The FBI has arrested a former Cypfer managing director on sealed cyber extortion charges, and sources link the case to its ShinyHunters investigation. Nothing has been proven, but UK organisations that would bring in a ransom negotiator after a breach should be asking how they vet that third party.
What happened
FBI agents arrested Edward Dubrovsky, a 54-year-old Canadian cyber security executive, in Pennsylvania on Thursday 8 October 2026. He was in the state for the Cyber Risk Summit, which ran at the Loews Philadelphia Hotel from 5 to 7 October. The New York Times first reported the detention of an unnamed Canadian; KrebsOnSecurity then identified him, and BleepingComputer and Hackread followed with court record details.
The docket is listed under the spelling “Dobrovsky”. It shows two charges: “conspiracy to threaten to impair the confidentiality of information” with intent to extort, and Hobbs Act “interference with commerce by threats”. The complaint itself is sealed. The case opened in Pennsylvania, but on 9 October it moved to the Texas federal court district that sources describe as the hub of the FBI’s ShinyHunters inquiry. A bail order shows prosecutors asked for him to be detained and the court agreed, pending a detention hearing in Texas.
The ShinyHunters link comes from reporting and has not been officially confirmed. FBI Director Kash Patel posted on X that agents had arrested “another suspected co-conspirator of the ShinyHunters group”, but he did not name anyone. The FBI declined to comment to Krebs. With the complaint under seal, nobody outside the case knows what Mr Dubrovsky is alleged to have done, or whether it relates to the breach of the FBI’s jobs portal. He is presumed innocent, and he had not commented publicly at the time of writing.
Who he is matters to the story. His LinkedIn profile described him as an “ex-founder” of Cypfer, a Canadian firm that negotiates with extortion groups on behalf of victims. Cypfer was the biggest sponsor of the Philadelphia summit. A Cypfer spokesperson has since said he was never a founder. According to the company, he was a managing director and resigned in November 2025. He has more recently been associated with CyberSteward, another Canadian advisory firm.
The detail
ShinyHunters is a data-theft and extortion crew rather than a classic ransomware operation. It usually gets into corporate software-as-a-service accounts with phishing or stolen credentials. It then copies out the data and threatens to publish it unless the victim pays. By the FBI’s count, the group and its associates have breached more than 140 organisations in the last twelve months, extracting upwards of $70 million from victims. The bureau became a victim itself when the group got into its Oracle PeopleSoft recruitment portal. Mandiant has separately reported the group exploiting CVE-2026-35273, a critical PeopleSoft flaw.
This is the latest in a run of arrests. Dutch police detained Pepijn van der Stap, whom the FBI describes as an alleged leader of the group. Reuters reported that a teenager known as “Rey”, identified as Saif al-Din Khader, was detained in Jordan on 29 September and is cooperating with investigators. According to Krebs, the FBI has been examining devices seized in the Dutch arrest, and charges against people at other ransom negotiation firms may follow. That second claim rests on unnamed sources and should be treated as unconfirmed.
The arrest also follows a separate US case charging the head of ransomware recovery firm MonsterCloud, covered previously on this site. The two cases are not connected.

Why it matters for UK organisations
Data-theft extortion of this kind is a familiar threat to British businesses, and UK victims commonly hire specialist negotiators. Usually that happens through a cyber insurance panel or an incident response retainer arranged in a hurry. The negotiator often ends up with privileged information: how much cover the victim has, its board’s appetite to pay, what data was taken and how the investigation is going. If any intermediary in that position were working against the victim, the damage would be serious. These allegations are untested, but they make that risk concrete.
There is a regulatory dimension as well. Under UK GDPR, a personal data breach must be reported to the ICO within 72 hours where it poses a risk to individuals. The decisions taken during an extortion response, including whether to engage the attacker at all, need to be defensible afterwards. Boards that hand those decisions entirely to an outside party without oversight are taking a governance risk, whoever that party is.
Sanctions are a further concern. Paying a group, or anyone acting for it, that turns out to be sanctioned can create legal exposure, and the victim depends on its advisers to check this properly. If the ShinyHunters link is substantiated, insurers and their panel firms in the UK market will face hard questions about how they vet and supervise negotiators.
Expert view
I want to be careful here, because a sealed complaint tells us very little. Arrests are not convictions. Still, I think the security industry has been slow to accept that the people standing between a victim and a criminal group are themselves a target, and potentially a weak link.
In my experience of incident response, negotiation is the least scrutinised part of the whole process. Forensic firms get audited and tested. Legal counsel is regulated. The negotiator, often chosen by the insurer and introduced at two in the morning, may never have been through the client’s own supplier checks.
Talking to an attacker can have real value. It buys time and lets you test the attacker’s claims. None of that requires handing over your negotiating position without checks. The answer is to treat a negotiator like any other high-risk supplier, not to avoid them altogether.
What to do now
- Review your incident response retainers and insurance panel now. Find out which negotiation firm would actually be appointed, who the individuals are, and whether you are allowed to veto the choice.
- Put negotiation under legal privilege and board control. Make sure outside counsel instructs the negotiator. Require written authority for every offer, and keep full transcripts of all contact with the attacker.
- Limit what you share. The negotiator needs to know some things, but your insurance limits and internal deliberations do not have to leave the war room.
- Build sanctions checks into your playbook. Before any payment is considered, record who carried out the checks and what evidence they relied on.
- Close the routes in that groups like ShinyHunters use. Enforce phishing-resistant multi-factor authentication on SaaS platforms, keep tight control of administrator accounts, and patch internet-facing business applications quickly. These map directly to the Cyber Essentials controls for user access control, secure configuration and security update management.
Bottom line
An executive from the ransom negotiation world is in custody on sealed extortion conspiracy charges. Sources link the case to ShinyHunters, but the FBI has not confirmed this, and nothing has been tested in court. Whatever the outcome, UK organisations should treat the people who negotiate on their behalf as a high-risk supplier, with proper vetting, oversight and records, rather than accepting whoever turns up when the crisis hits.