Allegations of recovery fraud
A recent indictment from US federal authorities has detailed a fraud scheme involving a ransomware recovery specialist. The individual is alleged to have marketed services to businesses by claiming to possess proprietary technology capable of decrypting files without paying a ransom.
According to the charges, the provider did not use technical tools to restore access. Instead, he allegedly contacted the ransomware operators, negotiated a payment using his own cryptocurrency accounts, and then billed the victims a higher fee than the ransom requested. This practice was hidden from the clients, who believed they were paying for a technical service rather than a ransom settlement.
Risks to the victim
For a business, this creates several complications. First, the cost of recovery is artificially inflated by the intermediary's undisclosed margin. Second, the business may unknowingly violate internal policies or legal guidelines regarding payments to criminal organisations.
In many cases, ransomware recovery is a matter of restoring data from backups. When backups fail, businesses often look for external specialists. If a provider claims they can 'crack' modern encryption without a key from the attacker, these claims are often impossible to verify and, as this case suggests, may be a cover for simple negotiation.
Protecting your business
If your business is affected by ransomware, the first step is to isolate the affected systems and check the integrity of your offline or cloud backups. Before engaging a recovery firm, ask for a clear explanation of their methodology.
If a firm claims they can decrypt files, they should be able to explain the specific vulnerability they are exploiting in the ransomware's code. Be wary of any provider that requires an upfront fee while promising a guaranteed decryption that seems to bypass the need for an attacker's key. It is often safer to rely on professional cyber insurance providers and legal counsel who use vetted incident response teams.