# FBI Arrests Founder of Ransomware Negotiation Firm (Edward Dubrovsky, Cypfer/CyberSteward) on Cyber Extortion and Conspiracy Charges Amid ShinyHunters Crackdown

> The FBI arrested Edward Dubrovsky (also spelled Dobrovsky in court records), 54, co-founder of Canadian ransomware negotiation firm Cypfer and of CyberSteward, on October 8, 2026 in Pennsylvania, on charges of conspiracy to threaten to impair the confidentiality of information with intent to extort and interference with commerce by threats. Krebs on Security places the arrest alongside the ShinyHunters crackdown, in which the FBI says the group breached 140+ organizations and collected at least $70 million in extortion payments; the complaint is sealed and Dubrovsky's alleged conduct has not been publicly detailed.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3178
- **ID:** TL-2026-3178
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** MONITORING
- **Actor:** ShinyHunters
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On October 8, 2026 the FBI arrested Edward Dubrovsky (spelled Dobrovsky in some court records), 54, a Canadian national and co-founder of the ransomware negotiation firm Cypfer and of CyberSteward, in Pennsylvania. He was detained days after attending the Cyber Risk Summit (October 5-7, 2026, Loews Philadelphia Hotel), which he had announced on LinkedIn about a month earlier. He is held at a federal facility in Philadelphia, and the case was moved to the Eastern District of Texas on October 9. The charges cited are conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference with commerce by threats. The complaint remains sealed; the Krebs on Security report, which cites the New York Times, an FBI Director Kash Patel statement, CourtListener records and the Bureau of Prisons inmate locator, does not describe his alleged conduct. Dubrovsky is also the author of the book 'Cyber Extortion Strategic Response'.

Krebs on Security places the arrest in the context of the broader FBI campaign against ShinyHunters (also tracked as Scattered LAPSUS$ Hunters, SLH/SLSH). The FBI states that ShinyHunters and co-conspirators have breached more than 140 organizations since 2025 and collected at least $70 million in extortion payments in 2026. Reporting describes the group's tradecraft as phishing and stolen credentials against corporate SSO accounts, third-party vendors and cloud SaaS platforms (Salesforce and Snowflake are named), followed by data theft and extortion. The group claimed a breach of the FBI's online recruitment portal (2-3 TB, including personnel, medical and psychiatric records) and attributed it to an Oracle PeopleSoft zero-day; that claim is the group's own and is not independently confirmed here.

Related enforcement: Dutch police arrested a 24-year-old Amsterdam man, identified as Pepijn van der Stap, on September 15, 2026 as an alleged ShinyHunters leader, with pre-trial detention extended by at least 90 days. Saif Al-din Khader ('Rey', 'ReyXBF'), reported as an administrator of Scattered LAPSUS$ Hunters and a former Hellcat leak-site and BreachForums administrator, was detained in Jordan (reported September 29 / October 2026) and is reported to be cooperating. On September 29 the FBI (Cyber Division AD Brett Leatherman) publicly urged remaining ShinyHunters members to surrender.

Analytic caution: no public source establishes that Dubrovsky's charges arise from ShinyHunters activity or specifies his conduct. The article ties the stories together by context only. No CVEs, network IOCs or malware hashes are published. For defenders, the principal relevance is third-party/insider risk in ransomware negotiation and incident-response engagements, plus the active ShinyHunters SaaS/SSO extortion threat.

## MITRE ATT&CK

- T1566 Phishing
- T1199 Trusted Relationship
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1078.004 Valid Accounts: Cloud Accounts
- T1530 Data from Cloud Storage
- T1213 Data from Information Repositories
- T1657 Financial Theft

## Sources

- [FBI Arrests Founder of Ransomware Negotiation Firm](https://krebsonsecurity.com/2026/10/fbi-arrests-founder-of-ransomware-negotiation-firm/)
- [FBI tells ShinyHunters members to turn themselves in after recent arrest](https://www.bleepingcomputer.com/news/security/fbi-tells-shinyhunters-members-to-turn-themselves-in-after-recent-arrest/)
- [FBI warns ShinyHunters members to come forward after alleged leader's arrest](https://www.nextgov.com/cybersecurity/2026/09/fbi-warns-shinyhunters-members-come-forward-after-alleged-leaders-arrest/416302/)
- [ShinyHunters suspect Rey reportedly detained](https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html)
- [FBI says ShinyHunters leader arrested after 140 breaches and $70mn extortion](https://beinsure.com/news/fbi-says-shinyhunters-leader-arrested-after-140-breaches-and-70mn-extortion/)
- [ShinyHunters defiant after FBI calls on members to come forward](https://www.securityweek.com/shinyhunters-defiant-after-fbi-calls-on-members-to-come-forward/amp/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3178
