Ransomware recovery CEO charged over secret ransom payments

Ransomware Recovery Firm’s CEO Charged with Secretly Paying Ransom Demands

A shocking indictment has been handed down against Zohar Pinhasi, the CEO of MonsterCloud, a company that claims to specialize in ransomware recovery. The charges allege that Pinhasi and his team were secretly paying ransom demands on behalf of their clients while misrepresenting their own decryption methods as proprietary technology.

According to the indictment, Pinhasi’s scheme ran from 2018 to 2023, during which time MonsterCloud allegedly collected over $19 million in recovery and remediation services from hundreds of companies across the US and Canada. Meanwhile, Pinhasi and his co-conspirators paid out more than $8 million in ransom demands, pocketing the difference as profit.

But here’s the kicker: prosecutors claim that Pinhasi’s team had no actual decryption technology to speak of. Instead, they would contact the very same ransomware operators who had extorted their clients, pay them for decryption keys, and then use those keys to restore the encrypted files. This practice is essentially a form of extortion, where MonsterCloud acts as a middleman between the attackers and their victims.

The indictment highlights several instances where Pinhasi’s company charged clients far more than they actually paid in ransom demands. For example, in one case, MonsterCloud allegedly paid $8,200 to a ransomware gang but charged its client $150,000 for recovery services. In another instance, the company paid out approximately $236,000 and billed its client around $380,000.

The use of “recovery proofs” – decrypted sample files used to convince clients that their data could be restored – is also called into question. Prosecutors allege that these samples were actually obtained from the ransomware operations themselves, rather than being recovered using any actual decryption technology.

As ProPublica reported in 2019, security researchers had previously raised concerns about MonsterCloud’s business practices. Researchers created a fake ransomware attack and approached several recovery companies, including MonsterCloud, with notes containing email addresses controlled by the researchers. They soon found that these addresses began receiving anonymous messages offering to pay the ransom – directly from the data recovery firms.

If convicted, Pinhasi faces up to 20 years in prison. While this case highlights a clear case of financial exploitation, it also serves as a warning to companies and individuals seeking ransomware recovery services: be cautious of firms that promise unrealistic or proprietary solutions to your decryption woes. Always research a company thoroughly before entrusting them with sensitive data and financial information.

As you navigate the complex world of cybersecurity, remember that not all heroes wear white hats – some may just be profiting from your misfortune. Be vigilant, do your due diligence, and never be afraid to question a firm’s claims or practices.


Source: Bleeping Computer — 2026-10-07