Ars Technica · July 11, 2026 · 1Cifer
A ransomware negotiator worked for the attackers: six years in prison and a lesson about vendor trust
A US court has sentenced a ransomware negotiator: the specialist whom victim companies hired to bargain with hackers was working for the attackers himself, helping them squeeze maximum ransom from his own clients. Six years in prison closes a scheme in which victims paid twice — the criminals, and their accomplice carrying a consultant's business card.
The story strikes at crisis management's weakest point. When a company is paralyzed by an attack, there's no time to vet the rescuers — you take the first person who confidently promises help. Secondary scams around incidents are built on exactly this effect, from fake "investigators" to conflicted consultants, and AI tools make such cover stories ever more convincing.
The practical conclusion for a company in Kazakhstan: choose your incident-response contractors before the incident, with a cool head. Put specific names into your response plan — a lawyer, a security firm, a negotiator — with verified references and contracts in place. A list drawn up on a calm Tuesday costs less than one hour of panic.


