DOJ Indicts Ransomware Recovery Firm CEO Over Secret Hacker Payments and Overbilling
The U.S. Department of Justice on Wednesday filed a wire‑fraud indictment against the chief executive of a firm that markets itself as a ransomware‑recovery specialist. Prosecutors allege the executive secretly arranged payments to cybercriminals on behalf of clients while inflating the fees charged to those same victims.
Ransomware recovery companies have proliferated as ransomware attacks have risen, offering to negotiate with attackers, retrieve encrypted data and restore operations for a fee that can run into the hundreds of thousands of dollars. Many businesses, lacking in‑house expertise, turn to these intermediaries to avoid prolonged downtime and the reputational damage of a public breach.
According to the indictment, the CEO instructed his staff to make undisclosed wire transfers to hacker‑controlled accounts after a breach, then billed the affected organizations for a “full‑service” response that included a purported decryption tool. The complaint says the payments were concealed from clients, allowing the firm to claim higher recovery costs and retain the difference as profit.
The charge of wire fraud reflects a broader DOJ effort to crack down on facilitators of ransomware. Federal authorities have previously pursued ransomware negotiators and even cryptocurrency mixers, arguing that paying criminals fuels the cycle of extortion. By masking the payments, the alleged scheme not only defrauded victims but also potentially violated sanctions and anti‑money‑laundering rules.
If convicted, the executive faces up to twenty years in federal prison and substantial restitution. The case could prompt tighter regulation of third‑party cyber‑incident response firms, many of which operate with limited oversight. Industry observers say the outcome may push organizations to rely more on internal incident‑response teams or vetted, government‑approved vendors rather than independent recovery outfits.
Victims of the alleged scheme include several mid‑size companies in the healthcare and manufacturing sectors, which reported paying tens of thousands of dollars for the recovery service before discovering discrepancies in the invoices. Their attorneys have filed civil suits seeking damages, arguing that the hidden payments compromised the confidentiality of the breach and exposed sensitive data to the very criminals they had paid.
The indictment also highlights the challenges law‑enforcement faces in tracing cryptocurrency transactions used by ransomware gangs. While the DOJ says it tracked the wire transfers through traditional banking channels, many ransomware payments now flow through digital wallets that can obscure the ultimate beneficiary. Experts suggest that clearer guidelines and mandatory reporting of ransom payments could help authorities intervene earlier.
Comments (0)
Be the first to comment.
Join the discussion