Edward Dubrovsky, a 54-year-old Canadian cybersecurity executive, was taken into custody in Pennsylvania in connection with alleged extortion activity that multiple reports have tied to the FBI's widening crackdown on the ShinyHunters hacking group, according to Politico and KrebsOnSecurity.
FBI Director Kash Patel said a day earlier that agents had arrested another suspected co-conspirator of ShinyHunters. The New York Times identified the suspect as a Canadian citizen picked up in Pennsylvania and described him as a believed primary co-conspirator in the recent hack of the FBI Jobs portal. Dubrovsky was attending a cybersecurity conference in the state when he was arrested, the two outlets reported.
Court records that are publicly available show Dubrovsky appeared in the Eastern District of Pennsylvania after his arrest. A subsequent court order transferred him to the Eastern District of Texas, where the charges were filed, and stated that he remains in custody. The complaint itself is sealed, though the docket lists conspiracy and extortion-related counts.
The docket cites conspiracy to threaten to impair the confidentiality of information with intent to extort money, along with interference with commerce by threats, described as Hobbs Act extortion and conspiracy to commit Hobbs Act extortion. The FBI has not publicly confirmed that Dubrovsky is the suspected ShinyHunters co-conspirator, but KrebsOnSecurity reported that multiple sources connected his arrest to the ShinyHunters investigation. Because the complaint stays sealed, it remains unclear what he is accused of doing or whether the case relates to the FBI breach.
Dubrovsky co-founded the Canadian cybersecurity company CYPFER and has also been linked to CyberSteward, another firm focused on ransomware negotiation and cyber-extortion response. Politico reported that CyberSteward is a trade name used by CYPFER and that the firms assist organizations in negotiating and sending extortion payments to cybercriminals. Dubrovsky also recently published a book, Cyber Extortion Strategic Response, on handling cyber extortion. KrebsOnSecurity reported that he had posted on LinkedIn that he intended to attend the NetDiligence Cyber Risk Summit in Pennsylvania with the CyberSteward team.
ShinyHunters is an extortion group known for stealing data from web applications and cloud-based SaaS platforms and then demanding ransom payments or publishing the stolen data. The name has been used over time by numerous threat actors running data theft and extortion campaigns worldwide, and the group has also operated as an extortion-as-a-service operation that helps other hackers press organizations they had already compromised. More recently, it has increasingly targeted cloud environments and enterprise SaaS platforms, often using stolen credentials, authentication tokens, phishing and social engineering. According to the FBI, ShinyHunters and associated actors have breached more than 140 organizations and collected more than $70 million in extortion payments over the past year.
The FBI has increased pressure on the group since the breach of its jobs portal, with multiple arrests and detentions linked to alleged ShinyHunters members in recent weeks.
More cybersecurity news from TechManNews.





