FBI Arrests Canadian Cybersecurity Expert Over Major Data Breach

Canadian cybersecurity executive and ransomware expert Edward Dubrovsky was arrested in the Philadelphia area as part of an ongoing federal investigation into a hack that exposed the sensitive personal data of current and former bureau employees.

The Federal Court Appearance and Transfer

Edward Dubrovsky, a Canadian cybersecurity executive and author of a book on handling ransomware negotiations, was taken into custody in the Philadelphia region. Following an initial court appearance where a magistrate judge appointed a federal public defender, court records and law enforcement officials confirm he has been transferred to Texas’s Eastern District for a scheduled detention hearing. Dubrovsky is facing charges related to extortion and making threats. CNN confirmed the defendant is believed to be tied to the FBI hack, building on initial reporting from independent journalist Brian Krebs. A LinkedIn profile under Dubrovsky’s name lists years of experience in the Canadian cybersecurity industry.

The ShinyHunters Intrusion of the FBI Jobs Portal

The federal investigation stems from a breach last month by the prolific cybercriminal group ShinyHunters. The actors breached an FBI jobs portal, harvesting the personal data of thousands of current and former personnel. Sources familiar with the data confirmed that the leak exposed identities of individuals working inside sensitive units focused on China and Russia. Last week, the FBI announced that Dutch authorities apprehended “one of the alleged leaders” of ShinyHunters, prompting senior bureau officials to ramp up public warnings.

Oracle Software Flaws and Contractor Failure

An internal FBI inquest traced the root cause of the security failure to a contractor managing the jobs portal. According to senior FBI cyber official Brett Leatherman, the contractor failed to apply a software update “explicitly issued to secure the platform.” The software in question is a human-resources platform made by Oracle. Security researchers from Google’s Threat Intelligence Group noted that the exact same vulnerability had previously been exploited to target the education sector in May and June, months before the FBI portal compromise occurred.

Leadership Video Updates and Extortion Demands

In the wake of internal employee criticism regarding inadequate support resources, FBI Director Kash Patel and Brett Leatherman issued direct video updates. Prior to the arrests, ShinyHunters utilized a dark-web site to demand that the bureau amend a previous threat advisory, expressing offense at how the agency characterized their extortion tactics. While many industry observers interpreted the demand as a tacit threat that ShinyHunters would leak the stolen data, the group later claimed that was never their intention. Responding to the mounting pressure and subsequent international arrests, Leatherman issued a direct warning to remaining cybercriminal elements.

Arrests have a way of changing who is willing to talk and seized infrastructure has a way of showing us who is left. The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.

FBI arrests cybersecurity firm co-founder linked to ShinyHunters data theft
Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

How to Pay for Unexpected Veterinary Bills and Pet Emergencies