A former employee of the company DigitalMint is under criminal investigation by the US Department of Justice, as he allegedly collaborated with ransomware gangs for personal financial gain (taking percentages from ransom payments).

DigitalMint, a Chicago-based company that specializes in negotiation cryptocurrency payment, confirmed that a former employee of the company is under investigation by authorities. According to Bloomberg, the suspect allegedly brokered ransom payments to cybercriminals, taking a cut of the ransom money paid by customers.
DigitalMint told BleepingComputer that it immediately terminated the employee upon becoming aware of the suspicious activity and that the company itself is not a target of the investigation.
"We acted immediately to protect our customers and are working with the relevant authorities," said DigitalMint CEO Jonathan Solomon.
See also: Aeza Group punished for hosting ransomware
The case has sparked a backlash in the cybersecurity industry, with law firms and insurance companies warning their clients to avoid working with DigitalMint while the case is under investigation.
The Justice Department and the FBI declined to comment on the developments, while DigitalMint did not disclose whether the suspect has already been arrested, citing the confidentiality of the ongoing investigation.
DigitalMint says it has handled over 2,000 ransomware incidents since 2017, making the case even more critical to the reputation of the recovery data services sector .
Ethical dilemmas and hidden agreements in ransomware negotiations
A revealing report by ProPublicain 2019 had brought to light the shady practices of some data recovery companies in the US, which secretly paid ransomware gangs while charging customers for data recovery services, without disclosing that payments were made to the attackers.
Ransom payments at that time were considered relatively low, ranging from a few thousand to a few hundred thousand dollars — small amounts compared to the millions demanded by modern ransomware gangs from large businesses.
In fact, criminal networks like GandCrab and REvil had gone so far as to offer special discounts and privileged chat interfaces for cooperating trading companies, creating a semi-official “channel” between criminals and intermediaries.
See also: Swiss government data stolen via ransomware

Bill Siegel, CEO of trading firm Coveware, warns that business models that don't use a flat fee structure lend themselves to this kind of potential abuse.
Siegel emphasizes that paying a ransom is often the worst decision a company can make — although it's often difficult to convey that message to an organization facing a critical situation due to a cyberattack.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The phenomenon highlights a deeper crisis of credibility and ethics in the cyberattack response: Who is truly protecting the organization — and who is simply carrying out its “takeover”?
See also: Most Ransomware attacks on organizations are the result of vulnerabilities
Ransomware protection
To avoid paying a ransom (and possibly being scammed by the trading companies), one must take steps to protect themselves from ransomware attacks:
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
Source: www.bleepingcomputer.com
