MonsterCloud owner charged with secretly paying ransoms

MonsterCloud owner charged with secretly paying ransoms

The U.S. Department of Justice announced charges on Wednesday against Zohar Pinhasi, owner of the Florida company MonsterCloud, in a case of alleged ransomware recovery fraud, according to The Hacker News. Prosecutors say he told ransomware victims he had proprietary decryption tools, when he was allegedly paying the attackers for decryptors and billing clients far more than he paid. These are allegations, and the defendant has not been convicted.

What we know

The Hacker News reports that the DoJ has charged Pinhasi, a 50-year-old U.S. and Israeli national also known as Zack Silver and Zack Green, with two counts of wire fraud and one count of wire fraud conspiracy. Each count carries a maximum of 20 years in prison if he is convicted.

According to the report, the case rests on these allegations:

  • Pinhasi told victims not to pay the ransom and said MonsterCloud had “proprietary tools” and “advanced decryption techniques”.
  • No specialised decryption tools existed. He allegedly contacted the criminals and paid them for a decryptor.
  • He then billed clients a fee described as “substantially higher” than the ransom he paid.

Two examples are cited. In August 2023 he allegedly paid about $8,200 to a threat actor and billed the client about $150,000. Around October 2021 he allegedly paid about $236,000 and charged the customer about $380,000. In total, he is accused of charging clients more than $19 million while paying more than $8 million in ransoms.

The report also notes that MonsterCloud’s website discouraged paying ransoms, while a Q&A on the site said the firm “sometimes” resorts to “other means” with ransomware perpetrators and that terms are disclosed in its service contract.

Who is affected

The affected parties are MonsterCloud’s clients, organisations hit by ransomware that hired the firm to recover their data. The number of victims and their names have not been disclosed in the report. The ransomware families and threat actors that were paid are also not disclosed.

Officials quoted in the report framed the case as a second victimisation. U.S. Attorney Joseph Nocella, Jr. said the defendant “re-victimized his clients”, and FBI Assistant Director James C. Barnacle Jr. said he “turned the victim’s crisis into his own profit center”.

What has not been confirmed

  • The charges are allegations. The outcome of any trial is not known, and the report does not include a response from the defendant.
  • The report does not say how many clients paid ransoms through MonsterCloud or whether any were refunded.
  • It does not identify the criminal groups that received payments, or say whether the payments were checked against sanctions lists.
  • This article relies on a single outlet’s account of the DoJ announcement. We have not seen the charging documents.

Why this matters

Analysis, not new facts. Ransomware victims are under time pressure and often cannot judge a recovery vendor’s claims. A vendor that says it can decrypt without payment, but is in fact paying, leaves the customer with an inflated bill and little visibility into who received the money. A third-party payment may also carry legal and regulatory obligations that the customer never got to consider. Treat this as a vendor-risk and governance issue as much as a security one.

How to vet a ransomware recovery vendor

These are general good-practice suggestions that follow from the allegations, not guidance from the DoJ:

  1. Ask in writing whether the vendor will ever negotiate with or pay attackers, and require that any such payment needs your explicit prior approval.
  2. Require an itemised invoice that separates the vendor’s fees from any ransom paid, with proof of payment.
  3. Ask how decryption will be done. A claim of a proprietary tool should be testable on a sample of your files before you commit.
  4. Check whether free decryptors exist for the strain you face, for example through public decryptor repositories, before paying anyone.
  5. Involve legal counsel, your cyber insurer and law enforcement early, so any payment decision is made by you with full information.

What to do

  1. If your organisation used MonsterCloud for a ransomware incident, ask for the vendor’s records of what was paid, to whom and when, and talk to counsel about reporting to the FBI.
  2. Add ransomware recovery vendors to your third-party risk register, with contract clauses on payment disclosure and audit rights.
  3. Pre-approve an incident response retainer with a vetted firm now, so you are not choosing a vendor in the middle of an outage.
  4. Rehearse a ransomware decision process covering who can authorise a payment, and who must be told. Keep offline, tested backups, which are the most reliable way to avoid needing a decryptor at all.

Sources

Spotted an error or outdated detail? Email contact@cyberstrikenews.com with the article link. We correct and note every change. Read our Editorial Policy.

Similar Posts