Threat reportThreat IntelligenceTL-2026-3178

FBI Arrests Founder of Ransomware Negotiation Firm (Edward Dubrovsky, Cypfer/CyberSteward) on Cyber Extortion and Conspiracy Charges Amid ShinyHunters Crackdown

mediumMONITORING

FBI Arrests Founder of Ransomware Negotiation Firm (Edward (TL-2026-3178), also tracked as Dubrovsky arrest, is a medium-severity tracked intrusion set, first published 2026-10-10. It is attributed to ShinyHunters with low confidence, affects Cypfer / CyberSteward Ransomware negotiation and incident-response, maps to 8 MITRE ATT&CK techniques (T1078, T1078.004, T1190), and is covered by 9 detection rules and 12 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
8MITRE ATT&CK
Actors
1ShinyHunters
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-3178

Threat ID
TL-2026-3178
Also known as
Dubrovsky arrest, Cypfer founder arrest
Severity
MEDIUM
Status
MONITORING
Category
THREAT_INTEL
First published
Last reviewed
Attribution
ShinyHunters
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, cloud-saas, government administration, telecoms, professional-services
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
12

Malware and tooling in FBI Arrests Founder of Ransomware Negotiation Firm (Edward

Malware and tooling: Morpheus, scattered lapsus$ hunters

How FBI Arrests Founder of Ransomware Negotiation Firm (Edward works

The FBI arrested Edward Dubrovsky (also spelled Dobrovsky in court records), 54, co-founder of Canadian ransomware negotiation firm Cypfer and of CyberSteward, on October 8, 2026 in Pennsylvania, on charges of conspiracy to threaten to impair the confidentiality of information with intent to extort and interference with commerce by threats. Krebs on Security places the arrest alongside the ShinyHunters crackdown, in which the FBI says the group breached 140+ organizations and collected at least $70 million in extortion payments; the complaint is sealed and Dubrovsky's alleged conduct has not been publicly detailed.

On October 8, 2026 the FBI arrested Edward Dubrovsky (spelled Dobrovsky in some court records), 54, a Canadian national and co-founder of the ransomware negotiation firm Cypfer and of CyberSteward, in Pennsylvania. He was detained days after attending the Cyber Risk Summit (October 5-7, 2026, Loews Philadelphia Hotel), which he had announced on LinkedIn about a month earlier. He is held at a federal facility in Philadelphia, and the case was moved to the Eastern District of Texas on October 9. The charges cited are conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference with commerce by threats. The complaint remains sealed; the Krebs on Security report, which cites the New York Times, an FBI Director Kash Patel statement, CourtListener records and the Bureau of Prisons inmate locator, does not describe his alleged conduct. Dubrovsky is also the author of the book 'Cyber Extortion Strategic Response'.

Krebs on Security places the arrest in the context of the broader FBI campaign against ShinyHunters (also tracked as Scattered LAPSUS$ Hunters, SLH/SLSH). The FBI states that ShinyHunters and co-conspirators have breached more than 140 organizations since 2025 and collected at least $70 million in extortion payments in 2026. Reporting describes the group's tradecraft as phishing and stolen credentials against corporate SSO accounts, third-party vendors and cloud SaaS platforms (Salesforce and Snowflake are named), followed by data theft and extortion. The group claimed a breach of the FBI's online recruitment portal (2-3 TB, including personnel, medical and psychiatric records) and attributed it to an Oracle PeopleSoft zero-day; that claim is the group's own and is not independently confirmed here.

Related enforcement: Dutch police arrested a 24-year-old Amsterdam man, identified as Pepijn van der Stap, on September 15, 2026 as an alleged ShinyHunters leader, with pre-trial detention extended by at least 90 days. Saif Al-din Khader ('Rey', 'ReyXBF'), reported as an administrator of Scattered LAPSUS$ Hunters and a former Hellcat leak-site and BreachForums administrator, was detained in Jordan (reported September 29 / October 2026) and is reported to be cooperating. On September 29 the FBI (Cyber Division AD Brett Leatherman) publicly urged remaining ShinyHunters members to surrender.

Analytic caution: no public source establishes that Dubrovsky's charges arise from ShinyHunters activity or specifies his conduct. The article ties the stories together by context only. No CVEs, network IOCs or malware hashes are published. For defenders, the principal relevance is third-party/insider risk in ransomware negotiation and incident-response engagements, plus the active ShinyHunters SaaS/SSO extortion threat.

MITRE ATT&CK techniques used in TL-2026-3178

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing

Defense Evasion

T1078 Valid Accounts

Persistence

T1078.004 Valid Accounts: Cloud Accounts

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Impact

T1657 Financial Theft

Affected products and versions in FBI Arrests Founder of Ransomware Negotiation Firm (Edward

  • Cypfer / CyberSteward — Ransomware negotiation and incident-response services
  • Salesforce / Snowflake — Cloud SaaS platforms targeted by ShinyHunters (per reporting)

Remediation for FBI Arrests Founder of Ransomware Negotiation Firm (Edward

Immediate actions

  • Review any engagements with ransomware negotiation or extortion-response vendors for conflicts of interest and confirm what victim data they hold
  • Enforce phishing-resistant MFA and review SSO and SaaS (Salesforce, Snowflake) session and token activity for anomalous access
  • Audit third-party vendor access to cloud SaaS tenants and revoke unused integrations

Workarounds

  • Treat unsolicited helpdesk or SSO credential requests as suspected phishing and verify out of band

Longer-term hardening

  • Vet third-party negotiators and IR providers, with contractual confidentiality, data-handling and background-check requirements
  • Segregate negotiation communications and victim data from vendor-controlled systems where possible
  • Monitor for bulk data export and unusual API use in SaaS platforms

Timeline of FBI Arrests Founder of Ransomware Negotiation Firm (Edward

  • Saif Al-din Khader ('Rey') reported as having cooperated with law enforcement since at least June 2025 (The Hacker News reporting; exact day not given, date approximate)
  • Dutch police arrest a 24-year-old Amsterdam man (Pepijn van der Stap) identified as an alleged ShinyHunters leader; pre-trial detention later extended by at least 90 days
  • Saif Al-din Khader ('Rey'/'ReyXBF'), reported Scattered LAPSUS$ Hunters administrator, detained by Jordanian authorities and reported to be cooperating
  • FBI Cyber Division AD Brett Leatherman publicly urges remaining ShinyHunters members to surrender; FBI states 140+ organizations breached and at least $70 million in extortion collected
  • Cyber Risk Summit begins at the Loews Philadelphia Hotel (October 5-7); Dubrovsky had announced attendance on LinkedIn
  • FBI arrests Edward Dubrovsky (Dobrovsky), 54, co-founder of Cypfer and CyberSteward, in Pennsylvania on extortion conspiracy and interference-with-commerce charges
  • Case moves to the Eastern District of Texas; Dubrovsky held in a federal facility in Philadelphia; complaint remains sealed; Krebs on Security publishes report

Sources cited for FBI Arrests Founder of Ransomware Negotiation Firm (Edward

Detection coverage for TL-2026-3178

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3178 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats