-a-service companies. The group then threatens to publish the stolen data online unless a ransom demand is paid, raking in over $70 million in extorted funds so far this year.
Dubrovsky’s arrest has significant implications for the cybersecurity industry, particularly those involved in ransomware negotiations. His company, CyberSteward, touts itself as a global leader in providing “coercive advisory, negotiations and settlement services” to organizations under threat from cybercrime groups like ShinyHunters. Dubrovsky himself is an author of a book on the topic, which promises to “take readers beyond the ransom note and into the decisions that determine how an organization responds, recovers, and protects what matters.”
The fact that Dubrovsky was involved in facilitating negotiations with cybercrime groups like ShinyHunters has sparked questions about his company’s true motives. Was he operating as a legitimate cybersecurity expert or playing a more insidious role in enabling the very hackers he claimed to be negotiating against?
The investigation is ongoing, and it remains to be seen whether Dubrovsky’s arrest will have far-reaching consequences for the cybersecurity industry. For now, one thing is clear: organizations under threat from cybercrime groups like ShinyHunters must exercise extreme caution when engaging with companies or individuals who claim to offer ransomware negotiation services.
As we navigate this complex landscape of cybersecurity threats and negotiations, it’s essential to prioritize transparency and vigilance. Cybersecurity professionals and organizations should approach such situations with a healthy dose of skepticism, carefully evaluating the motivations and credentials of those offering assistance. By doing so, they can better protect themselves and their clients from the growing threat of cybercrime.
Source: Krebs on Security — 2026-10-10