Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Fake Ransomware Recovery Firm Charged Over $11M Decryption Markup

6

 

The owner of a US cybersecurity company has been charged with running a ransomware recovery fraud that allegedly involved secretly paying attackers for decryption keys and then charging victims a large markup. Zohar Pinhasi, 50, owner of MonsterCloud and also known as “Zack Silver” and “Zack Green,” appeared in a New York court on wire fraud charges. Prosecutors say his company claimed it could recover encrypted data without paying ransom, while it actually relied on ransom payments obtained from the same criminal groups.

According to the indictment, Pinhasi marketed MonsterCloud as a ransomware remediation service that used proprietary tools and advanced decryption techniques. He reportedly warned victims not to pay ransomware operators directly, positioning his firm as a safer alternative. In reality, investigators allege that he contacted the ransomware groups responsible for the attacks, paid them for decryption keys, and then used those keys to restore clients’ files while charging them for supposedly independent recovery work.

The alleged financial gap was substantial. Pinhasi is accused of paying more than $8 million in ransoms while billing clients over $19 million, creating an estimated $11 million markup. In one example, he allegedly paid a ransomware affiliate about $8,200 for a decryption key and then charged the affected client approximately $150,000. Prosecutors say the scheme effectively caused victims to pay twice—first through inflated recovery fees and indirectly through the ransom payments made on their behalf.

The case highlights a serious trust problem in the ransomware incident-response market. Organizations under pressure to restore operations may accept claims of “guaranteed decryption” without verifying the technical basis for those claims. Genuine recovery can sometimes be possible through free decryptors, backups, or known flaws in ransomware strains, but no legitimate provider can promise recovery for every attack. Businesses should therefore ask providers for transparent methods, written scopes of work, references, and clear pricing before signing emergency contracts.

Pinhasi has been charged with wire fraud and wire fraud conspiracy and could face decades in prison if convicted. The allegations remain accusations until proven in court, but the case is a warning to ransomware victims: recovery services should be scrutinized as carefully as the original cyberattack. Independent legal counsel, cyber insurance guidance, law-enforcement reporting, and verified incident-response specialists can help organizations avoid becoming victims a second time 


Share it:

Cyber Crime Wire Fraud

Decryption Tools

Ransomware