One of the most significant cyberattacks against a federal law enforcement agency in recent memory is now producing arrests — and the suspect at the center of the latest development is not a shadowy, anonymous hacker, but a named cybersecurity professional from Canada. The case raises serious questions about insider knowledge, digital vulnerabilities, and the security of sensitive government data.
Federal authorities have arrested Edward Dubrovsky, a Canadian cybersecurity executive with a public profile as a ransomware expert, in connection with a damaging breach that exposed the personal data of thousands of current and former FBI employees. Dubrovsky was taken into custody in the Philadelphia area and appeared in federal court, where a magistrate judge appointed a public defender to represent him. He now faces charges related to extortion and making threats, and has been transferred to the Eastern District of Texas for a detention hearing, according to court records and a law enforcement official.
FBI Director Kash Patel confirmed the arrest on Friday, though he did not name Dubrovsky or specify where the arrest took place. CNN confirmed through multiple sources familiar with the investigation that the defendant is believed to be connected to the FBI hack. Investigative journalist Brian Krebs first reported Dubrovsky’s alleged involvement.
“Earlier this week, our agents in the field arrested another suspected co-conspirator”
of the cybercriminal group believed to be responsible for the hack, Patel said on Friday.
A LinkedIn profile linked to Dubrovsky describes him as a
“globally recognized cybersecurity expert”
with years of experience in Canada’s cybersecurity industry. He is also the author of a book on managing ransomware negotiations with cybercriminals — making his alleged involvement in such an attack particularly notable.
What Happened in the Breach
The hack was carried out by a group called ShinyHunters, a prolific cybercriminal organization that last month claimed responsibility for breaking into an FBI jobs portal and stealing personal data on thousands of current and former bureau employees. Among the exposed information were the identities of FBI personnel working in sensitive units focused on China and Russia, according to people who reviewed the data.
The vulnerability exploited by the hackers traces back to an unpatched flaw in a human resources software platform made by Oracle. According to Google’s Threat Intelligence Group, ShinyHunters had previously used that same flaw to attack educational institutions in May and June — months before the FBI breach. Despite a security patch being available, the FBI’s contractor managing the jobs portal had not applied it.
Brett Leatherman, a senior FBI cyber official, confirmed last week that the FBI
“removed the contractor”
after determining it had failed to update software
“explicitly issued to secure the platform.”
The Investigation and What Comes Next
The FBI’s investigation is ongoing, and sources indicate authorities are still looking at other individuals believed to be involved. The arrest of Dubrovsky follows a separate development last week in which Dutch authorities arrested what the FBI described as
“one of the alleged leaders”
of ShinyHunters.
Leatherman addressed the cybercriminals directly in a video statement posted after that arrest, sending a clear warning to anyone still involved.
“Arrests have a way of changing who is willing to talk and seized infrastructure has a way of showing us who is left,”
Leatherman said.
“The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.”
In the aftermath of the breach, ShinyHunters used their dark-web site to demand that the FBI revise a previous advisory about the group, claiming to be
“offended”
by how the agency described its alleged extortion tactics. Many cybersecurity professionals interpreted the demand as a veiled threat to leak the stolen data — though the hackers later said that was never their intent.
Meanwhile, some FBI employees expressed frustration over what they described as inadequate security resources offered to victims of the breach. Patel and Leatherman responded with a series of public statements and video updates aimed at keeping employees informed and warning those responsible.
Dubrovsky did not respond to a request for comment Friday night, nor did the public defender’s office in Philadelphia. The FBI also declined to comment when asked specifically about his arrest.