P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

MonsterCloud indictment: alleged fee was 18.3 times the ransom in one case and 1.6 times in the other

The US indictment of the owner of MonsterCloud gives two worked examples: an alleged fee of 18.3 times the ransom in one, 1.6 times in the other. Nothing is proved, and the record shows what a UK buyer of ransomware help should ask in writing.

By Parminder Kumar Sharma · · 20 min read

A dark room with a graphite laptop at the back right whose screen, washed in coral-red light, shows a locked-out notice made of one empty pill, three grey bars and a grid of twelve blank tiles. On the walnut desk in front lie one very large pale invoice-sized sheet, ruled with empty grey bars and one amber pill, and one tiny curled receipt slip with a single bar: a big bill beside a small payment. Our own words at left read alleged about $150,000 fee on about $8,200 ransom, 18.3 times.

In the indictment's two worked examples, the alleged fee was 18.3 times the ransom in one and 1.6 times in the other

The US indictment of the owner of MonsterCloud, a Florida company the indictment calls a "purported ransomware remediation company", gives two worked examples of what a client was allegedly charged against what the company allegedly paid the attackers. In or around August 2023: about $150,000 charged, about $8,200 paid as ransom. That is 18.3 times (derived; the indictment says "nearly twenty times"). In or around October 2021: about $380,000 charged, about $236,000 paid. That is 1.6 times (derived). For the whole alleged scheme, the indictment says more than $19 million was charged and more than $8 million was paid in ransoms.

All of this is allegation. The owner is charged, not convicted, and is presumed innocent. The Department of Justice (DOJ) says the owner was indicted on 23 September 2026 in the Eastern District of New York on two counts of wire fraud and one count of wire fraud conspiracy, and was arraigned on 7 October. In its own words: "An indictment is merely an allegation." We do not name the defendant. The DOJ names the company, and this briefing is about the company's alleged conduct. We name no one else in the record either: not the spokesperson, the clients, the co-conspirators or the officials, only their roles.

Here is what that opening fact does not establish:

  • That 18.3 is typical. It is the larger of the two examples the indictment chooses. The same document says the "full" service cost "up to two or more times the ransom", and that fees were "sometimes multiple times higher". The other example is 1.6.
  • That the gap is profit. Fees minus ransoms is not profit. The indictment gives no cost figure, and it describes the $19 million only as payment for "data recovery and remediation services", a package that also had an analysis phase quoted at roughly $2,500 to $10,000.
  • That any of it is proved. The figures are the government's. No court has tested them, and neither DOJ release says what the defence will argue.
  • Anything about any other recovery or negotiation firm. The record concerns one company.
  • That a fee above the ransom is unlawful in itself. The documents frame the alleged wrong as false claims of a decryption capability and concealment of the payments, not the size of the invoice.

What the court record fixes, and what it leaves out

The news pointers are consistent with the DOJ on the headline figures. Apart from the plea and bond reporting flagged above, we took nothing from them that the DOJ text does not carry. Two DOJ releases exist, one from the Office of Public Affairs and one from the US Attorney's Office for the Eastern District of New York, and the indictment itself is a ten-page filing. Table 1 sets what they fix against what they do not say.

Table 1. What the DOJ releases of 7 October 2026 and the indictment filed 23 September 2026 (case 1:26-cr-00271, Eastern District of New York, Brooklyn) fix, and what they leave unstated.

  1. Topic
    Charges
    Fixed on the record
    Count One, conspiracy to commit wire fraud. Counts Two and Three, wire fraud. A forfeiture notice. DOJ: a maximum of 20 years on each count
    Not stated
    A combined sentence. Any other charge. Any plea in either release
  2. Topic
    Period
    Fixed on the record
    "From at least on or about" 1 June 2018 to "on or about" 30 June 2023, both "approximate": 1,856 days, about 5.1 years (derived)
    Not stated
    Why the August 2023 example falls after the end date
  3. Topic
    The counts
    Fixed on the record
    Count Two: a wire of about $175,000 on or about 26 April 2021 from one New York company to the owner's Florida bank account. Count Three: a phone call on or about 2 August 2021 with a second New York company
    Not stated
    The ransom, if any, paid for the Count Two client. Neither worked example is one of the counts
  4. Topic
    How clients found it
    Fixed on the record
    The website said "our team specializes in helping businesses recover their data without succumbing to ransom demands". Many clients first used its "Contact Us" form
    Not stated
    Advertising, referrals, how many clients arrived another way
  5. Topic
    What clients were told
    Fixed on the record
    Do not pay. "Proprietary tools" and "advanced decryption techniques". Methods withheld as "trade secrets". Some contracts said the firm "might" contact or pay attackers
    Not stated
    How many clients signed which wording, and what each understood
  6. Topic
    What is alleged happened
    Fixed on the record
    No proprietary technology. The owner contacted and paid attackers for keys that staff then used. The fee was typically "substantially higher". Payments typically went undisclosed
    Not stated
    How many clients got files back, or how completely. The release says only that staff used keys "in an attempt" to decrypt
  7. Topic
    Scale
    Fixed on the record
    "Dozens" of ransom payments. More than $8 million paid. Hundreds of companies in the United States and Canada paid more than $19 million. At least two have offices in the Eastern District
    Not stated
    A count of victims who lost money. Restitution. Any ratio across the whole scheme
  8. Topic
    Attackers and payment
    Fixed on the record
    The payees are "cybercriminals". Ransoms are described generally as "often" in cryptocurrency
    Not stated
    Any ransomware group, wallet or payment channel named
  9. Topic
    Sanctions
    Fixed on the record
    Nothing in either release or the indictment
    Not stated
    Whether any payee was a sanctioned person
  10. Topic
    Outside the US
    Fixed on the record
    Canada is named. The DOJ thanks its Office of International Affairs for help
    Not stated
    Any UK victim. What the international help was
  11. Topic
    Others
    Fixed on the record
    "Multiple co-conspirators", known and unknown to the grand jury, including employees and contractors. The FBI is investigating
    Not stated
    Any other defendant or further charge

Two points of reading. First, the Count One period ends on 30 June 2023, yet the indictment dates its best-known example to "in or around August 2023", and both DOJ releases repeat the date. The charged dates are labelled approximate on the face of the document, and no release addresses the gap, so we report both as written and do not reconcile them. Second, the Eastern District release says the owner used a portion of clients' fees to pay attackers and "kept the rest". The indictment text speaks of fees charged and ransoms paid and gives no figure for costs, staff or profit.

The money: what each figure counts

The headline figures count three different things, and the briefing keeps them apart. A fee is what a client was billed. A ransom is what the indictment says went to an attacker. The gap between them is a subtraction, not a finding. Table 2 shows each derived number and what it leaves out.

Table 2. Derived figures from the indictment (paragraphs 12, 14, 15 and 20) and the counts. All inputs are the government's approximate or minimum figures.

  1. Inputs
    August 2023 example: fee about $150,000, ransom about $8,200
    Derived
    18.3 times. Ransom is 5.5% of the fee. Gap about $141,800, which is 94.5% of the fee
    What it does not show
    A count in the indictment. Costs. What the client knew
  2. Inputs
    October 2021 example: fee about $380,000, ransom about $236,000
    Derived
    1.6 times. Ransom is 62.1% of the fee. Gap about $144,000, 37.9% of the fee. The indictment says "nearly $150,000"
    What it does not show
    Costs. What the client knew
  3. Inputs
    Whole scheme: more than $19 million charged, more than $8 million paid
    Derived
    On the minimums: 2.4 times, 42% paid out, gap about $11 million, 58% of the fees
    What it does not show
    Both are floors, so the true ratio could be higher or lower. The DOJ gives no gap and no profit
  4. Inputs
    Analysis phase: quoted "typically" at about $2,500 to $10,000, with a money-back guarantee
    Derived
    1.7% to 6.7% of $150,000 (derived)
    What it does not show
    Whether the analysis fee sits inside the $150,000 and the $19 million. How many clients stopped after this phase
  5. Inputs
    Count Two wire: about $175,000 on 26 April 2021
    Derived
    None. No ransom is given for this client
    What it does not show
    Whether it resembles either example

SecurityWeek's headline puts the gap at an "$11M markup". That is the same subtraction we made, 19 minus 8, of two minimums. The DOJ states neither a gap nor a profit, and "markup" in the Eastern District release is a description of fees against ransoms, case by case, not a total.

Three horizontal bars show the alleged fee split into ransom paid and the rest. August 2023: fee about 150,000 dollars, ransom about 8,200, 5.5 percent, fee 18.3 times the ransom. October 2021: fee about 380,000 dollars, ransom about 236,000, 62.1 percent, 1.6 times. The first two share one scale. Whole scheme, own scale, on minimums: over 19 million charged, over 8 million paid, 42 percent, about 2.4 times. All derived from the indictment.
Drawn from paragraphs 15 and 20 of the indictment filed 23 September 2026. Ratios, shares and gaps are our derivations. The whole-scheme bar uses minimums and its own scale.

The picture is the argument. The August 2023 example is a thin orange sliver on a long bar: the alleged ransom was about one part in eighteen of the fee. In the October 2021 example the ransom is most of the fee. A reader who remembers only the 18.3 will overestimate the typical gap, and one who remembers only the aggregate will underestimate the worst case. The record supports both pictures, which is why neither number should travel alone.

What clients were told, and what the indictment alleges

The case rests on a gap between what a client could see and what the indictment says happened behind it. Table 3 lines the two up, using the indictment's own paragraphs. It is an account of allegations, not of findings.

Table 3. What the client was shown, against what the indictment alleges (paragraph numbers in brackets).

  1. What the client was shown
    A website that cautioned against paying and offered recovery "without succumbing to ransom demands" (8)
    What the indictment alleges
    The suggestion of proprietary technology was false, and multiple clients engaged the firm because they would not have authorised any payment (8, 9)
  2. What the client was shown
    "Proprietary tools" and "advanced decryption techniques", methods kept as "trade secrets" (17)
    What the indictment alleges
    No specialised or proprietary technology existed, and no specialised method of decrypting files (9, 17)
  3. What the client was shown
    An analysis phase, quoted at about $2,500 to $10,000, with a money-back guarantee (10, 12)
    What the indictment alleges
    The owner or staff took the ransom note and usually two sample encrypted files from the client (13)
  4. What the client was shown
    "Recovery proofs": decrypted samples offered as evidence of capability (10, 13)
    What the indictment alleges
    In many instances the owner shared the samples with the attacker and got decrypted samples back, without telling the client (13)
  5. What the client was shown
    A "full" recovery contract, costing "up to two or more times the ransom" (14)
    What the indictment alleges
    Fees were typically "substantially higher", sometimes multiple times, than the ransom paid, and the difference was typically not disclosed (9, 15)
  6. What the client was shown
    A contract line that the firm would contact attackers "only once all possible means of directly decrypting Client's files have been exhausted" (16)
    What the indictment alleges
    Dealing with attackers was generally the first step, and the standard way keys were obtained (16)
  7. What the client was shown
    Staff vocabulary: "recovery tool" (18)
    What the indictment alleges
    Staff were directed to say "recovery tool" instead of "decryptor", and not to disclose payments (18)
  8. What the client was shown
    A paid spokesperson on the website (19)
    What the indictment alleges
    In May 2019 the spokesperson asked whether the firm had proprietary decryption software. The owner allegedly replied: "MonsterCloud doesn't hold any Proprietary technology [to] decrypt the ransomware data" (19)

Fairness needs two further facts. The indictment itself says some contracts told clients the firm "might communicate with or pay cybercriminals", so the allegation is not that the contracts were silent. The allegation is that the order described, payment last, was untrue in practice, and that payments were generally not disclosed. Separately, The Hacker News quotes a question and answer on the company's website. We read the page on 8 October: asked "Do you pay ransoms on behalf of your clients to recover data?", it answers that the firm "sometimes" resorts to "other means" and ends: "All terms are disclosed in our service contract." We do not know when that wording was published, and the answer does not say in terms that the firm pays attackers. Whether it told a client enough is a question for the court, and BleepingComputer says it asked the defendant's lawyers for comment.

Three labels that are not controls

"Ransomware recovery" and "decryption" as a service label. The indictment calls the company a "purported ransomware remediation company". A label like that tells a buyer what the firm sells, not how it gets there. The NCSC's own guidance says the opposite of an easy claim: "Files encrypted by most ransomware typically have no way of being decrypted by anyone other than the attacker", and points to the No More Ransom Project for the exceptions. So a claim of proprietary decryption of a current ransomware family is the thing to test: which family, which weakness, which public tool, and what evidence. The indictment alleges that the evidence on offer, the "recovery proofs", came through the attacker.

"Do not pay" as a brand. The website's caution against paying matches official advice. The NCSC and UK law enforcement "do not encourage, endorse nor condone" ransom payments, and the DOJ release cites FBI and CISA guidance that does not recommend paying. Agreeing with the regulator is cheap. The alleged gap was between the advice on the page and the practice behind it, so the advice was never the tell.

Reputation. The DOJ's headline calls the owner a "known cybersecurity expert". A reputation is another claim a buyer cannot audit from outside. We say this without drawing any conclusion about the defendant: the same applies to any firm's marketing, including ones that are entirely above board.

What the case does not say matters as much. The documents do not allege that paying attackers is unlawful in itself, and UK guidance states: "The ultimate decision whether to pay the ransom is with the victim." The alleged wrong is deceiving clients who, in multiple cases, would not have authorised a payment. So the control is not "does the firm ever pay". It is "who decides, on what information, and who can prove it". For the same discipline applied to ransomware brand names, see our earlier briefing on one affiliate, four ransomware brands.

For UK organisations that hire ransomware recovery or negotiation help

Neither DOJ release nor the indictment names a UK victim. The only non-US place named among the clients is Canada. The relevance to a UK reader is the structure, not the geography: a third party stands between you and the attacker and holds the evidence you would need to check it. UK guidance already says what to ask. Everything below is from the primary pages we read on 8 October 2026.

Who decides about paying. The NCSC, with the insurance bodies ABI, BIBA and IUA, states in guidance first published on 14 May 2024: "The ultimate decision whether to pay the ransom is with the victim." It recommends consulting experts such as insurers, the NCSC, law enforcement or Cyber Incident Response (CIR) companies.

Sanctions. The Office of Financial Sanctions Implementation (OFSI) guidance, updated on 28 January 2026, says that making funds or economic resources, including cryptoassets, available to a person under an asset freeze is prohibited, and that breaches are a serious criminal offence. Its civil penalty maximum is the greater of £1 million or 50% of the value of the breach. It says paying a designated person might expose victims, and "organisations facilitating ransomware payments on behalf of the victim", to liability. The onus of due diligence is on the organisation. Ransomware payments are "unlikely" to receive a licence. A suspected payment to a designated person should be reported to OFSI. A firm that pays an attacker for you is exactly that facilitator, so ask how it screens.

The regulator. In a joint letter of 7 July 2022 the NCSC and the Information Commissioner said the ICO "does not consider the payment of monies to criminals who have attacked a system as mitigating the risk to individuals" and that payment will not reduce any penalty. The ICO's guidance gives the same view and sets the notification rule: tell the ICO "no later than 72 hours" after becoming aware of a personal data breach likely to risk individuals. That deadline runs to the regulator, not to the public, as our earlier briefing on the 72 hour clock set out. The ICO marks that guidance as under review because of the Data (Use and Access) Act. A payment, by you or on your behalf, stops neither the clock nor the penalty.

What "assured" means. The NCSC recommends that all UK organisations use an NCSC-assured CIR provider. The NCSC owns the scheme, its delivery partners CREST and IASME deliver the Standard Level for it, and the NCSC runs the Enhanced Level assessment itself, with a panel of NCSC and industry experts. Assurance covers a provider's capability, the competence of its lead consultant or team leader, a Cyber Essentials certificate (Plus at Enhanced Level), and basic checks on financial and security standing. At Enhanced Level those checks include whether the company or its officers have been convicted of offences such as fraud, and a credit risk indicator at joining. Membership is reviewed at least every two years. The NCSC's buyer's guide is candid about the limits: "you should not rely on" membership as a guarantee that using a company "will be risk-free", the NCSC is not party to your contract, and clients "will need to do their own due diligence". The buyer's guide does not mention ransom negotiation, payment policy or fee structure. Our inference, from the wording, is that a conviction check cannot see a charge. We make no suggestion that any scheme member is the subject of any allegation.

Where to report. The UK government's "where to report a cyber incident" service, run by the NCSC, routes a ransomware report. The NCSC's guidance also names report.ncsc.gov.uk and the Report Fraud website, which serves England, Wales and Northern Ireland. Scottish reports go to Police Scotland on 101. The OFSI guidance and the National Crime Agency page still say Action Fraud, so expect both names in use. The service states that what you tell it is not shared with the ICO, so the ICO notification is separate. The NCA leads the law enforcement response to ransomware, according to the 2022 joint letter.

Table 4. UK ransom-payment measures as found on 8 October 2026: what exists, and what we could not find.

  1. Measure
    Home Office proposals, consulted January to 8 April 2025
    Found
    Three proposals: a targeted ban on payments by public sector bodies and regulated critical national infrastructure; a payment prevention regime, where victims report an intent to pay and government may block payments to sanctioned persons; mandatory incident reporting. Response of 22 July 2025: 273 responses, "will continue to develop"
    Not found
    A date. Draft clauses. A settled answer on third-party payment facilitators, which respondents raised
  2. Measure
    Cyber Security and Resilience (Network and Information Systems) Bill
    Found
    Passed the Commons on 16 June 2026. Lords committee ended 7 September. Report stage listed for 26 October 2026
    Not found
    The word "ransom" anywhere in the text as amended in Grand Committee. Any payment ban
  3. Measure
    Cyber Extortion and Ransomware (Reporting) Bill
    Found
    A private member's bill. First reading 21 October 2025. No second reading sitting is recorded. Last updated 1 May 2026. Its long title concerns reporting, including payments made
    Not found
    A payment ban in its long title
  4. Measure
    King's Speech 2026, 13 May 2026, and the Security Minister's speech of 30 September 2026
    Found
    The speech notes name the cyber bill. The minister mentions ransomware once, in passing
    Not found
    The word "ransom" in the 129-page background notes

So, as of 8 October 2026, a ban on ransom payments by the public sector or critical national infrastructure is a government proposal, not law, and we found no bill carrying it. Status could move, and the cyber bill's report stage is eighteen days away. Table 5 turns the case into questions to put in writing before you sign.

Table 5. What to ask a recovery or negotiation firm in writing before engagement, and which alleged failure each question tests.

  1. Ask in writing
    Will you ever contact or pay attackers for us, and on whose authority?
    Alleged failure it tests
    Payments made, in many cases without informing or consulting the client
    Evidence to ask for
    A clause that no contact or payment happens without our signed instruction
  2. Ask in writing
    Will you tell us before and after, and give us copies?
    Alleged failure it tests
    Payments typically undisclosed. "Recovery tool" used for "decryptor"
    Evidence to ask for
    Copies of every attacker exchange, the payment record and the amount
  3. Ask in writing
    What will decrypt our files, and how do you know?
    Alleged failure it tests
    "Proprietary tools" kept as "trade secrets"
    Evidence to ask for
    The ransomware family identified, and the technical basis, such as a public decryptor. No trade-secret refusal
  4. Ask in writing
    Who holds the keys, the samples and the proof?
    Alleged failure it tests
    "Recovery proofs" produced through the attacker
    Evidence to ask for
    Samples we choose, tested where we or an independent party can watch. We keep the originals
  5. Ask in writing
    How do you screen for sanctions before any payment?
    Alleged failure it tests
    Facilitating a payment is a risk under UK sanctions law
    Evidence to ask for
    A named process, dated evidence, who signs off, and a commitment to report to OFSI and the NCSC
  6. Ask in writing
    What is your fee structure, and is any attacker payment passed through at cost?
    Alleged failure it tests
    A fee typically "substantially higher" than the ransom, not disclosed
    Evidence to ask for
    An itemised invoice that separates fees from any attacker payment
  7. Ask in writing
    What insurance and certification do you hold, and are you on the NCSC CIR scheme?
    Alleged failure it tests
    A label is not a control
    Evidence to ask for
    The CIR level, checked on the NCSC list directly, and your own due diligence

What to do, in order

This is defender-level advice for a UK organisation, drawn from the NCSC, OFSI and ICO pages above and from the indictment's allegations. It is not legal advice.

Take this with you

Actions, in the order worth doing

  • Before any incident, decide in writing who may authorise contact with attackers or any payment, and put "no contact and no payment without that person's signed instruction" into every recovery or incident response retainer.
  • Check any provider on the NCSC website directly: whether it is on the Cyber Incident Response list and at which level. Then do your own due diligence, which the NCSC says is the buyer's job.
  • Put the questions in Table 5 to the provider in writing, and keep the answers with the contract.
  • When files are encrypted, keep your own copy of the ransom note and of any sample files you hand over, and record decisions on a system the attack has not touched, as the NCSC advises.
  • Report the incident: the where-to-report service, Report Fraud or Police Scotland, the NCSC, your insurer or broker, and your sector regulator if you have one.
  • If personal data is involved, decide whether to notify the ICO within 72 hours of becoming aware. A payment, by you or for you, does not change that duty or reduce a penalty.
  • Before anyone pays anything, check sanctions, and tell OFSI as soon as practicable if you suspect a payment reached a designated person.
  • Before you accept a decryption claim, check the No More Ransom Project, and ask for the family name and the technical basis in writing.
  • After the incident, ask for an itemised invoice, reconcile it against the copies of attacker exchanges, and record the decision trail for the board.

The question that exposes the gap

On the indictment's account, the arrangement worked while a client could not tell a firm that decrypts from a firm that buys the key. So put the question to the provider you would call tonight. If it paid the attackers on your behalf last Tuesday, which document in your files would say so, who wrote it, and would they have written it if you had not asked?

Key facts

Sources

  1. PrimaryPress release of 7 October 2026, press release number 26-1153, read in full: charges, 20 years on each count, the $8,200 and $150,000 example, over $19 million charged and over $8 million paid, official statements, the allegation and presumption of innocence wordingUS Department of Justice, Office of Public Affairsaccessed 2026-10-08
  2. PrimaryPress release of 7 October 2026, read in full in a browser tab (the plain fetch met a security interstitial and was not bypassed): arraignment in Brooklyn, indictment date, the "kept the rest" and "substantial markup" wording, docket number, thanks to the Office of International AffairsUS Attorney's Office, Eastern District of New Yorkaccessed 2026-10-08
  3. PrimaryThe indictment, case 1:26-cr-00271, document 1, filed 23 September 2026, ten pages. A scanned image: read by rasterising each page and checking every figure and quotation by eye. Source of the counts, the period, the two worked examples, the recovery process and the victims paragraphUS District Court, Eastern District of New Yorkaccessed 2026-10-08
  4. PrimaryRansomware hub, read in full: law enforcement position on payment, the recommendation to use an assured Cyber Incident Response providerNational Cyber Security Centreaccessed 2026-10-08
  5. PrimaryMitigating malware and ransomware attacks, read in full: files encrypted by most ransomware typically cannot be decrypted by anyone but the attacker, No More Ransom, reporting routesNational Cyber Security Centreaccessed 2026-10-08
  6. PrimaryGuidance for organisations considering payment in ransomware incidents, version 1.0 of 14 May 2024, read in full: the decision is the victim's, consult experts, sanctions, record decisions, reportingNCSC with ABI, BIBA and IUAaccessed 2026-10-08
  7. PrimaryCyber Incident Response scheme introduction, read in full: what the scheme is, the recommendation to use an assured provider, the two levelsNational Cyber Security Centreaccessed 2026-10-08
  8. PrimaryCIR information for service providers, read in full: assessment panel, delivery partners CREST and IASME, Cyber Essentials requirements, client due diligenceNational Cyber Security Centreaccessed 2026-10-08
  9. PrimaryAssured CIR Scheme Buyer's Guide v1.0, March 2025, eight pages, read in full: what assured means, who delivers each level, the checks made, the limits, the two-year review. It does not mention ransom negotiation or paymentNational Cyber Security Centreaccessed 2026-10-08
  10. PrimaryJoint letter of 7 July 2022 to the Law Society and the Bar Council, read in full: payment is not mitigation and will not reduce an ICO penalty, payments not usually unlawful but sanctions apply, the NCA leads the law enforcement responseInformation Commissioner's Office and NCSCaccessed 2026-10-08
  11. PrimaryRansomware and data protection compliance, scenarios 3 and 7 read in full: the 72 hour rule and the ICO view of payment. Marked under review because of the Data (Use and Access) ActInformation Commissioner's Officeaccessed 2026-10-08
  12. PrimaryFinancial sanctions guidance for ransomware, updated 28 January 2026, read in full: asset freezes, facilitators, the penalty ceiling, licensing, reporting, due diligenceOffice of Financial Sanctions Implementation, HM Treasuryaccessed 2026-10-08
  13. PrimaryWhere to report a cyber incident, read: the NCSC service, and that what you submit is not shared with the ICOGOV.UK, run by the NCSCaccessed 2026-10-08
  14. PrimaryCybercrime threat page, read: ransomware as the greatest cyber serious and organised crime threat, the law enforcement position on payment, Action Fraud reportingNational Crime Agencyaccessed 2026-10-08
  15. PrimaryHome page read in a browser tab on 8 October 2026: the service for England, Wales and Northern Ireland, and 101 for ScotlandReport Fraud (police)accessed 2026-10-08
  16. PrimaryGovernment response of 22 July 2025 to the ransomware legislative proposals, read: the three proposals, 273 responses, next stepsHome Officeaccessed 2026-10-08
  17. PrimaryNews story of 21 July 2025 on taking the ransomware measures forward with industry, readGOV.UKaccessed 2026-10-08
  18. PrimaryCyber Security and Resilience (Network and Information Systems) Bill, stages read from the Parliament Bills API on 8 October 2026 and the Lords text as amended in Grand Committee searched for the word ransom, which does not occurUK Parliamentaccessed 2026-10-08
  19. PrimaryCyber Extortion and Ransomware (Reporting) Bill, a private member's bill, stages read from the Parliament Bills API on 8 October 2026UK Parliamentaccessed 2026-10-08
  20. PrimaryKing's Speech 2026 background briefing notes, 13 May 2026, 129 pages, searched in full for the word ransom, which does not occurPrime Minister's Officeaccessed 2026-10-08
  21. PrimarySecurity Minister's speech of 30 September 2026, searched for ransomware: one mention, on investment in resilienceGOV.UKaccessed 2026-10-08
  22. PrimaryThe company's own questions and answers page, read on 8 October 2026, for the answer on paying ransoms. The date the wording was published is unknownMonsterCloud (the company named in the indictment)accessed 2026-10-08
  23. Reported byNews pointer of 8 October 2026 quoting the Eastern District release; figures checked against the DOJ textThe Registeraccessed 2026-10-08
  24. Reported byNews pointer; its $11M markup headline is the subtraction of two minimums and is not a DOJ figureSecurityWeekaccessed 2026-10-08
  25. Reported byNews pointer; the only source for a not guilty plea and bond, attributed there to the US Attorney's Office; also reports it asked the defence for commentBleepingComputeraccessed 2026-10-08
  26. Reported byNews pointer of 7 October 2026, read in a browser tab: republishes the Office of Public Affairs release; its own note says the release does not say whether the defendant is out on bondDataBreaches.netaccessed 2026-10-08
  27. Reported byNews pointer; figures checked against the DOJ textHelp Net Securityaccessed 2026-10-08
  28. Reported byNews pointer; quotes the company's website question and answer, which we then read directlyThe Hacker Newsaccessed 2026-10-08

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.