MonsterCloud CEO charged over secret ransom payments to attackers

MonsterCloud CEO charged over secret ransom payments to attackers

The owner of ransomware remediation firm MonsterCloud has been charged in the United States with fraud, according to BleepingComputer. Prosecutors allege he secretly paid ransomware operators for decryption keys while telling victims the company recovered data with its own proprietary technology. The charges are allegations; the defendant has pleaded not guilty.

What we know about the ransomware recovery fraud case

  • Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” was indicted by a federal grand jury in the Eastern District of New York on September 23.
  • He was arraigned on Wednesday in federal court in Brooklyn, surrendered, pleaded not guilty and was released on a $2 million bond, the U.S. Attorney’s Office told BleepingComputer.
  • He faces one count of conspiracy to commit wire fraud and two counts of wire fraud. If convicted, he faces up to 20 years in prison.
  • The alleged scheme ran from June 2018 to June 2023.

According to the indictment, Pinhasi owned and operated MonsterCloud LLC, a Florida-based company that advertised tools and decryption techniques for recovering encrypted data without paying cybercriminals.

What prosecutors allege

Prosecutors say MonsterCloud had no such proprietary decryption technology. Instead, they allege, Pinhasi and co-conspirators contacted ransomware operators, paid for decryption keys and used those keys to restore customers’ files.

The indictment also alleges the company used decrypted sample files as “recovery proofs” to convince victims it could restore their data, even though the samples came from the ransomware operations themselves.

Some MonsterCloud contracts did disclose that the company might communicate with or pay cybercriminals. Those contracts allegedly said it would do so only if it could not decrypt files by other means. Prosecutors claim that dealing with the attackers was usually the first step, not the last.

How much money was involved

  • Prosecutors say Pinhasi and co-conspirators facilitated more than $8 million in ransom payments.
  • They say hundreds of companies in the United States and Canada were charged more than $19 million for recovery and remediation services.
  • In one cited incident, he allegedly paid a ransomware gang about $8,200 and charged the victim approximately $150,000.
  • In another, he allegedly paid approximately $236,000 and charged the customer about $380,000.

Who is affected

The indictment cites hundreds of customer companies in the US and Canada. Victim names have not been disclosed in the source reporting. BleepingComputer contacted Pinhasi’s attorneys, Christopher Clark and Rodney Villazor, for comment and said it will update its story if they respond.

Why this matters

Analysis, not new reporting. A ransomware victim under pressure is poorly placed to check a vendor’s claims. If the allegations are accurate, the cost of the recovery went up, the real method was hidden, and money reached the criminals the customer was trying to avoid funding. That raises legal and sanctions questions that a customer would want to understand before paying anyone, directly or through an intermediary. The facts available here do not say whether any customer faced such consequences.

What to do

  1. Ask any recovery or negotiation vendor in writing whether it will contact or pay the attackers, and under what conditions, before you sign.
  2. Require disclosure of any payment made on your behalf, with the amount, the recipient and the proof of what was bought, so that fees can be compared with the ransom.
  3. Treat sample decryptions as weak evidence. The indictment alleges such samples came from the attackers themselves.
  4. Involve legal counsel and your cyber insurer early, since payments to criminals carry legal and compliance implications.
  5. If you used MonsterCloud between June 2018 and June 2023, review your contracts and invoices, and consider speaking with counsel about whether to contact the U.S. Attorney’s Office.
  6. Reduce the need for any of this: test offline, immutable backups and rehearse restoration so recovery does not depend on a third party’s claims.

Sources

Spotted an error or outdated detail? Email contact@cyberstrikenews.com with the article link. We correct and note every change. Read our Editorial Policy.

Similar Posts