
Zohar Pinhasi, 50, owner of the Florida ransomware remediation company MonsterCloud, has been charged with defrauding ransomware victims. A federal grand jury in the Eastern District of New York indicted him on September 23 on one count of conspiracy to commit wire fraud and two counts of wire fraud, and he was arraigned Wednesday in Brooklyn, according to BleepingComputer. He pleaded not guilty and was released on a $2 million bond; he faces up to 20 years in prison if convicted.
Prosecutors allege that from June 2018 to June 2023 MonsterCloud advertised proprietary tools and techniques for recovering encrypted files without paying criminals, when in practice it contacted the ransomware operators, bought decryption keys, and used them to restore customers’ data. The indictment acknowledges that some contracts said the company might communicate with or pay cybercriminals, but says those contracts described it as a last resort when it was usually the first step. Prosecutors say it also showed victims decrypted sample files as “recovery proofs” that actually came from the attackers. In one cited case the company allegedly paid a gang about $8,200 and charged the victim about $150,000; in another it paid about $236,000 and charged about $380,000. Overall, prosecutors say the scheme facilitated more than $8 million in ransom payments while billing hundreds of US and Canadian companies more than $19 million. The charges are allegations, and BleepingComputer says it asked Pinhasi’s attorneys for comment.
BleepingComputer notes a 2019 ProPublica investigation raised similar concerns about MonsterCloud and other recovery firms paying attackers while implying another method. The case is a useful reminder for anyone hiring an incident-response or recovery firm: ask in writing whether ransom payments or contact with the attackers are part of the service, and who pays and who receives any decryption keys.
