Ransomware recovery CEO charged over secret ransom payments

A Ransomware Recovery CEO’s Dirty Secret: Charging Victims Twice, Paying Attackers

In a stunning case of alleged deceit, Zohar Pinhasi, 50, owner of Florida-based ransomware remediation company MonsterCloud, has been charged with conspiracy to commit wire fraud and two counts of wire fraud. Prosecutors claim that instead of using proprietary technology to recover encrypted data, Pinhasi secretly paid ransomware attackers for decryption keys while charging his customers exorbitant fees.

According to the indictment, Pinhasi’s scheme ran from June 2018 to June 2023, during which time he and his co-conspirators allegedly facilitated more than $8 million in ransom payments. MonsterCloud charged its clients an average of $150,000 per recovery incident, despite paying only around $8,200 in ransomware demands. The indictment also reveals that the company used decrypted sample files as “recovery proofs” to convince victims they could restore their data.

This is not the first time concerns have been raised about MonsterCloud’s practices. A 2019 ProPublica investigation uncovered similar allegations of paying ransomware operators while claiming to offer a solution other than paying attackers. Researchers created fake ransomware and posed as victims, only to see recovery companies like MonsterCloud contact them with offers to pay the ransom. These incidents raise serious questions about the ethics and honesty of some ransomware remediation firms.

Ransomware attacks have become increasingly common in recent years, with attackers demanding hundreds of thousands of dollars from victims in exchange for decryption keys. While paying the ransom may seem like a straightforward solution, it’s essential to understand that this often enables further attacks and emboldens cybercriminals. In Pinhasi’s case, prosecutors claim he and his co-conspirators took advantage of desperate victims by charging them inflated fees while secretly cutting deals with attackers.

As cybersecurity experts continue to grapple with the complexities of ransomware recovery, this case serves as a stark reminder that some companies may prioritize profits over principles. If convicted, Pinhasi faces up to 20 years in prison for his alleged crimes.

So what can you do if your business falls victim to a ransomware attack? First and foremost, don’t pay the ransom without thoroughly researching the recovery options available to you. Be cautious of companies that claim they can recover encrypted data without disclosing their methods or communicating directly with attackers. Always review contracts carefully, looking for clauses that may indicate the company plans to contact or pay attackers on your behalf. By being informed and vigilant, you can minimize the risk of falling prey to deceitful recovery firms like MonsterCloud.


Source: Bleeping Computer — 2026-10-07