FBI Arrests Ransomware Negotiation Firm Co-Founder in ShinyHunters Probe
FBI arrests Cypfer co-founder Edward Dubrovsky in ShinyHunters investigation.
Summary
The FBI has arrested Edward Dubrovsky, co-founder of the Canadian ransomware negotiation firm Cypfer, in connection with the ShinyHunters investigation into a breach of the FBI's jobs portal. Dubrovsky, now associated with CyberSteward, is a cybersecurity executive specializing in ransomware negotiation and incident response. This arrest follows the detention of another suspected ShinyHunters member, Saif al-Din Khader, and adds scrutiny to companies involved in ransomware recovery.
Full text
Cyber CrimeFBI Arrests Ransomware Negotiation Firm Co-Founder in ShinyHunters ProbebyWaqasOctober 10, 20264 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening FBI arrests Cypfer co-founder Edward Dubrovsky, now associated with CyberSteward, in the ShinyHunters investigation into the FBI jobs portal breach. A co-founder of Canadian ransomware negotiation firm Cypfer has been identified as the person arrested in connection with the FBI’s ShinyHunters investigation, adding an unexpected turn to a case already involving suspected hackers, breached FBI systems and international arrests. The New York Times reported on October 9 that the FBI had arrested a suspect in Pennsylvania connected to the ShinyHunters investigation. Cybersecurity journalist Brian Krebs later identified the suspect as Edward Dubrovsky, a Canadian cybersecurity executive and co-founder of Cypfer. Krebs reported that Dubrovsky is now associated with another Canadian security firm, CyberSteward. Edward Dubrovsky’s LinkedIn profile Dubrovsky is not an unknown figure in cybersecurity. His professional background is in ransomware negotiation and incident response, work normally associated with helping companies respond to extortion attacks. The arrest also comes days after a separate DOJ case against MonsterCloud CEO Zohar Pinhasi, another ransomware recovery figure accused of secretly paying attackers for decryption keys while charging victims higher recovery fees. The two cases are separate, but both put new scrutiny on companies and individuals working around ransomware recovery and negotiation. The FBI has not publicly released Dubrovsky’s name in a formal announcement reviewed by Hackread.com. The exact charges, if any, and his alleged role in the ShinyHunters investigation were not immediately clear at the time of writing. Court records reviewed by Hackread.com show the case was filed in the Eastern District of Pennsylvania on October 8 and terminated there on October 9 after Dubrovsky was committed to the Eastern District of Texas. A bail status order says the government moved for detention, the motion was granted, and Dubrovsky was detained pending a detention hearing in the charging district. CourtListener docket for United States v. Dobrovsky showing the arrest entry, pretrial detention order and transfer to the Eastern District of Texas. Source: CourtListener / RECAP New Arrest Follows Rey Detention The reported arrest follows earlier coverage of suspected ShinyHunters member Saif al-Din Khader, known online as “Rey,” who was detained in Jordan on September 29. Reuters reported that Khader was cooperating with the FBI and other authorities as investigators worked to identify others connected to the group. Hackread.com also reported that the FBI confirmed multiple arrests in the ShinyHunters investigation, but declined to identify all suspects or confirm whether Khader was among them. At the time, the bureau said it was working with international partners and continuing to pursue people involved in the cyber incident. The FBI’s investigation intensified after ShinyHunters claimed responsibility for compromising the FBI’s job application portal (apply.fbijobs.gov). The group claimed it accessed sensitive information belonging to current, former and prospective FBI personnel, including personal and health-related data. Days later, ShinyHunters told Hackread.com that it will not leak the stolen FBI data and that the breach was part of its marketing campaign. The FBI confirmed unauthorized activity affecting the jobs portal but has not publicly verified ShinyHunters’ full claims about the stolen data. 🚨 Our agents in the field have arrested another suspected co-conspirator of the ShinyHunters group – the group believed to be responsible for the recent https://t.co/RG0D4I5KFS incident, which occurred on a platform managed by a third-party vendor.This is the latest arrest…— FBI Director Kash Patel (@FBIDirectorKash) October 9, 2026 PeopleSoft Breach and Contractor Fallout The FBI jobs portal incident has also led to fallout around third-party system management. A missed security patch reportedly left the bureau’s Oracle PeopleSoft jobs portal exposed, leading the FBI to remove a contractor from its assignment. Accenture was identified as the company managing the platform. ShinyHunters previously claimed it exploited a PeopleSoft vulnerability to gain access. Google’s Mandiant separately reported that the group had exploited CVE-2026-35273, a critical flaw in Oracle PeopleSoft’s Environment Management component, and used URL encoding to get around WAF rules blocking the vulnerable endpoint. The newly reported arrest adds another piece to a fast-moving investigation, but several details remain unresolved. Authorities have not publicly explained how Dubrovsky is allegedly connected to the case, whether the arrest is directly related to the FBIJobs.gov breach, or how it fits with the reported detention of Rey and the earlier arrest of Pepijn van der Stap in the Netherlands, the FBI described as an alleged ShinyHunters leader. For now, the confirmed picture is that the FBI’s ShinyHunters investigation has moved from breach response into arrests, international cooperation and questions about how a missed enterprise software patch exposed one of the bureau’s own systems. ShinyHunters Data Breach Download Infrastructure Still Intact and Online Despite the arrests and reported cooperation of suspected members, ShinyHunters’ stolen-data download infrastructure remains active. The group’s dark web leak site has moved in and out of availability in recent days, but its download system is still reachable, with multiple terabytes of stolen data from major companies still available. The situation leaves an open question for investigators and victims. If Rey was operating or helping manage the platform, the continued availability of the download infrastructure may suggest that other people still have access, that parts of the system were separately hosted, or that the backend was not immediately affected by the arrests. None of those possibilities has been confirmed. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts Cyber AttackCyber CrimeCybersecuritydata breachFBIKash PatelPepijn van der StapShinyHunters Leave a Reply Cancel reply View Comments (0) Related Posts Cyber Crime Hacking News RedHack’ Writing off Debt was in retaliation over destruction of 6k olive trees. Last week, RedHack, the world’s first and oldest hacktivist hacker group dating to 1997, had claimed to compromise data… byPushpa Mishra Read More Cyber Crime ATM bombing suspect blew himself up while filming tutorial Europol revealed that the gang was involved in at least fifteen ATM bombings in Germany, causing financial losses of around €2.15 million. byDeeba Ahmed Read More Security Cyber Attacks Cyber Crime Malware Another Country is under massive DDoS attacks – Thanks to Mirai Malware It looks like Mirai malware DDoS botnet is here to stay — Hackers are currently using Mirai to… byWaqas Read More News Cyber Crime Cyber Events Dark Web Genesis Market for Sale: Operators Seek Buyers for Defunct Enterprise Who would buy Genesis Market, which some speculate to be an FBI honeypot operation? byHabiba Rashid