Abstract:
The FBI recently arrested a co-founder of a Canadian cybersecurity company. This person has long been engaged in ransomware incident response and ransom negotiation business, and is currently facing federal criminal charges for allegedly assisting the hacker group ShinyHunters. This case is not only related to the recent theft of sensitive information of a large number of FBI employees, but may also further draw attention to the relationship between cybersecurity consulting companies, ransomware negotiation services, and the cybercrime industry chain.

According to information disclosed on October 9 by the KrebsOnSecurity website run by cybersecurity investigative reporter Brian Krebs, FBI agents arrested Edward Dubrovsky, co-founder of a Canadian cybersecurity company, in Pennsylvania on October 8, local time. Previously, the New York Times reported that the FBI arrested a Canadian man in Pennsylvania on suspicion of assisting the ShinyHunters hacker group, but did not release his name.
Multiple people familiar with the matter told KrebsOnSecurity that Dubrovsky was attending a cyber insurance industry conference in Pennsylvania when he was arrested. His company's business involves negotiating ransomware payments with cybercriminals and providing response and negotiation services to businesses that have suffered cyberattacks.
According to information on the relevant conference website, the Cyber Risk Summit will be held at the Loews Hotel in Philadelphia from October 5th to 7th. One of the major sponsors of the conference is Canadian cybersecurity company Cypfer. Public LinkedIn profiles show that Dubrovsky was a co-founder of Cypfer and is currently associated with another Canadian cybersecurity company, CyberSteward.
Dubrovsky previously stated on LinkedIn that he planned to attend the conference with the CyberSteward team and looked forward to continuing to discuss strategic consulting, negotiation and solutions in ransomware and cyber extortion incidents with industry insiders.
Public records in the U.S. federal court show that Edward Dobrovsky, whose last name is spelled slightly differently, was arrested in Pennsylvania on October 8 and faced charges related to Internet extortion and conspiracy. Some court documents, including core prosecution materials in the case, have been sealed. However, some documents are still included in the legal information website CourtListener.
Existing court records show that related charges include conspiracy to threaten to compromise the confidentiality of information for the purpose of extorting money and interfering with commercial activities through threats. It should be noted that the current public information is still limited, some key documents of the case have not yet been made public, and the relevant charges do not mean that the defendant has been found guilty by the court.
The website of the U.S. Federal Bureau of Prisons shows that a 54-year-old Edward Dubrovsky is currently being held in a federal facility in Philadelphia. At the same time, court records show that the case was transferred to the Federal District Court for the Eastern District of Texas on October 9. People familiar with the matter said that the FBI has focused its investigation into the ShinyHunters organization to a field office in Texas.
The FBI did not comment to KrebsOnSecurity regarding Dubrovsky's arrest. At the time of the report, Dubrovsky had not yet been publicly confirmed to have retained an attorney, and court records show he had not yet obtained a court-appointed public defender at the time.
Dubrovsky has also written a book called "Cyber Extortion Strategic Response", which is about 252 pages in length and focuses on how companies can assess threats, develop response plans, communicate and protect their own interests after encountering a ransomware attack.

A core point in the book is that communicating with criminals does not mean agreeing to pay a ransom; participating in negotiations does not mean that payment must eventually be made. Engagement with the attacker may have other purposes, such as verifying the authenticity of the data claimed to have been stolen, gathering additional information, buying time to deal with the incident, and preserving options while the organization evaluates different response options.
This view reflects a principle long-emphasized in the ransomware incident response industry: the role of professional negotiators is not just to help victims lower the ransom, but may also include determining what information the attacker has, assessing the credibility of the threat, and assisting enterprises in developing strategies to restore business and reduce losses.
However, Dubrovsky's arrest has raised new questions for the industry. If a company that negotiates extortion incidents for businesses is suspected of having inappropriate ties to a hacker group, the line between its business activities and cybercrime could become the focus of a law enforcement investigation.
This arrest is closely related to the ongoing investigation of the ShinyHunters hacking group. The organization has frequently launched attacks against software-as-a-service companies in recent years. It usually enters corporate systems through phishing, stealing account credentials, etc., obtains customer or internal data, and then threatens to make the stolen information public to force victims to pay ransom.
According to information previously disclosed by the FBI, ShinyHunters has extorted more than $70 million from victims so far this year. The group's attack model often does not require large-scale damage to the victim's system, but uses the threat of stealing data and making it public as the main pressure method.
This model makes it possible for enterprises to face serious follow-up risks even if they can quickly restore their systems. If an attacker has copied customer data, employee information, or trade secrets, reinstalling the server and restoring backups will not eliminate the impact of the data breach. As a result, businesses may need to juggle business recovery, privacy notices, legal liability, regulatory reporting, and potential extortion negotiations.
Recently, ShinyHunters also claimed to have hacked into the FBI's online recruitment portal and stolen a large amount of sensitive employee information. The stolen data allegedly included employees' departments, areas of expertise, and medical and mental health records. After the incident was exposed, the hacker organization used this information to further provoke the FBI, causing the investigation to rapidly escalate.
The FBI is currently tracking down relevant members of the organization and analyzing previously seized electronic devices and digital communication records. KrebsOnSecurity cited people familiar with the matter as saying that investigators are examining devices seized by Dutch police when they arrested cybercriminal Pepijn van der Stap last month. These devices may contain information that could help identify the identities and movements of others involved.
After Van der Stap was arrested, another member of ShinyHunters began to operate under the name "Rey" and took over part of the organization's operations. This person then used the FBI data leak to publicly provoke U.S. law enforcement agencies.
Reuters previously reported that "Rey" was identified as a teenager named Saif Al-din Khader. He was detained by local law enforcement in Jordan last week and is reportedly cooperating with the FBI investigation. Krebs previously reported that the group was suspected of trying to extort a navigation and digital aviation company that was spun off from Boeing before Khader was detained.

As the investigation continues to advance, U.S. law enforcement agencies are trying to sort out ShinyHunters’ organizational relationships, membership identities, attack activities, and potential business connections. Investigators need to determine not only who was actually involved in the cyber intrusion, but also whether there were others who provided negotiation, money transfer or other assistance to the hackers.
KrebsOnSecurity quoted sources as saying that related investigations into other companies in the ransomware negotiation industry may also continue to expand. Sources believe that as law enforcement agencies analyze seized equipment and communication records, it is not ruled out that more relevant company leaders will face charges in the future.
However, as of the time of the report, there is no public evidence to prove that all companies that provide ransomware negotiation services are connected to cybercriminal organizations, nor can it be concluded that all the businesses Dubrovsky is involved in involve illegal activities. The case is still in the investigation and judicial process stage, and the specific facts need to be further confirmed by subsequent court documents and information from law enforcement agencies.
This case also highlights the unique position of ransomware negotiation services. When a company encounters cyber blackmail, professional consultants may need to communicate directly with the attacker, verify the data held by the other party, determine whether the threat is credible, and assist the company in deciding whether to continue negotiations. The work itself is not necessarily illegal, but negotiators face strict compliance requirements as they come into contact with criminals, handle sensitive information and sometimes be involved in decisions involving large sums of money.
For companies that have been attacked, hiring professional consultants can help them handle the crisis in a more organized manner, but you still need to be cautious when choosing a service provider. Companies need to understand the consultant's actual responsibilities, how information is handled, communication arrangements with law enforcement, and whether there are potential conflicts of interest in the service. The legal line between professional advice and assistance in committing a crime is particularly important for negotiations involving criminal activity.
Looking at the broader cybersecurity situation, the ShinyHunters case shows that modern cybercrime is no longer limited to hackers exploiting vulnerabilities to invade systems. Around data theft and extortion activities, a complex ecosystem including account intrusion, data transactions, threat communication, fund processing and professional services may also form. For law enforcement to thoroughly investigate such groups, they need to track the attackers themselves and also analyze the network of peripheral relationships and services they may rely on.
Whether Dubrovsky’s arrest will further implicate the heads of other cybersecurity companies is still unclear. But as the FBI continues to investigate ShinyHunters' data theft and extortion activities against businesses and government agencies, the case may become an important point in U.S. law enforcement's examination of the relationship between the ransomware negotiation industry and cybercrime.
What can be confirmed so far is that the case has expanded from simply tracing members of the hacker organization to investigating a company co-founder who has a background in the cybersecurity industry and has been engaged in ransomware response business for a long time. Next, more documents released by the court, follow-up actions by law enforcement agencies, and legal responses from those involved will determine the specific direction of this case.
Comments