MonsterCloud owner charged with fraud over secret ransom payments

MonsterCloud owner charged with fraud over secret ransom payments

According to The Hacker News, the U.S. Department of Justice announced charges on Wednesday against Zohar Pinhasi, owner of the Florida company MonsterCloud, in a ransomware recovery fraud case. Prosecutors allege he told victims he could decrypt their data with proprietary tools, when he was actually paying the attackers for decryptors and billing clients far more than he paid. The allegations have not been tested in court.

What we know

The report, which cites the DoJ announcement, says the 50-year-old U.S. and Israeli national (also reported as Zack Silver and Zack Green) faces two counts of wire fraud and one count of wire fraud conspiracy. Each count carries a maximum of 20 years in prison if he is convicted.

The government alleges that Pinhasi urged ransomware victims not to pay, and claimed to hold “proprietary tools” and “advanced decryption techniques”. In practice, the report says, no specialised decryption tools existed. He instead contacted the cybercriminals, paid for a decryptor, and charged the client a fee “substantially higher” than the ransom.

Two examples were cited:

  • August 2023: a ransom of about $8,200 was paid to a threat actor, and the client was billed about $150,000.
  • Around October 2021: a ransom of about $236,000 was paid, and the customer was charged about $380,000.

In total, Pinhasi is accused of charging clients more than $19 million while paying more than $8 million in ransoms.

What MonsterCloud said publicly

The report notes that MonsterCloud’s website advised against paying ransoms, saying that doing so “does not guarantee a positive outcome”. Its Q&A also said the company “sometimes” resorted to “other means” to resolve incidents, with terms disclosed in the service contract. The charges allege the real practice differed from the marketing about decryption technology.

U.S. Attorney Joseph Nocella, Jr. of the Eastern District of New York said the defendant “re-victimized his clients”. FBI Assistant Director James C. Barnacle Jr. said the defendant turned the victim’s crisis into a “profit center”.

Who is affected

The sources do not say how many clients were involved, which ransomware families were behind the incidents, or whether any client data was exposed beyond the original attacks. Those details have not been disclosed. The cases named cover at least 2021 and 2023, so organisations that used a recovery firm in that period may want to review what they were told.

Why this matters

This section is our analysis, not reported fact.

Ransomware recovery is a market where customers are under extreme time pressure and cannot easily check technical claims. A vendor that says it can decrypt without paying, but actually negotiates and pays on the side, creates several risks for a typical organisation:

  • Legal and regulatory exposure, because a ransom payment may need to be reported or assessed against sanctions rules, and a hidden payment prevents that.
  • Cost, since the allegations describe markups well above the ransom itself.
  • Continued risk, because paying for a decryptor does not remove the intruder’s access. The FBI statement says the underlying threat was never remediated.

What to do

  1. Before hiring a ransomware recovery or negotiation firm, ask in writing whether they will contact or pay the attackers, and require that any payment be disclosed and approved by you.
  2. Ask for the evidence behind any claim of proprietary decryption, such as which ransomware families it covers, and have your own incident response team or counsel assess it.
  3. Check invoices against any ransom amounts disclosed to you, and keep the contract terms on file.
  4. Regardless of whether data is restored, investigate the intrusion: find the initial access, remove persistence, and reset credentials.
  5. Keep tested offline backups and an incident response retainer so you are not choosing a vendor in the middle of a crisis.
  6. If you used MonsterCloud and have concerns, speak to legal counsel and consider contacting the FBI.

We will update this article if further official details are published.

Sources

Spotted an error or outdated detail? Email contact@cyberstrikenews.com with the article link. We correct and note every change. Read our Editorial Policy.

Similar Posts