LIVE · cybersecurity feed
Live wire
ransomware

FBI Arrests Founder of Ransomware Negotiation Firm

Federal agents have arrested a Canadian cybersecurity professional in Pennsylvania, linking him to an ongoing investigation into the ShinyHunters hacking group. Edward Dubrovsky, co-founder of the Canadian firm CyberSteward, was taken into custody on October 8, facing charges of conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference…

ZeroDay News ·

Source: Krebs on Security

Federal agents have arrested a Canadian cybersecurity professional in Pennsylvania, linking him to an ongoing investigation into the ShinyHunters hacking group. Edward Dubrovsky, co-founder of the Canadian firm CyberSteward, was taken into custody on October 8, facing charges of conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference with commerce by threats.

Dubrovsky was reportedly attending the Cyber Risk Summit in Philadelphia, held from October 5 to 7, when the arrest occurred. His company, CyberSteward, specializes in ransomware negotiation and advisory services. Prior to co-founding CyberSteward, Dubrovsky was also a co-founder of another Canadian security company, Cypfer. His LinkedIn profile indicates his expertise in "strategy & compliant driven coercive (ransomware, extortion) advisory, negotiations and settlement services." He is also the author of "Cyber Extortion Strategic Response," a book detailing approaches to ransomware negotiations.

Court records initially listed Dubrovsky's last name as "Dobrovsky" but confirmed his identity and age as 54. While the initial arrest was in Pennsylvania, the case has since been moved to the Eastern District of Texas, which sources indicate is a central hub for the FBI's ShinyHunters investigation. Many documents related to the case remain sealed.

The ShinyHunters group is known for using phishing and stolen credentials to exfiltrate data from corporate accounts, particularly those at software-as-a-service companies. They then threaten to publish the stolen data unless a ransom is paid. The FBI estimates the group has extorted over $70 million from victims this year alone.

The arrest of Dubrovsky follows earlier developments in the ShinyHunters investigation. Last month, Dutch police arrested Pepijn van der Stap, a convicted cybercriminal, in connection with the group. Following Van der Stap's arrest, another ShinyHunters member, known as "Rey," reportedly took over the group and publicly taunted the FBI after the group stole data from the agency's online recruitment portal. This stolen data allegedly included details on agents' units, specializations, and medical and psychiatric records.

More recently, "Rey" was identified as Saif Al-din Khader, a teenager who has reportedly been detained and is cooperating with FBI investigators. Khader was allegedly apprehended while attempting to extort a navigation and digital aviation unit that had been divested by Boeing in late 2025.

The FBI has not issued an official comment on Dubrovsky's arrest or the ongoing investigation. Dubrovsky currently does not have legal representation listed in the available court records. Sources suggest that further charges against individuals at other companies specializing in ransomware negotiation may be forthcoming as the investigation progresses.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

saashigh

ASOS Breach Reveals the Risks in Customer-Facing SaaS

A recent security incident involving the British online fashion retailer ASOS has brought to light the inherent risks associated with customer-facing Software-as-a-Service (SaaS) platforms. The breach reportedly showcased how the compromise of a single user identity could serve as an initial access vector, subsequently allowing attackers to achieve broad penetration into a company's internal…

patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.

security

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have reported an active credential-theft campaign leveraging GitHub Actions workflows, which has led to the compromise of tens of thousands of repositories. The campaign reportedly exploited two high-profile open-source maintainer accounts to propagate a malicious workflow into over 340 repositories directly. One notable instance involved the account of Takashi Kitao,…