U.S. prosecutors charged MonsterCloud owner Zohar Pinhasi with allegedly defrauding ransomware victims by claiming his company recovered encrypted files using proprietary technology without paying attackers. According to the indictment, the Florida company instead secretly purchased decryptors from ransomware operators between June 2018 and June 2023, using clients’ fees to fund ransom payments while retaining substantial markups. Prosecutors allege MonsterCloud charged hundreds of businesses in the United States and Canada more than $19 million for recovery and remediation services and facilitated more than $8 million in ransom payments.
In one alleged instance, MonsterCloud charged a client $150,000 to resolve an $8,200 ransom demand. Pinhasi faces two counts of wire fraud and one count of wire fraud conspiracy, each carrying a potential 20-year prison sentence if convicted. He pleaded not guilty and was released on a $2 million bond. The FBI is investigating, and the indictment alleges participation by employees, contractors and other co-conspirators. A 2019 ProPublica investigation previously raised similar concerns, which Pinhasi disputed. Organizations hiring ransomware recovery providers should require explicit disclosure of any attacker negotiations or payments and independently verify claims of proprietary decryption capabilities.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
According to the U.S. Attorney's Office, Pinhasi surrendered on Wednesday and was arraigned in federal court in Brooklyn. He pleaded not guilty and was released on a $2 million bond.
A federal grand jury in the Eastern District of New York indicted Pinhasi on September 23 on one count of conspiracy to commit wire fraud and two counts of wire fraud. The charges concern alleged deception of ransomware victims seeking MonsterCloud's recovery services.
In an August 2023 case, Pinhasi allegedly paid approximately $8,200 to a ransomware threat actor and billed the MonsterCloud client approximately $150,000.
In May 2019, a paid MonsterCloud spokesperson questioned Pinhasi about the company's business practices and decryption software. According to the indictment, Pinhasi acknowledged that MonsterCloud did not possess proprietary technology to decrypt ransomware-encrypted data.
A 2019 ProPublica investigation reported that MonsterCloud sometimes paid ransomware operators while presenting itself as an alternative to paying attackers. Researchers posing as victims traced ransom-payment offers to recovery firms, including MonsterCloud, using attacker email addresses they controlled.
Prosecutors allege that from June 2018 through June 2023, Zohar Pinhasi and co-conspirators secretly bought ransomware decryptors while claiming to use proprietary recovery technology. The alleged scheme collected more than $19 million from hundreds of U.S. and Canadian companies and facilitated more than $8 million in ransom payments.
Pinhasi denied misleading customers and disputed that MonsterCloud had promised decryption in advance. He described the company's case-dependent recovery methods as a trade secret.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
7 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcejustice.gov
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.