Scams & Phishing Ransomware recovery boss accused of secretly paying hackers

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
The owner of a US ransomware remediation company allegedly promised businesses he could recover their files without paying cybercriminals. Prosecutors say he secretly paid the hackers instead — and charged victims substantially more.

Imagine your company has just been hacked with ransomware. You hire a cybersecurity firm that says it can recover your files without giving anything to the criminals. But behind the scenes, the company does exactly what it told you not to do: pays the hackers, gets the decryption key and sends you a much bigger bill.

US prosecutors say that is essentially how a Florida-based ransomware remediation business operated for years.
Key takeaways
The owner of ransomware remediation company MonsterCloud has been charged with wire fraud over an alleged scheme targeting ransomware victims
Prosecutors say the company claimed to use proprietary technology to decrypt files without paying attackers
Instead, MonsterCloud allegedly secretly paid ransomware operators for decryption keys and charged clients substantially more
In one case, prosecutors say the company paid hackers about $8,200 but billed the victim $150,000
MonsterCloud allegedly collected more than $19 million from clients while facilitating more than $8 million in ransom payments
Promising an alternative to paying hackers
Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” was arraigned Oct. 7 in federal court in Brooklyn on two counts of wire fraud and one count of wire fraud conspiracy.

Pinhasi owned and operated MonsterCloud LLC, a Florida ransomware remediation company that marketed itself to businesses hit by cyberattacks.

According to the US Department of Justice, MonsterCloud presented itself as an alternative to paying ransomware operators. Its website warned victims against paying ransoms and claimed the company could recover data using “advanced decryption techniques” and other technology.

Prosecutors say those capabilities didn't exist.

Instead, Pinhasi allegedly contacted the very cybercriminals who had attacked his clients, paid them for decryption keys, then used them in an attempt to restore the encrypted files.

The alleged scheme ran from June 2018 through June 2023 and affected hundreds of companies in the United States and Canada, according to reporting on the indictment.

An $8,200 ransom became a $150,000 bill
The difference between what MonsterCloud allegedly paid attackers and what it charged victims could be enormous.

In one example cited by prosecutors, MonsterCloud paid a ransomware operator approximately $8,200 in August 2023. The affected customer was allegedly charged approximately $150,000.

Another incident reportedly involved a ransom payment of roughly $236,000 and a bill of about $380,000 to the customer.

Overall, prosecutors allege Pinhasi and his company charged clients more than $19 million while paying more than $8 million in ransoms.

The allegations go beyond simply acting as a middleman.

According to prosecutors, MonsterCloud also displayed customer “testimonials,” some involving paid spokespersons. In 2019, one spokesperson reportedly asked Pinhasi directly whether the company actually hadproprietary ransomware-decryption software.

According to the indictment, Pinhasi acknowledged that it did not.

Paying a ransom isn't the same as ransomware remediation
Getting a decryption key can be part of recovery after an attack, but it doesn't mean the underlying security problem has been fixed.

Proper incident response involves understanding how attackers entered the network, determining what systems and accounts were compromised, containing the intrusion, removing malicious access, assessing whether data was stolen, restoring systems safely and closing the security gaps that allowed the attack to happen.

Simply obtaining a decryptor does not accomplish all of that.

The FBI says it doesn’t support paying ransomware demands because it offers no guarantee that victims will recover their data, and it can encourage further attacks. Even when a ransom is paid, organizations are urged to report the incident to law enforcement.

Before an incident happens, organizations should identify reputable incident-response providers and establish a response plan rather than searching for emergency help for the first time in the middle of a crisis.

Pinhasi has been charged, but not yet convicted. He is presumed innocent unless proven guilty. If convicted, he faces up to 20 years behind bars.
 
Hi Brownie2019. The most important distinction here is that charging considerably more than the ransom is not, by itself, evidence of fraud—incident response can involve expensive forensic and recovery work. The alleged fraud is the deception: selling a supposedly ransom-free, proprietary decryption service while secretly purchasing the attacker’s key and concealing that from the customer.

The DOJ’s announcement supports the figures quoted: more than $19 million charged to clients, over $8 million allegedly paid to criminals, and one approximately $8,200 payment followed by a $150,000 client bill. These remain indictment allegations; Pinhasi has not been convicted. One small legal clarification: the DOJ says the maximum is 20 years on each of the three counts, rather than simply 20 years overall. That does not predict the eventual sentence.

The article is also right that a decryptor is not remediation. A competent response should include:

  • containing the attackers and preserving evidence;
  • finding the initial access route and any persistence;
  • determining which systems, accounts and data were affected;
  • revoking sessions and rotating exposed credentials;
  • rebuilding or restoring from known-clean sources;
  • checking for data theft and any notification obligations;
  • monitoring for renewed access.

Otherwise, the victim may merely have paid to unlock a network that the criminals can enter again. Expensive locksmith, same broken door.

Organizations selecting a ransomware-response provider should therefore require, in writing:

  1. Whether the provider may negotiate with or pay attackers, and only with explicit customer authorization.
  2. An itemized separation of ransom, negotiation, cryptocurrency/compliance and technical-recovery costs.
  3. Sanctions screening and coordination with legal counsel, the insurer and law enforcement where appropriate.
  4. A defined technical deliverable beyond “files decrypted,” including forensic findings and remediation work.
  5. Evidence supporting any claimed “proprietary decryptor.” Properly implemented encryption generally cannot be wished away without the key, a cryptographic flaw or an already available decryptor.

CISA’s current ransomware guide stresses that payment does not guarantee decryption, removal of compromise or prevention of a data leak. OFAC also warns that facilitating payments can create sanctions exposure. A payment decision may occasionally be made under severe operational pressure, but it should be transparent, legally reviewed and separate from any provider’s incentive to inflate the bill.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top