Back to all lessons
Awareness Lessons
3 days ago

Ransomware Recovery Firm Charged With Secretly Paying Ransoms While Billing Victims $19M+

MonsterCloud's owner allegedly defrauded ransomware victims by secretly paying ransoms to obtain decryptors while falsely claiming to use proprietary recovery tools — charging clients far more than the actual ransom amounts. This case highlights a critical blind spot: organizations under duress often lack the technical expertise to vet the legitimacy or methods of incident response vendors they hire. The fraud persisted because victims had no visibility into what recovery actions were actually being taken on their behalf. This matters not only because of direct financial harm, but because secret ransom payments may violate OFAC sanctions regulations and can fund further criminal activity. Trust in third-party IR vendors must be earned through transparency, credentials, and contractual accountability — not assumed during a crisis.

Tactical Insight

Immediate actions

  • Verify incident response vendor credentials, certifications (e.g., CREST, DFIR), and references before engaging them during a ransomware event.
  • Require full written disclosure of all proposed recovery methods, including whether ransom payment is being considered, before signing any contract.

Long-term improvements

  • Establish a pre-vetted list of approved IR vendors with clear contractual clauses requiring transparency on recovery techniques and cost itemization.
  • Include audit rights in IR vendor contracts so your organization can review all payments and actions taken on your behalf.
  • Build internal incident response playbooks so staff can intelligently oversee and challenge external vendor recommendations.

Detection & compliance measures

  • Consult legal counsel on OFAC ransomware payment guidance before any third party acts on your behalf, as your organization may bear liability for undisclosed ransom payments.
  • Require itemized invoices and supporting evidence (e.g., logs, tool outputs) from any IR vendor to validate that claimed work was actually performed.