Skip to main content
Should You Pay the Recovery Firm After Ransomware?Incident Management
6 min readFor Compliance Managers

Should You Pay the Recovery Firm After Ransomware?

You've been hit. Files are encrypted. Operations are down. Then an email arrives from a firm claiming they can recover everything for $20,000 to $60,000, far less than the ransom demand. They've got proof: screenshots of your stolen data. They say they hacked the attackers and can delete the exfiltrated files.

Do you pay them?

This isn't a theoretical exercise. GuidePoint Security documented exactly this scenario when investigating attacks linked to DragonForce, Settra, and Anubis ransomware operations. The "recovery firm" calling itself Ransom Busters was, according to GuidePoint's moderate-confidence assessment, actually a ransomware affiliate working across multiple RaaS programs, stealing payouts from their own criminal partners.

For compliance managers, this creates a new decision point in your incident response protocol. Here's how to handle it.

The Decision You're Facing

When a third party contacts you claiming they can resolve your ransomware incident, you need to determine:

  1. Is this a legitimate recovery firm with technical capability?
  2. Is this the attacker attempting to collect payment directly?
  3. Should you engage at all, or does engagement create additional compliance exposure?

Your answer affects ISO/IEC 27001 Clause 5.24 (Information Security Incident Management) obligations, SOC 2 CC7.4 (incident response and remediation), and potentially breach notification timelines under applicable regulations.

Key Factors That Affect Your Choice

Timing of contact
If someone reaches out before the attack becomes public or before you've disclosed to law enforcement, ask how they learned about your incident. Legitimate recovery firms don't have real-time feeds of unreported ransomware attacks.

Evidence of access
The firm provides screenshots of your stolen data. This proves access, but not the source. In the GuidePoint investigation, Ransom Busters demonstrated access to the same datasets held by the ransomware affiliate because they were the affiliate.

Technical indicators from your forensic analysis
If you've already begun incident response, compare the attacker's tools and methods against any information the supposed recovery firm provides. GuidePoint found identical forensic fingerprints across intrusions: SoftPerfect Network Scanner for reconnaissance, s5cmd for exfiltration to AWS, Remotely remote-management tool, and a backdoor account with password "Numlock!123." The same attacker-controlled hostname appeared in multiple incidents.

Payment structure and guarantees
What assurance do you have that payment will result in data deletion? If the "recovery firm" is actually the affiliate, payment gives you nothing you wouldn't get from paying the original ransom, and potentially less, since there's no reputational incentive for the affiliate to honor any agreement.

Path A: Engage Law Enforcement and Forensic IR First

Choose this path when:

  • The recovery firm contacted you unprompted
  • They demonstrated access to stolen data without explaining how they obtained it
  • Contact occurred before you publicly disclosed the incident
  • Your forensic analysis hasn't yet identified the attack vector or confirmed containment

What this looks like:

You treat the recovery firm's contact as part of the attack timeline. Document the communication. Report it to law enforcement (FBI IC3, Secret Service, or your local cyber task force). Share indicators with your forensic IR team to compare against evidence from the intrusion.

Do not negotiate. Do not provide additional information about your environment. The contact itself may be an attempt to confirm that you don't have backups or that you're willing to pay.

Compliance implications:

This path aligns with ISO/IEC 27001 Clause 5.24(b), which requires you to assess information security events and classify them as incidents. An unsolicited recovery offer from a party with unexplained access to stolen data is part of the incident.

For SOC 2, this supports CC7.4's requirement to respond to identified security incidents by executing response plans. The plan should include procedures for evaluating third-party communications during active incidents.

Path B: Verify Legitimacy Through Independent Channels

Choose this path when:

  • You initiated contact with the recovery firm (not the reverse)
  • The firm has verifiable case history and public reputation
  • They can explain their methodology without requiring payment first
  • Your legal counsel has reviewed engagement terms

What this looks like:

Before any payment or detailed technical discussion, verify:

  • Business registration and physical location
  • References from other organizations (verify directly, not through contacts the firm provides)
  • Technical staff credentials and backgrounds
  • Whether they have relationships with law enforcement or CISA
  • Their position on paying ransoms (legitimate IR firms will tell you this is a business decision with legal and ethical implications, not a guaranteed solution)

Request a technical proposal that explains how they would recover data or delete exfiltrated files. Vague promises aren't enough.

Compliance implications:

ISO/IEC 27001 Clause 5.19 (Information Security in Supplier Relationships) requires you to define and agree on security requirements with suppliers. A recovery firm handling your encrypted data and stolen information is absolutely a supplier requiring security assessment.

For SOC 2, this maps to CC9.2 (vendor management and monitoring). You need the same due diligence you'd apply to any third party accessing your systems or data.

Path C: Contain, Restore, and Report Without Third-Party Recovery

Choose this path when:

  • You have tested backups that predate the encryption
  • Your forensic analysis confirms the attacker no longer has access
  • The cost and risk of engaging a third party exceeds the cost of restoration from backups
  • Legal counsel advises that payment (even to a "recovery firm") creates regulatory complications

What this looks like:

Execute your business continuity plan per ISO 22301. Restore from backups. Accept that exfiltrated data may be published (it probably will be regardless of payment). Focus your resources on notification obligations, regulatory reporting, and control improvements.

If the attacker exfiltrated regulated data (PII, PHI, financial records), you have notification obligations under GDPR, HIPAA, or state breach laws regardless of whether you pay anyone. Payment doesn't eliminate those obligations.

Compliance implications:

This is often the cleanest path from a compliance perspective. You're executing documented procedures (backup restoration, incident response, breach notification) rather than introducing new variables through third-party negotiation.

ISO/IEC 27001 Clause 5.29 (Information Security During Disruption) and Clause 5.30 (ICT Readiness for Business Continuity) support this approach, if you've actually implemented and tested the controls.

Summary Matrix

Factor Path A: Law Enforcement First Path B: Verify Legitimacy Path C: Restore Without Third Party
Recovery firm contacted you first Yes, treat as part of attack Proceed with extreme caution Not applicable
Firm has unexplained access to your data Yes, report immediately Disqualifying factor Not applicable
You have tested backups Still report, but reduces urgency Reduces need to engage Proceed with restoration
Forensic analysis complete Provides comparison data Required before engagement Required before declaring containment
Legal/regulatory exposure from payment Avoids payment complications Requires legal review Avoids payment complications
Timeline pressure Fastest path to clarity Slowest path (due diligence takes time) Speed depends on backup testing

The GuidePoint research revealed something your incident response plan probably didn't account for: the attacker might contact you twice, using different identities. Your verification process needs to assume that any unsolicited offer, no matter how helpful it sounds, could be part of the attack itself.

Update your ISO/IEC 27001 Clause 5.24 procedures to include decision criteria for evaluating third-party recovery offers. Document the questions you'll ask, the verification steps you'll take, and the authority required to authorize payment. Your next tabletop exercise should include this scenario.

Because the next time someone emails claiming they can make your ransomware problem disappear for $20,000, you need to know exactly which path you're taking, and why.

You Might Also Like