Threats — Breaking News
FBI Arrests Canadian Cyber Executive Edward Dubrovsky in ShinyHunters Probe
Director Kash Patel announced the arrest of a suspected ShinyHunters co-conspirator on Oct. 9; sources identify the suspect as Edward Dubrovsky, co-founder of Canadian cybersecurity firm CYPFER. The FBI has not publicly confirmed the link.
Photo: ajay_suresh, CC BY 2.0, via Wikimedia Commons
FBI Director Kash Patel announced Friday that agents arrested “another suspected co-conspirator of the ShinyHunters group,” capping a month that has seen two arrests in the long-running investigation into one of the most prolific extortion operations of the past year.
The New York Times reported the suspect is a Canadian citizen arrested in Pennsylvania, believed to be a primary co-conspirator in the hack of the FBI’s own jobs portal. Politico and KrebsOnSecurity identified the suspect as Edward Dubrovsky, 54, arrested while attending the NetDiligence Cyber Risk Summit at the Loews Philadelphia Hotel, which ran Oct. 5–7 (BleepingComputer’s report).
A note on the name: the court docket reviewed by DataBreaches.Net spells the surname “Dobrovsky,” while Politico, KrebsOnSecurity, and the Times report “Dubrovsky.” HackedWire uses the press-reported spelling pending verification against the official docket, which lists the complaint under seal.
Court records show Dubrovsky appeared in the Eastern District of Pennsylvania and was transferred to the Eastern District of Texas. The complaint remains sealed. The docket lists conspiracy and extortion-related charges: “18:371 AND 1030(a)(7)(B) - CONSPIRACY TO THREATEN TO IMPAIR THE CONFIDENTIALITY OF INFORMATION WITH THE INTENT TO EXTORT MONEY; 18:1951(a) AND (b)(2) - INTERFERENCE WITH COMMERCE BY THREATS (HOBBS ACT EXTORTION AND CONSPIRACY TO COMMIT HOBBS ACT EXTORTION).”
Dubrovsky co-founded the Canadian cybersecurity company CYPFER and has been associated with CyberSteward, a firm specializing in ransomware negotiation and cyber-extortion response. He recently published the book Cyber Extortion Strategic Response.
Photo: Tim Evanson, CC BY-SA 2.0, via Wikimedia Commons
A second arrest, across the Atlantic
Separately, Dutch police confirmed the Sept. 15 arrest of a 24-year-old Amsterdam man as part of a ShinyHunters investigation, announcing it on Sept. 28. The police did not name him, but Brian Krebs and DataBreaches.Net identified the suspect as Pepijn van der Stap, known online as “Umbreon” — a name that echoes the oversized Umbreon Pokémon image SecurityWeek reports was embedded in the defacement of the FBI jobs portal.
Van der Stap was convicted in 2023 of data theft and extortion and sentenced to four years, with one suspended. At the time of his arrest he was employed as offensive security lead at Neo Security. ShinyHunters denied any connection to van der Stap when contacted by The Hacker News, and Dutch police said a separate murder-solicitation inquiry arising from his seized laptop is unrelated to the ShinyHunters case.
Scale of the operation
Per the FBI, ShinyHunters and associated actors have breached more than 140 organizations and collected more than $70 million in extortion payments over the past year. SecurityWeek reports the FBI jobs-portal hack — which occurred around Sept. 21 — likely used a modified exploit for CVE-2026-35273, the critical Oracle PeopleSoft flaw that ShinyHunters has been weaponizing since May (our reporting on the flaw).
What we know
- The FBI arrested a Canadian citizen in Pennsylvania on Oct. 8, announced by Director Patel on Oct. 9 as “another suspected co-conspirator of the ShinyHunters group.”
- Press outlets identify the suspect as Edward Dubrovsky, 54, co-founder of CYPFER and a cyber-extortion response specialist; the sealed-complaint docket lists conspiracy and Hobbs Act extortion charges.
- Dutch police arrested a 24-year-old Amsterdam man on Sept. 15 in a ShinyHunters investigation; sources name him as Pepijn van der Stap, aka “Umbreon.”
- The FBI says ShinyHunters and associates breached 140+ organizations and collected $70M+ in extortion over the past year.
What remains unknown
- The FBI has not publicly confirmed Dubrovsky is the ShinyHunters co-conspirator; the complaint is sealed and it is not established he was charged specifically over the FBI jobs hack.
- Van der Stap’s identity is source-reported, not named by Dutch police; ShinyHunters denies any connection to him.
- The docket’s spelling of the suspect’s surname (“Dobrovsky”) conflicts with press reporting (“Dubrovsky”) and is unverified against the official record.
- No DOJ press release had been published as of Oct. 10.
What you can do
For defenders, the through-line is the exploited attack surface: ShinyHunters has repeatedly chained a single unpatched flaw — CVE-2026-35273 in Oracle PeopleSoft — across victims. Organizations running PeopleSoft should apply Oracle’s June 10 Security Alert and treat the advisory’s mitigations as, in Oracle’s words, “a high-priority risk reduction measure.” See our companion report on the flaw and its WAF-bypass revival.
Corrections: No corrections have been published for this article.
Related coverage
About the author
Never miss a breach report
Get HackedWire’s verified incident coverage in your inbox. Subscribe to the newsletter →