Canadian Cybersecurity Executive Edward Dubrovsky Arrested in Extortion Case Linked to ShinyHunters Investigation
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania on suspicion of extortion. Multiple reports have linked the case to the FBI’s ongoing investigation into the ShinyHunters cybercrime group.
Dubrovsky, 54, has held senior positions at cybersecurity companies that help victims of data breaches and ransomware negotiate extortion payments with cybercriminals.
FBI arrests suspected ShinyHunters co-conspirator
FBI Director Kash Patel announced that agents had arrested “another suspected co-conspirator in the Shiny Hunters group.” The New York Times reported that the suspect was a Canadian national arrested in Pennsylvania and believed to be a key co-conspirator in the recent ShinyHunters FBI job portal hack.
Politico and KrebsOnSecurity reported that Dubrovsky was arrested while attending a cybersecurity conference in Pennsylvania.
A publicly available court record shows that Dubrovsky turned himself in to the Eastern District of Pennsylvania after being taken into custody. A later court order states that he was transferred to the Eastern District of Texas, where the charges were filed, and ordered to remain in custody.
The indictment remains sealed, but the docket lists conspiracy and extortion-related charges.
The case file cites the following statutes and allegations:
18 U.S.C. § 371 and § 1030(a)(7)(B): conspiracy to threaten to compromise the confidentiality of information for the purpose of extorting money; and 18 U.S.C. § 1951(a) and (b)(2): interfering with commerce by intimidation, including conspiracy to commit trade extortion and Hobbs Act extortion.
Although the FBI has not officially confirmed that Dubrovsky is a suspected ShinyHunters co-conspirator, KrebsOnSecurity reports that multiple sources have linked his arrest to the ShinyHunters investigation.
Dubrovsky’s cybersecurity industry background
Dubrovsky previously co-founded the Canadian cybersecurity firm CYPFER and was also affiliated with CyberSteward, a company specializing in ransomware negotiation and cyber-extortion response.
Politico reported that CyberSteward is a business name used by CYPFER. The companies help organizations negotiate and transfer extortion payments to cybercriminals.
Dubrovsky also recently published a book about responding to cyber extortion, titled Strategic Responses to Cyber Extortion.
According to KrebsOnSecurity, Dubrovsky previously said on LinkedIn that he planned to attend the NetDiligence Cyber Risk Summit in Pennsylvania with the CyberSteward team.
What is ShinyHunters?
ShinyHunters is an extortion group that steals data from web applications and cloud-based software-as-a-service platforms. The group then demands that victims pay a ransom or risk having the stolen information published.
Over time, the ShinyHunters name has been used by numerous threat actors involved in data theft and extortion campaigns around the world.
In addition to conducting its own breaches, the group has operated as an extortion-as-a-service operation, helping other hackers pursue ransom payments from organizations they had already compromised.
ShinyHunters has increasingly targeted cloud environments and enterprise SaaS platforms. Its tactics have included the use of stolen credentials, authentication tokens, phishing and social engineering to access corporate systems and steal data.
FBI investigation into ShinyHunters continues
According to the FBI, ShinyHunters and its associates infiltrated more than 140 organizations over the past year and collected more than $70 million in extortion proceeds.
The FBI has increased pressure on the group following multiple arrests and detentions in recent weeks involving alleged ShinyHunters members, as well as a breach of the group’s job portal.
The charges against Dubrovsky remain sealed. It is therefore unclear what specific conduct he is accused of or whether the case is directly related to the FBI’s ShinyHunters investigation.
Join Mikko Hypponen and security leaders from the NFL, Chanel and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix and revalidate at machine speed.
Source: www.bleepingcomputer.com



