556/69 Friday, October 9, 2026

The U.S. Department of Justice has charged an executive of MonsterCloud, a company providing ransomware recovery services, with allegedly defrauding organizations that had fallen victim to cyberattacks. According to reports, the company advertised that it possessed advanced proprietary technology capable of decrypting customers’ data without negotiating with ransomware groups. In reality, however, the company allegedly made secret ransom payments to hackers in exchange for decryption keys. The case highlights an additional risk faced by ransomware victims, who may not only suffer data loss but also be exposed to deceptive practices by service providers that lack transparency.
According to case details, the alleged scheme operated from mid-2018 through 2023. The company would first contact ransomware operators to purchase decryption keys, then use sample files decrypted by the attackers as evidence to convince victims that MonsterCloud had successfully recovered the data using its own capabilities. The financial impact was significant. In one case, the company reportedly paid a ransom of only USD 8,200 but charged the victim USD 150,000 for recovery services. Over the course of the scheme, the company allegedly collected more than USD 19 million from hundreds of organizations in the United States and Canada, while more than USD 8 million was passed on to cybercriminal groups. Concerns about the company’s lack of transparency had already been raised in 2019, when cybersecurity researchers conducted a controlled test and found that the company attempted to negotiate and pay a ransom instead of using the recovery techniques it claimed to provide.
The case serves as an important reminder for organizations and system administrators when selecting partners or service providers for cybersecurity incident response and recovery. Organizations should carefully verify the background and credibility of providers and clearly define contractual conditions regarding ransom payments and financial support to cybercriminals. However, the most sustainable and effective risk reduction measure is preparation before an incident occurs. Organizations should maintain regular backups, including offline copies that ransomware cannot access, and routinely test restoration procedures. This helps ensure that systems can be recovered and business operations can continue without depending on cybercriminals or exposing the organization to additional fraud.
