Security News

Ransomware Negotiator Arrested in US Extortion Case Linked to FBI Breach

CyberScoop · 10 Oct 2026
Key Takeaway Make sure security patches are applied promptly across your own systems and those run by suppliers and contractors, since a single missed update at a third party can expose your data.

Federal authorities arrested Edward Dubrovsky, 54, in Pennsylvania on Thursday, according to court records posted Friday. He is a former chief operating officer and founder of CYPFER, a firm that helps organisations negotiate with ransomware operators. He is charged with conspiring to threaten the confidentiality of information to extort money, and with conspiring to commit Hobbs Act extortion. Other details of the case remain sealed.

The FBI did not publicly announce the arrest, but the case appears to align with actions following the ShinyHunters attack on the FBI's IT systems, which exposed personal data about thousands of bureau employees. FBI Director Kash Patel said the bureau had arrested "another suspected co-conspirator" of the group without naming the suspect, and the New York Times reported a Canadian man was arrested in Pennsylvania in connection with the attack. Neither Dubrovsky nor CYPFER responded to requests for comment.

ShinyHunters has previously targeted cloud platforms, healthcare organisations, universities, retailers and technology companies. Its victims this year include Instructure, Salesforce, Snowflake and McKesson. FBI assistant director for cyber Brett Leatherman said a review found the FBI breach came through a third-party platform, where a contractor had not installed a security patch issued for the system. Reuters reported the contractor worked for Accenture.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from CyberScoop, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.