Cyber exec arrested in case allegedly tied to ShinyHunters hackers

FBI

Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI’s ongoing crackdown on the ShinyHunters hacking group.

Dubrovsky, 54, has had senior roles at cybersecurity firms that help data breach and ransomware victims negotiate extortion payments with cybercriminals.

Yesterday, FBI Director Kash Patel announced that agents had arrested “another suspected co-conspirator of the ShinyHunters group”.  The New York Times reported that the suspect was a Canadian citizen arrested in Pennsylvania and believed to be a primary co-conspirator in the recent ShinyHunters FBI Jobs hack.

Last night, both Politico and KrebsOnSecurity reported that Dubrovsky was arrested in Pennsylvania, where he was attending a cybersecurity conference.

Publicly available court records show that Dubrovsky appeared in the Eastern District of Pennsylvania after being taken into custody. A later court order says he was transferred to the Eastern District of Texas, where the charges were filed, with the order stating that he remains in custody.

While the complaint is currently under seal, the docket lists conspiracy and extortion-related charges.

“18:371 AND 1030(a)(7)(B) – CONSPIRACY TO THREATEN TO IMPAIR THE CONFIDENTIALITY OF INFORMATION WITH THE INTENT TO EXTORT MONEY; 18:1951(a) AND (b)(2) – INTERFERENCE WITH COMMERCE BY THREATS (HOBBS ACT EXTORTION AND CONSPIRACY TO COMMIT HOBBS ACT EXTORTION),” reads the case docket.

While the FBI has not publicly confirmed that Dubrovsky is the suspected ShinyHunters co-conspirator, KrebsOnSecurity reports that multiple sources linked Dubrovsky’s arrest to the ShinyHunters investigation.

Dubrovsky previously co-founded Canadian cybersecurity company CYPFER and has also been associated with CyberSteward, another firm specializing in ransomware negotiation and cyber-extortion response.

Politico reports that CyberSteward is a trade name used by CYPFER and that the firms help organizations negotiate and send extortion payments to cybercriminals.

Dubrovsky also recently published a book, “Cyber Extortion Strategic Response,” about handling cyber extortion.

According to KrebsOnSecurity, Dubrovsky had previously posted on LinkedIn that he planned to attend the NetDiligence Cyber Risk Summit in Pennsylvania with the CyberSteward team.

ShinyHunters is an extortion group known for stealing data from web applications and cloud-based SaaS platforms, then demanding ransom payments from victims or the stolen data would be published.

Over time, the ShinyHunters name has been used by numerous threat actors involved in data theft and extortion campaigns worldwide.

In addition to conducting its own breaches, the group has also operated as an extortion-as-a-service operation, helping other hackers extort organizations they had already compromised into paying ransom demands.

More recently, ShinyHunters has increasingly targeted cloud environments and enterprise SaaS platforms, often using stolen credentials, authentication tokens, phishing, and social engineering to gain access to corporate systems and steal data.

According to the FBI, ShinyHunters and associated actors have breached more than 140 organizations and collected more than $70 million in extortion payments over the past year.

The FBI has stepped up pressure on the group since the breach of its jobs portal, with multiple arrests and detentions linked to alleged ShinyHunters members in recent weeks.

Because the complaint against Dubrovsky remains sealed, it is still unclear what he is accused of doing or whether the case is connected to the FBI breach.

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat