Back to all lessons
Awareness Lessons
yesterday

Ransomware Recovery Firm CEO Charged with Defrauding Victims While Secretly Paying Attackers

MonsterCloud's CEO allegedly exploited victims at their most vulnerable moment — immediately after a ransomware attack — by falsely claiming proprietary decryption capabilities while simply paying ransomware gangs and massively marking up the cost. This case exposes a critical blind spot: organizations in crisis often cannot verify the claims of third-party recovery vendors, creating fertile ground for fraud. It also highlights the dangerous reality that engaging with ransomware attackers, even indirectly through a vendor, carries legal, financial, and ethical risks. The incident underscores that the incident response supply chain itself is an attack surface that requires due diligence, transparency, and contractual accountability.

Tactical Insight

Immediate actions

  • Vet any ransomware recovery or incident response vendor by requesting verifiable references, audited methodologies, and proof of claimed capabilities before signing contracts.
  • Require full financial transparency from recovery vendors, including itemized invoices that distinguish vendor costs from third-party payments.

Long-term improvements

  • Establish pre-vetted, contractually bound incident response retainer agreements with reputable firms before a crisis occurs, leaving no room for opportunistic vendors.
  • Include clauses in IR vendor contracts that explicitly prohibit undisclosed ransom payments and require disclosure of any negotiations with threat actors.
  • Build an internal incident response playbook so your team is never fully dependent on a single external vendor's unverifiable claims.

Detection & oversight measures

  • Engage an independent legal or forensic auditor to review all costs and actions taken by third-party recovery firms during and after an incident.
  • Cross-reference recovery vendor claims with threat intelligence feeds and law enforcement advisories to identify known ransomware groups and verify decryption feasibility.