A Canadian Ransomware Negotiator Was Charged: How to Vet Your Incident Response Firm
On October 8, 2026, the FBI arrested Edward Dubrovsky, a Canadian cybersecurity executive whose firms help ransomware victims negotiate with criminals, on US extortion conspiracy charges. He has not been convicted, and the complaint is sealed. For Canadian small businesses, the useful question is not what he did, which no court has decided. It is how you would vet an incident response firm before a crisis forces the choice.
Most small businesses meet their incident response firm on the worst day of the year, often through an insurer, a lawyer or a quick search. This post sets out what has been reported about the case, carefully, and then a checklist you can use now.
What Has Been Reported About the Dubrovsky Case?
Federal court records show Dubrovsky, 54, was arrested in Pennsylvania on October 8, 2026, according to KrebsOnSecurity and CyberScoop. The docket lists conspiracy to threaten to impair the confidentiality of information with intent to extort money, and Hobbs Act extortion charges (a US federal law against extortion that affects commerce). The complaint itself is sealed, and the case has been moved to the Eastern District of Texas.
Other reported details, each attributed:
- Why he was in Pennsylvania: KrebsOnSecurity reported he was attending a cyber insurance conference, and BleepingComputer said he was attending a cybersecurity conference when he was arrested.
- His background: Reports describe him as a former senior executive at CYPFER, a Canadian firm that helps organizations negotiate with ransomware operators, who is also associated with another firm, CyberSteward. His exact title is disputed. A CYPFER spokesperson told KrebsOnSecurity he was not a founder, as his LinkedIn profile claims, but a managing director who resigned in November 2025.
- What is not known: BleepingComputer notes that because the complaint is sealed, it is still unclear what he is accused of doing. Neither he nor CYPFER responded to CyberScoop's requests for comment.
Is the Case Linked to ShinyHunters?
It is reported, not confirmed. KrebsOnSecurity said multiple sources tied the arrest to the FBI's investigation of ShinyHunters, the extortion group that breached the FBI's online recruitment portal. FBI Director Kash Patel announced the arrest of "another suspected co-conspirator" of the group without naming anyone. As BleepingComputer and CyberScoop both note, the FBI has not publicly named Dubrovsky as that suspect.
The group matters to Canadian businesses either way. According to the FBI, as reported by KrebsOnSecurity and BleepingComputer, ShinyHunters has extorted more than $70 million from victims. In April, ShinyHunters used one Canada Life employee's account to reach the insurer's Salesforce environment, exposing personal information of up to 70,000 people, as we covered in our Canada Life data breach explainer.
KrebsOnSecurity also reported, citing sources, that charges against principals at other ransomware negotiation companies may be forthcoming. Treat that as unconfirmed until charges are filed.
Why Does This Matter If Nothing Is Proven?
Because the case, whatever a court in the Eastern District of Texas eventually decides, shows how much trust a victim hands to the firm in the middle. During a ransomware or extortion incident, the response firm may talk to the criminals, advise on whether to pay, and handle the money. Whatever the outcome of this case, a business that chose its firm in a panic has no basis for judging whether that trust is deserved.
The fix is ordinary due diligence, done in advance. The Cyber Centre's Baseline Controls put incident response first, as BC.1 on our incident response control page explains, and our guide to building an incident response plan notes that knowing who to call before an incident saves critical time.
How Do You Vet an Incident Response Firm?
Vet an incident response firm before you need one, using written answers rather than a sales call. The six checks below cover who the firm answers to, who can approve payments, how it gets paid and how the crime gets reported. None of them requires technical knowledge, and most take a single email to your insurance broker, your lawyer or the firm itself.
- Check your insurer's panel first. Ask your broker whether your cyber policy requires a specific response firm or breach coach, and whether using a firm outside that list affects coverage. Get the answer in writing.
- Decide who can authorize payment. Write down which named executives can approve any payment or any contact with the criminals, and require the firm to get that approval in writing every time. A response firm should never be the one deciding.
- Understand how the firm is paid. Ask whether any fee depends on the size of a ransom or a settlement. A flat or hourly fee removes an obvious conflict of interest.
- Ask who else it works for. A firm that also sells to your insurer, your lawyer or your IT provider may be the right choice, but you should know. Ask for its conflict-of-interest policy and two client references.
- Make reporting non-negotiable. Your contract and your plan should say the crime will be reported, whatever the firm advises. See the next section.
- Keep your own records. Insist on copies of every message exchanged with the attackers and every payment instruction. If questions come up later, you need your own evidence, not the firm's summary.
Where Should the Crime Be Reported in Canada?
Report it to police and the national system, whatever your response firm says. Most businesses file through the National Cybercrime and Fraud Reporting System run by the RCMP's NC3 and the Canadian Anti-Fraud Centre, plus their local police, as our guide on how to report a cyber attack in Canada explains. The Cyber Centre's playbook says to contact local police before even considering payment.
On paying, the Canadian Centre for Cyber Security's Ransomware Playbook (ITSM.00.099) says the decision belongs to your organization, but warns that paying may be unlawful under laws against terrorism, money laundering, funding criminal organizations or sanctions legislation. Our ransomware guide quotes the Government of Canada's position that it does not recommend paying ransom to cyber criminals.
Two other calls belong in the first hours. Notify your insurer, because most policies require prompt notification, often within 24 to 72 hours, as our cyber insurance guide explains. And involve legal counsel early, since contact with criminals and any payment decision carry legal risk.
The Question to Ask This Week
Put one question to your IT lead or provider: "If we were hit tonight, which incident response firm would we call, who chose it, and who has authority to approve any payment?" If nobody can answer in one sentence, that gap is worth closing before anything else.
To see how ready your business is across incident response and the other Baseline Controls, take our free cybersecurity assessment. It takes under 30 minutes and gives you a prioritized list of what to fix first.
How prepared is your business?
Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.
Check Your ScoreFrequently Asked Questions
Who is Edward Dubrovsky and what is he charged with?
Edward Dubrovsky is a 54-year-old Canadian cybersecurity executive who has held senior roles at firms that help ransomware and extortion victims negotiate with criminals. He was arrested in Pennsylvania on October 8, 2026. The docket lists conspiracy to threaten to impair the confidentiality of information with intent to extort money, and Hobbs Act extortion charges. The complaint is sealed, he has not been convicted, and the case was moved to the Eastern District of Texas.
Is the Dubrovsky case connected to ShinyHunters?
It is reported, not confirmed. KrebsOnSecurity said multiple sources linked the arrest to the FBI's ShinyHunters investigation, and FBI Director Kash Patel announced the arrest of an unnamed suspected ShinyHunters co-conspirator the same week. The FBI has not publicly confirmed that Dubrovsky is that suspect, and because the complaint is sealed, what he is accused of doing is still unclear.
How should a small business choose an incident response firm?
Choose before an incident. Check whether your cyber insurance policy requires a firm from the insurer's panel, get written terms on who can authorize any payment or contact with criminals, confirm how the firm is paid, and make sure your plan still reports the crime to police and the national cybercrime reporting system. Ask for references and how the firm handles conflicts of interest.
Does the Government of Canada recommend paying a ransom?
No. The Government of Canada does not recommend paying ransom to cyber criminals. The Canadian Centre for Cyber Security's ransomware playbook says to contact your local police before you even consider paying, and warns that paying may be unlawful under laws against terrorism, money laundering, funding criminal organizations or sanctions.
Cite This Page
Suggested citation:
Cybersecurity Canada (2026). A Canadian Ransomware Negotiator Was Charged: How to Vet Your Incident Response Firm. Retrieved from https://cybersecuritycanada.ca/news/posts/canadian-ransomware-negotiator-charged-how-to-vet-incident-response-firm/
Permanent URL: https://cybersecuritycanada.ca/news/posts/canadian-ransomware-negotiator-charged-how-to-vet-incident-response-firm/ · Published October 11, 2026
Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.
Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.
How does your organization measure up?
Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.
Take the Free Assessment