BREACH WATCH BRIEF High 💀 Threat intel

FBI Arrests Co‑Founder of Ransomware Negotiation Firm Amid ShinyHunters Investigation

The FBI detained Edward Dubrovsky, co‑founder of Cypfer (now CyberSteward), as part of the ShinyHunters probe. The arrest underscores the hidden third‑party risk of ransomware‑negotiation services and why continuous vendor oversight is essential for audit readiness.

SeverityHigh
Type💀 Threat intel
ConfidenceHigh
ReportedOct 10, 2026
Technology & SaaS Enterprises using ransomware negotiation or incident‑response services Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

The FBI arrested Edward Dubrovsky, co‑founder of the ransomware‑negotiation firm Cypfer (now CyberSteward), in connection with the ShinyHunters data‑theft investigation. The operation targets the criminal ecosystem that offers negotiation services to ransomware victims.

Why it matters for trust and compliance

  • This incident illustrates the necessity of continuous third‑party risk monitoring and documented due‑diligence to maintain a defensible control‑assurance posture.
  • Continuous monitoring of vendor legal status and sanctions listings.
  • Documented due‑diligence evidence to support audit readiness and control assurance.

Who is affected

Enterprises using ransomware negotiation or incident‑response services

Recommended actions

  1. Audit all existing contracts with ransomware‑negotiation firms for due‑diligence gaps.
  2. Implement continuous third‑party risk monitoring for legal and reputational alerts.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.