FBI Arrests Cypfer Co-Founder Edward Dubrovsky Over Extortion
- Federal Bureau of Investigation agents arrested Edward Dubrovsky, the co-founder of Canadian cybersecurity firm Cypfer, in Pennsylvania on October 8 in connection with an ongoing extortion investigation involving...
- The New York Times reported that the Federal Bureau of Investigation arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters, though the report did not name...
- Online records show the Cyber Risk Summit took place at the Loews Philadelphia Hotel between October 5 and October 7.
Federal Bureau of Investigation agents arrested Edward Dubrovsky, the co-founder of Canadian cybersecurity firm Cypfer, in Pennsylvania on October 8 in connection with an ongoing extortion investigation involving the ShinyHunters hacking group, multiple sources tell KrebsOnSecurity.
Pennsylvania Arrest Connects Cyber Firm Co-Founder to Data Theft
The New York Times reported that the Federal Bureau of Investigation arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters, though the report did not name the suspect. Federal court records confirm that Edward Dubrovsky was taken into custody on October 8 on cyber extortion and conspiracy charges. An inmate locator on the U.S. Bureau of Prisons website lists the 54-year-old at a federal facility in Philadelphia. Sources close to the investigation told KrebsOnSecurity that the suspect was visiting Pennsylvania to attend a cyber insurance conference when authorities made the arrest.
Conference Sponsoring Leads to Federal Court Filings
Online records show the Cyber Risk Summit took place at the Loews Philadelphia Hotel between October 5 and October 7. The conference website lists Canadian security firm Cypfer as its biggest sponsor. LinkedIn profiles indicate Dubrovsky co-founded Cypfer before later associating with another sponsoring firm, CyberSteward. Court documents indexed on Courtlistener.com charge the defendant with conspiracy to threaten to impair the confidentiality of information with the intent to extort money, alongside interference with commerce by threats. A notice filed on October 9 moved the case files to the Eastern District of Texas, which sources identify as the epicenter of the federal investigation.
Ransomware Extortion Tactics Drive Federal Probe
ShinyHunters typically uses phishing and stolen credentials to siphon data from corporate software-as-a-service accounts before demanding ransom payments to prevent publication of the files. The Federal Bureau of Investigation states that the group has extorted more than $70 million from victims this year. Following the Dutch police arrest of convicted cybercriminal Pepijn van der Stap last month in connection with the same inquiry, investigators seized digital devices that sources say are currently undergoing forensic review. Additional charges against principals at other ransomware negotiation firms may be forthcoming, according to sources speaking to KrebsOnSecurity.
At the heart of the book is a critical distinction: communicating with a criminal is not the same as negotiating a payment, and negotiating is not a commitment to pay.
Amazon listing excerpt for Cyber Extortion Strategic Response by Edward Dubrovsky
