What happened
U.S. authorities allege that MonsterCloud’s chief executive covertly paid multiple ransomware gangs to obtain decryption keys for compromised customer data, then billed victims inflated amounts, effectively defrauding them. The payments and overcharges were not disclosed to the company’s board or customers.
Why it matters for trust and compliance
- This incident spotlights the control objective of vendor oversight and incident‑response documentation, showing why continuous monitoring and auditable evidence of ransomware negotiations are essential for a defensible trust posture.
- Strengthen third‑party risk policies to require real‑time incident reporting and independent verification of ransom payments.
- Collect and retain logs, payment records, and communication artifacts to provide audit‑ready evidence of ransomware response.
Who is affected
Technology SaaS providers Managed‑service and cloud‑security vendors
Recommended actions
- Audit existing vendor contracts for mandatory incident‑response disclosure clauses.
- Implement continuous monitoring of vendor security events and require evidence of any ransom negotiations.