Former Ransomware Negotiator Accused of Secret Deal with Cybercriminals to Split Victim Payments


# Former Ransomware Negotiator Under DOJ Investigation for Alleged Collusion with Cybercriminals

The Department of Justice is conducting a criminal investigation into a former ransomware negotiator suspected of secretly collaborating with cybercriminal gangs to profit from extortion schemes.

## The Investigation

The suspect previously worked for DigitalMint, a Chicago-based incident response company specializing in ransomware negotiations and cryptocurrency payment facilitation. The firm claims to have handled over 2,000 ransomware cases since 2017.

According to Bloomberg’s initial report, investigators are examining whether the former employee:
– Worked directly with ransomware groups during negotiations
– Received kickbacks from ransom payments
– Charged clients inflated fees while secretly profiting from the criminal activity

## Company Response

DigitalMint has confirmed the investigation and taken immediate action:
– Terminated the employee upon discovering the alleged misconduct
– Cooperated fully with law enforcement
– Clarified that the company itself is not under investigation

“We acted swiftly to protect our clients and have been cooperating with law enforcement,” stated CEO Jonathan Solomon. The company has begun notifying affected stakeholders about the situation.

## Industry Impact

Several law and insurance firms have reportedly advised clients to avoid using DigitalMint’s services during the ongoing investigation. Both the DOJ and FBI have declined to comment on the matter.

## Historical Context

This case echoes a 2019 ProPublica investigation that exposed similar practices among data recovery firms. Those companies secretly paid ransomware gangs while charging clients for restoration services, without disclosing the payments to attackers.

Some ransomware operations, including GandCrab and REvil, even created special discount programs and communication channels specifically for these intermediary firms.

## Industry Expert Analysis

Bill Siegel, CEO of ransomware negotiation firm Coveware, highlighted the systemic risks in certain business models:

“Business models that are financially incentivized towards larger transaction volume and higher transaction size do NOT fit within the incident response industry,” Siegel explained. “If an intermediary earns a large fixed percentage of a ransom, objective advice is not going to follow.”

Siegel emphasized that fixed-fee structures help prevent such conflicts of interest, noting that paying ransoms is often not the best decision for companies, though this can be difficult to communicate during high-stress situations.

## Key Takeaway

This investigation underscores the importance of transparency and ethical practices in the cybersecurity industry, particularly as ransom payments have escalated from thousands to millions of dollars in recent years.

Share This Article