Federal prosecutors charged a ransomware negotiator employed by an incident response firm with secretly colluding with the criminal groups he was hired to negotiate against.
According to the indictment, the negotiator inflated ransom amounts presented to victim companies, then received kickbacks from the ransomware operators via cryptocurrency wallets under his control.
The scheme surfaced during a broader investigation into a ransomware group's finances, when analysts noticed recurring payments to a wallet cluster later linked to the defendant.
The case has shaken the incident-response industry, prompting firms to introduce dual-negotiator protocols, payment audits and stricter conflict-of-interest controls.
