Federal agents arrested a Canadian cybersecurity executive in Pennsylvania on Thursday in connection with the investigation into the ShinyHunters hacking group, according to the FBI and multiple sources close to the case. The New York Times first reported the arrest of a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters. Neither the Times nor a statement from FBI Director Kash Patel identified the man, and the FBI declined to comment on the matter.
One source told KrebsOnSecurity the man was in Pennsylvania to attend a cyber insurance conference, and that his company handled ransomware negotiations with cybercrime groups. Court records show that on October 8 an Edward Dobrovsky, with a slight misspelling of the last name, was arrested in Pennsylvania on cyber extortion and conspiracy charges. A summary of the complaint charges the defendant with conspiracy to threaten to impair the confidentiality of information with intent to extort money, and with interference with commerce by threats. Several documents, including the core complaint, are sealed, though a notice filed on October 9 moved the case to the Eastern District of Texas, which sources say is now the center of the FBI's ShinyHunters investigation.
The Bureau of Prisons inmate locator lists a 54-year-old Edward Dubrovsky as being held at a federal facility in Philadelphia. A LinkedIn profile for Edward Dubrovsky identifies him as an ex-founder of Cypfer, a Canadian security company that was the largest sponsor of the Cyber Risk Summit held at the Loews Philadelphia Hotel from October 5 to October 7. Dubrovsky is now associated with another Canadian firm and conference sponsor, CyberSteward, and wrote in a LinkedIn post roughly a month ago that he planned to attend the summit with his CyberSteward colleagues.
A Cypfer spokesperson said Dubrovsky was not a founder or co-founder as his LinkedIn profile claims, but served as a managing director before resigning in November 2025. Dubrovsky's profile states he wrote Cyber Extortion Strategic Response, a 252-page book on ransomware negotiations. In an excerpt from the Amazon listing, the book draws a distinction between communicating with a criminal and negotiating a payment, noting that negotiating is not a commitment to pay and that engagement can serve objectives such as testing claims, gathering information, creating time and preserving options.
Dubrovsky could not be reached for comment, and court records show he does not currently have an attorney or a public defender. ShinyHunters typically uses phishing and stolen credentials to take data from corporate accounts at software-as-a-service companies, then threatens to publish it unless a ransom is paid; the FBI says the group has extorted more than $70 million from victims this year. Sources say the FBI is examining devices seized last month when Dutch police arrested convicted cybercriminal Pepijn van der Stap, and that charges against principals at other ransomware negotiation firms may follow. After Van der Stap's arrest, a ShinyHunters member named Rey took control of the group and taunted the FBI over data stolen from its online recruitment portal, including unit and specialization details and medical and psychiatric records. Reuters reported last week that Rey, identified as a teenager named Saif Al-din Khader, had been detained and was cooperating with investigators.
More cybersecurity news from TechManNews.







