What to Ask Before Hiring a Ransomware Recovery Company
What should you ask before hiring a ransomware recovery company?
Ask five things before you sign: whether they will pay the attackers on your behalf, how exactly they get your files back, what the fee is based on, whether they will put that in writing, and who reports the attack to the FBI. A legitimate ransomware recovery company answers all five plainly. One that talks about secret “proprietary decryption” and will not explain it is a warning sign.
This question got a lot more urgent this week. On October 7, 2026, the U.S. Department of Justice announced charges against the owner of MonsterCloud, a Florida ransomware remediation company. The case is a useful lesson for any business owner, because the alleged scheme only worked on people who were in a panic and did not know which questions to ask.
What happened with MonsterCloud?
According to the indictment, filed in federal court in Brooklyn, MonsterCloud’s owner Zohar Pinhasi told clients the company could recover encrypted data without paying the ransom, using what its website described as “proprietary tools” and “advanced decryption techniques.” Prosecutors allege that in reality the company contacted the attackers, paid them for the decryption keys, and used those keys to restore the files.
The DOJ says clients were charged more than $19 million between 2018 and 2023, while more than $8 million went to the ransomware gangs. In one example from August 2023, prosecutors allege about $8,200 was paid to the attacker and the client was billed about $150,000. Pinhasi faces two counts of wire fraud and one count of wire fraud conspiracy, and pleaded not guilty. These are allegations: an indictment is not a conviction, and he is presumed innocent unless proven guilty in court.
Whatever the outcome of the case, it shows a pattern that has come up before. A 2019 ProPublica investigation reported that recovery firms promising technical fixes, MonsterCloud among them, were often quietly paying the ransom and marking up the cost. MonsterCloud disputed that at the time, describing its methods as trade secrets. If you are ever in that position, the questions below are how you tell the difference.
Is it legal to pay a ransomware demand?
Usually, yes, but not always, and that is exactly why you need to know whether your recovery company is paying. The U.S. Treasury’s Office of Foreign Assets Control warns that paying a ransom to a sanctioned group can violate federal sanctions law, and that the business on whose behalf the payment is made can be liable, not just the company that sends the money. Some ransomware groups are on sanctions lists.
A payment made in your name, without your knowledge, can therefore become your problem. It also matters to your cyber insurance, which usually has its own rules about ransom payments and approved vendors, and to your lawyer, if the attack exposed customer or patient data.
The five questions to ask, and what good answers sound like
- “Will you pay the attackers, or negotiate with them, on our behalf?” A good answer is a straight yes or no. Some reputable firms do negotiate and pay when there is no other option, openly, with your written approval and a sanctions check first. The red flag is a firm that says it never pays but cannot say how it recovers the data.
- “How exactly will you get our files back?” Honest answers are things like: restoring from your backups, using a free public decryptor for that specific ransomware strain, or a negotiated payment. Free decryptors for many strains are published by law enforcement and security companies through No More Ransom. “We have our own technology we cannot discuss” is not an answer.
- “What is your fee, and is any ransom passed through separately?” The ransom and the firm’s fee should be shown as separate lines. If you are quoted one lump sum, ask what portion goes to the attacker.
- “Will you put the method in the contract?” Whatever they told you on the phone should appear in the engagement letter, including whether a payment will be made and who approves it.
- “Who reports this to the FBI, and when?” A legitimate firm will encourage you to report the attack at ic3.gov and will work with law enforcement. A firm that discourages reporting is protecting itself, not you.
Also call your cyber insurance carrier before you hire anyone. Many policies require you to use an approved incident response firm, and hiring someone else first can put your claim at risk.
Should you pay the ransom at all?
The FBI and CISA advise against paying, because payment funds the next attack and does not guarantee you get your data back or that the stolen copy is deleted. Most attacks now steal data as well as encrypting it, so a decryption key only solves half the problem.
In practice, the businesses that do not have to make this decision are the ones whose backups worked. If you can wipe the affected machines and restore from a clean, recent backup, the attacker’s leverage drops to the stolen data alone. That is the whole argument for testing your backups before you need them, not the day after.
How do you avoid needing a ransomware recovery company?
You cannot rule out an attack, but you can make it something you recover from in days rather than a negotiation. For a small business, that comes down to a short list:
- Backups that attackers cannot reach. At least one copy offline or immutable, and a cloud backup that is tested by actually restoring from it, on a schedule.
- Multi-factor authentication on email, remote access and anything else reachable from the internet. Stolen passwords and exposed remote desktop are still how most attacks begin.
- Supported, patched systems. Unpatched PCs are an open door; this month that means anything still on Windows 11 24H2 after October 14.
- A written plan that says who to call first: your IT provider, your insurer, your lawyer. It should name a recovery firm you have already vetted with the questions above, so nobody is choosing one in a panic.
We wrote about how ransomware has actually played out locally in Florida’s city ransomware attacks, and about what small businesses should prioritize in cybersecurity for small businesses.
Want a Second Opinion Before Something Happens?
iTech Plus provides cybersecurity, ransomware recovery and managed IT for small businesses and medical practices across Polk and Osceola counties, including Lakeland, Winter Haven, Davenport and Kissimmee. If you want to know whether your backups would actually get you through a ransomware attack, we offer a free IT assessment with a written report. Call (321) 221-7117 or email info@itechplus.co.







