FBI Arrests Ransomware Negotiation Firm Co-Founder in ShinyHunters Cybercrime Probe

www.news4hackers.com-fbi-arrests-ransomware-negotiation-firm-co-founder-in-shinyhunters-cybercrime-probe-fbi-arrests-ransomware-negotiation-firm-co-founder-in-shinyhunters-cybercrime-probe

A co-founder of a Canadian ransomware negotiation firm has been detained in connection with the FBI’s ongoing investigation into the ShinyHunters cybercriminal group.

Introduction

The arrest marks a significant development in the case, which involves a breach of the FBI’s job application portal and international law enforcement collaboration. The individual, Edward Dubrovsky, is linked to Cypfer, a company specializing in ransomware incident response and negotiation. Dubrovsky is now affiliated with CyberSteward, another Canadian cybersecurity firm. His arrest in Pennsylvania was confirmed by cybersecurity journalist Brian Krebs, who noted the connection to the ShinyHunters probe.

The Arrest

Edward Dubrovsky’s Role

The FBI has not publicly disclosed Dubrovsky’s name or specific charges, but court records indicate he was transferred to the Eastern District of Texas following pretrial detention. Dubrovsky’s alleged role in the case remains unclear. Authorities have not specified whether his arrest is directly tied to the FBI portal breach or how it relates to the detention of Pepijn van der Stap, a Dutch national linked to ShinyHunters.

The ShinyHunters Investigation

Breach of FBI’s Job Portal

The ShinyHunters investigation gained momentum after the group claimed responsibility for compromising the FBI’s job portal, apply.fbijobs.gov. The breach allegedly exposed sensitive data, including personal and health-related information of current, former, and prospective FBI employees. ShinyHunters stated it would not leak the stolen data, framing the incident as a marketing tactic. The FBI confirmed unauthorized activity but has not verified all claims about the extent of the breach.

Technical Details

Technical analysis by Mandiant revealed that ShinyHunters exploited a critical vulnerability in Oracle PeopleSoft, specifically CVE-2026-35273, to gain access. The group used URL encoding to bypass web application firewall (WAF) protections. The breach also highlighted issues with third-party system management, as the FBI removed a contractor, Accenture, from its assignment after a missed security patch exposed the platform.

International Collaboration

The arrest follows the detention of Saif al-Din Khader, a suspected ShinyHunters member known as “Rey,” in Jordan. Khader reportedly cooperated with authorities, aiding efforts to identify other group members. Additionally, the FBI confirmed multiple arrests in the investigation but did not disclose details about all suspects.

Implications

Dubrovsky’s background in negotiation and incident response contrasts with his alleged ties to the ShinyHunters group, raising questions about potential conflicts of interest. Meanwhile, the FBI’s handling of the breach has drawn scrutiny over third-party vendor security practices and the risks of unpatched software. As the investigation progresses, law enforcement agencies are working with international partners to track down additional suspects.

Conclusion

The ShinyHunters case highlights the evolving tactics of cybercriminal groups and the challenges of securing critical infrastructure. The outcome of Dubrovsky’s legal proceedings may provide further clarity on the scope of the breach and the involvement of individuals in the ransomware ecosystem.



About Author

en_USEnglish