Ransomware consultant said he would decrypt data, is accused of paying ransoms instead

Friday, October 9, 2026
There may be several reasons why clients chose to use MonsterCloud. US government advice (echoed by other governments) is not to pay ransoms as it may encourage more attacks, and victims may not get their data back. In addition, in some cases, if the attackers are from a country or group subject to trade sanctions, making a payment may actually be illegal, leaving the victim facing criminal charges.
There may be other factors at play. “Cases vary; sometimes negotiators simply overcharge for their services. In other cases, they may inflate the final amount, saying, for instance, that 50 percent extra is to ensure a third-party validation of secure data erasure or something similar that the client would buy,” said Ilia Kolochenko of cybersecurity company ImmuniWeb.
He warned that there were several techniques being used to extract additional money from ransomware victims.
“Some will be contacted by fake law enforcement agencies, which typically promise to find and arrest the hackers, but also mention the victim’s civil liability for the data breach and ask to prepay a bond for an eventual regulatory fine. Other victims may be contacted by fake cybersecurity companies, which claim that they have already found their stolen data on the Dark Web and ask for money to ‘securely erase’ the data from the dark web to avoid bad publicity and regulatory sanctions,” he said.
Similar cases have come to court recently, said Kolochenko, one in July involving a Florida business and another targeting a Latvian national in May. Read Full Article
IT PRO: New Google Gemini setting could give AI tool broad access to users' Macs
CISO Voice: La FTC confirma la investigación a OpenAI y Anthropic por riesgos al consumidor