He wrote the guide to negotiating with ransomware crews. He was arrested at a security conference.
Edward Dubrovsky made his name on the other end of the phone from ransomware gangs. He co-founded CYPFER, a Canadian firm built around negotiating with them on behalf of companies that had just been broken into, and he recently published a guide to doing it. On Thursday 9 October the FBI arrested him in Pennsylvania, where he was attending a cybersecurity conference.
He is 54. The charges are conspiring to threaten the confidentiality of information in order to extort money, a federal computer fraud offence, plus Hobbs Act extortion and conspiracy to commit it. He has been moved to the Eastern District of Texas and is in custody there. The complaint is sealed, so the government's version of events is not public yet, and nobody should treat a charge as a verdict. Several outlets have connected the arrest to the investigation into ShinyHunters, the extortion crew that breached the FBI's own jobs portal, and the bureau's director announced the arrest of another suspected co-conspirator the same week without naming anyone.
ShinyHunters has turned up here before, over McKesson and Carhartt among others. The FBI counts more than 140 organizations compromised and over $70 million collected in extortion payments from them in the past year alone, with other suspected members picked up in the Netherlands and Jordan.
The uncomfortable read is that you cannot tell from the outside who is trustworthy with your data, including the people hired to clean up afterwards. What you can control is how far one leaked password travels. Tendvane's privacy and accounts check goes through the sign-in settings on your PC and shows which accounts are still protected by a password alone.