The owner of a US ransomware remediation company allegedly promised businesses he could recover their files without paying cybercriminals. Prosecutors say he secretly paid the hackers instead — and charged victims substantially more.
Imagine your company has just been hacked with ransomware. You hire a cybersecurity firm that says it can recover your files without giving anything to the criminals. But behind the scenes, the company does exactly what it told you not to do: pays the hackers, gets the decryption key and sends you a much bigger bill.
US prosecutors say that is essentially how a Florida-based ransomware remediation business operated for years.
Key takeaways
The owner of ransomware remediation company MonsterCloud has been charged with wire fraud over an alleged scheme targeting ransomware victims
Prosecutors say the company claimed to use proprietary technology to decrypt files without paying attackers
Instead, MonsterCloud allegedly secretly paid ransomware operators for decryption keys and charged clients substantially more
In one case, prosecutors say the company paid hackers about $8,200 but billed the victim $150,000
MonsterCloud allegedly collected more than $19 million from clients while facilitating more than $8 million in ransom payments
Promising an alternative to paying hackers
Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” was arraigned Oct. 7 in federal court in Brooklyn on two counts of wire fraud and one count of wire fraud conspiracy.
Pinhasi owned and operated MonsterCloud LLC, a Florida ransomware remediation company that marketed itself to businesses hit by cyberattacks.
According to the US Department of Justice, MonsterCloud presented itself as an alternative to paying ransomware operators. Its website warned victims against paying ransoms and claimed the company could recover data using “advanced decryption techniques” and other technology.
Prosecutors say those capabilities didn't exist.
Instead, Pinhasi allegedly contacted the very cybercriminals who had attacked his clients, paid them for decryption keys, then used them in an attempt to restore the encrypted files.
The alleged scheme ran from June 2018 through June 2023 and affected hundreds of companies in the United States and Canada, according to reporting on the indictment.
An $8,200 ransom became a $150,000 bill
The difference between what MonsterCloud allegedly paid attackers and what it charged victims could be enormous.
In one example cited by prosecutors, MonsterCloud paid a ransomware operator approximately $8,200 in August 2023. The affected customer was allegedly charged approximately $150,000.
Another incident reportedly involved a ransom payment of roughly $236,000 and a bill of about $380,000 to the customer.
Overall, prosecutors allege Pinhasi and his company charged clients more than $19 million while paying more than $8 million in ransoms.
The allegations go beyond simply acting as a middleman.
According to prosecutors, MonsterCloud also displayed customer “testimonials,” some involving paid spokespersons. In 2019, one spokesperson reportedly asked Pinhasi directly whether the company actually hadproprietary ransomware-decryption software.
According to the indictment, Pinhasi acknowledged that it did not.
Paying a ransom isn't the same as ransomware remediation
Getting a decryption key can be part of recovery after an attack, but it doesn't mean the underlying security problem has been fixed.
Proper incident response involves understanding how attackers entered the network, determining what systems and accounts were compromised, containing the intrusion, removing malicious access, assessing whether data was stolen, restoring systems safely and closing the security gaps that allowed the attack to happen.
Simply obtaining a decryptor does not accomplish all of that.
The FBI says it doesn’t support paying ransomware demands because it offers no guarantee that victims will recover their data, and it can encourage further attacks. Even when a ransom is paid, organizations are urged to report the incident to law enforcement.
Before an incident happens, organizations should identify reputable incident-response providers and establish a response plan rather than searching for emergency help for the first time in the middle of a crisis.
Pinhasi has been charged, but not yet convicted. He is presumed innocent unless proven guilty. If convicted, he faces up to 20 years behind bars.