FBI arrests ransomware negotiation firm co-founder in ShinyHunters probe
According to Krebs on Security (original report), FBI agents arrested the co-founder of a Canadian cybersecurity firm on Thursday in connection with the investigation into the ShinyHunters hacking group. The FBI has not commented, and several details come from anonymous sources and sealed or partly sealed court records, so they are not yet confirmed.
What we know about the ransomware negotiator arrest
- Krebs reports, citing multiple sources, that the arrest relates to the ShinyHunters investigation. Krebs describes the group as having recently taken sensitive data on thousands of FBI agents.
- The New York Times reported that the FBI arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters. The Times did not name him, and a statement from FBI Director Kash Patel on X did not either.
- One source told Krebs the person was visiting Pennsylvania for a cyber insurance conference and that his company handled ransomware negotiations with cybercrime groups.
- The Cyber Risk Summit ran at the Loews Philadelphia Hotel from Oct. 5 to Oct. 7. Krebs says its biggest sponsor was the Canadian firm Cypfer.
- Krebs links the arrest to Edward Dubrovsky, a Cypfer co-founder now associated with the firm CyberSteward. Federal court records show that on October 8 an “Edward Dobrovsky” (a slightly different spelling) was arrested in Pennsylvania.
- The complaint reportedly charges conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference with commerce by threats. A Bureau of Prisons locator lists a 54-year-old Edward Dubrovsky held in Philadelphia.
- A notice filed October 9 moved the case to the Eastern District of Texas. Sources told Krebs that field office is now the centre of the ShinyHunters investigation.
Who is affected
Directly, the people named in the reporting: the arrested man, who is charged by complaint and has not been convicted, and the FBI personnel whose data ShinyHunters is reported to have taken. The scope of that data, how it was obtained and what it contains are not disclosed in the source material.
Indirectly, any organisation that has used a ransomware negotiation or extortion advisory firm. Victims, insurers and negotiators handle sensitive information, so this case puts that supply chain in the spotlight.
What has not been confirmed
- The FBI has not publicly identified the arrested man, and the Times story did not name him.
- The charges are allegations in a complaint. Several court documents, including the core complaint, are sealed.
- What role the man is alleged to have played in ShinyHunters activity is not disclosed.
- Whether the name spelling in the court record matches the person Krebs names is not stated beyond Krebs noting the difference.
- Whether the arrested man’s company or its clients are implicated has not been reported.
Why this matters
Analysis, not reported fact. Negotiators sit between victims and criminals and often see ransom notes, stolen-data samples and payment details. If the allegations are borne out, that position of trust is a risk worth reviewing, though nothing reported so far suggests any client data was misused.
What to do
- If you use an external negotiation or incident response firm, confirm what contractual confidentiality, data handling and access limits apply to your case files.
- Review what data you have shared with third-party advisers and insurers during any past incident, and make sure it can be revoked or deleted.
- Treat reports linking the arrest to ShinyHunters as unconfirmed until the court or the Justice Department publishes charging documents.
- Keep monitoring for extortion contact or leak-site mentions of your organisation, and brief leadership using confirmed facts only.
- Do not draw conclusions about any firm or person beyond what the court record shows. Charges are not proof of guilt.
