All news
Security
8 October 2026

US authorities charge ransomware recovery provider with fraud

A ransomware recovery specialist has been charged with defrauding clients by claiming to decrypt data while secretly paying ransoms to attackers. The provider allegedly charged fees higher than the ransom amounts and pocketed the difference without disclosing the payments to victims.

What this means for your business

Small and medium businesses should exercise caution when hiring ransomware recovery firms that claim to have proprietary decryption tools. If you suffer a data breach, seek verified legal and technical advice to ensure recovery efforts do not involve undisclosed payments to criminal groups.

Allegations of recovery fraud

A recent indictment from US federal authorities has detailed a fraud scheme involving a ransomware recovery specialist. The individual is alleged to have marketed services to businesses by claiming to possess proprietary technology capable of decrypting files without paying a ransom.

According to the charges, the provider did not use technical tools to restore access. Instead, he allegedly contacted the ransomware operators, negotiated a payment using his own cryptocurrency accounts, and then billed the victims a higher fee than the ransom requested. This practice was hidden from the clients, who believed they were paying for a technical service rather than a ransom settlement.

Risks to the victim

For a business, this creates several complications. First, the cost of recovery is artificially inflated by the intermediary's undisclosed margin. Second, the business may unknowingly violate internal policies or legal guidelines regarding payments to criminal organisations.

In many cases, ransomware recovery is a matter of restoring data from backups. When backups fail, businesses often look for external specialists. If a provider claims they can 'crack' modern encryption without a key from the attacker, these claims are often impossible to verify and, as this case suggests, may be a cover for simple negotiation.

Protecting your business

If your business is affected by ransomware, the first step is to isolate the affected systems and check the integrity of your offline or cloud backups. Before engaging a recovery firm, ask for a clear explanation of their methodology.

If a firm claims they can decrypt files, they should be able to explain the specific vulnerability they are exploiting in the ransomware's code. Be wary of any provider that requires an upfront fee while promising a guaranteed decryption that seems to bypass the need for an attacker's key. It is often safer to rely on professional cyber insurance providers and legal counsel who use vetted incident response teams.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.