FBI arrests Cypfer co-founder Edward Dubrovsky, now related to CyberSteward, within the ShinyHunters investigation into the FBI jobs portal breach.
A co-founder of Canadian ransomware negotiation agency Cypfer has been recognized because the individual arrested in reference to the FBI’s ShinyHunters investigation, including an surprising flip to a case already involving suspected hackers, breached FBI techniques and worldwide arrests.
The New York Instances reported on October 9 that the FBI had arrested a suspect in Pennsylvania linked to the ShinyHunters investigation. Cybersecurity journalist Brian Krebs later recognized the suspect as Edward Dubrovsky, a Canadian cybersecurity govt and co-founder of Cypfer. Krebs reported that Dubrovsky is now related to one other Canadian safety agency, CyberSteward.
Dubrovsky is just not an unknown determine in cybersecurity. His skilled background is in ransomware negotiation and incident response, work usually related to serving to corporations reply to extortion assaults.
The arrest additionally comes days after a separate DOJ case towards MonsterCloud CEO Zohar Pinhasi, one other ransomware restoration determine accused of secretly paying attackers for decryption keys whereas charging victims larger restoration charges. The 2 instances are separate, however each put new scrutiny on corporations and people working round ransomware restoration and negotiation.
The FBI has not publicly launched Dubrovsky’s identify in a proper announcement reviewed by Hackread.com. The precise prices, if any, and his alleged position within the ShinyHunters investigation weren’t instantly clear on the time of writing.
Courtroom data reviewed by Hackread.com present the case was filed within the Jap District of Pennsylvania on October 8 and terminated there on October 9 after Dubrovsky was dedicated to the Jap District of Texas. A bail standing order says the federal government moved for detention, the movement was granted, and Dubrovsky was detained pending a detention listening to within the charging district.

New Arrest Follows Rey Detention
The reported arrest follows earlier protection of suspected ShinyHunters member Saif al-Din Khader, identified on-line as “Rey,” who was detained in Jordan on September 29. Reuters reported that Khader was cooperating with the FBI and different authorities as investigators labored to establish others linked to the group.
Hackread.com additionally reported that the FBI confirmed a number of arrests within the ShinyHunters investigation, however declined to establish all suspects or verify whether or not Khader was amongst them. On the time, the bureau stated it was working with worldwide companions and persevering with to pursue individuals concerned within the cyber incident.
The FBI’s investigation intensified after ShinyHunters claimed duty for compromising the FBI’s job software portal (apply.fbijobs.gov).
The group claimed it accessed delicate info belonging to present, former and potential FBI personnel, together with private and health-related knowledge. Days later, ShinyHunters advised Hackread.com that it’s going to not leak the stolen FBI knowledge and that the breach was a part of its advertising marketing campaign.
The FBI confirmed unauthorized exercise affecting the roles portal however has not publicly verified ShinyHunters’ full claims in regards to the stolen knowledge.
PeopleSoft Breach and Contractor Fallout
The FBI jobs portal incident has additionally led to fallout round third-party system administration. A missed safety patch reportedly left the bureau’s Oracle PeopleSoft jobs portal uncovered, main the FBI to take away a contractor from its task. Accenture was recognized as the corporate managing the platform.
ShinyHunters beforehand claimed it exploited a PeopleSoft vulnerability to achieve entry. Google’s Mandiant individually reported that the group had exploited CVE-2026-35273, a crucial flaw in Oracle PeopleSoft’s Setting Administration part, and used URL encoding to get round WAF guidelines blocking the susceptible endpoint.
The newly reported arrest provides one other piece to a fast-moving investigation, however a number of particulars stay unresolved. Authorities haven’t publicly defined how Dubrovsky is allegedly linked to the case, whether or not the arrest is straight associated to the FBIJobs.gov breach, or the way it suits with the reported detention of Rey and the sooner arrest of Pepijn van der Stap within the Netherlands, the FBI described as an alleged ShinyHunters chief.
For now, the confirmed image is that the FBI’s ShinyHunters investigation has moved from breach response into arrests, worldwide cooperation and questions on how a missed enterprise software program patch uncovered one of many bureau’s personal techniques.
ShinyHunters Knowledge Breach Obtain Infrastructure Nonetheless Intact and On-line
Regardless of the arrests and reported cooperation of suspected members, ShinyHunters’ stolen-data obtain infrastructure stays lively. The group’s darkish internet leak web site has moved out and in of availability in latest days, however its obtain system remains to be reachable, with a number of terabytes of stolen knowledge from main corporations nonetheless accessible.
The scenario leaves an open query for investigators and victims. If Rey was working or serving to handle the platform, the continued availability of the obtain infrastructure could recommend that different individuals nonetheless have entry, that elements of the system have been individually hosted, or that the backend was not instantly affected by the arrests. None of these prospects has been confirmed.








![11 social media tendencies each marketer ought to watch in 2026 [new data]](https://blog.aimactgrow.com/wp-content/uploads/2026/09/social20media20trends-1-120x86.png)

