MonsterCloud CEO charged over secret ransom payments

MonsterCloud CEO charged over secret ransom payments

The owner of ransomware recovery firm MonsterCloud has been charged in the US with defrauding victims. Prosecutors say he secretly paid attackers for decryption keys while telling customers their data was being recovered with the company's own technology.

Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted on September 23 by a federal grand jury in the Eastern District of New York. A grand jury is the panel of citizens that decides whether federal prosecutors have enough evidence to bring charges. Pinhasi was arraigned on Wednesday in federal court in Brooklyn.

He faces one count of conspiracy to commit wire fraud and two counts of wire fraud. Prosecutors say the alleged scheme ran from June 2018 to June 2023. The U.S. Attorney's Office told BleepingComputer that Pinhasi surrendered on Wednesday, pleaded not guilty, and was released on a $2 million bond. If convicted, he faces up to 20 years in prison.

BleepingComputer has asked Pinhasi's attorneys, Christopher Clark and Rodney Villazor, for comment.

Paying the attackers came first

According to the indictment, Pinhasi owned and ran MonsterCloud LLC, a Florida company that advertised tools and decryption techniques for restoring encrypted data without paying cybercriminals.

Prosecutors allege that the company had no such proprietary technology. Instead, Pinhasi and his co-conspirators allegedly reached out to ransomware operators, bought decryption keys from them, and used those keys to restore customers' files.

The indictment notes that some MonsterCloud contracts did mention that the company might talk to or pay cybercriminals. However, those contracts allegedly described this as a fallback, used only if the files could not be decrypted any other way. Prosecutors claim that in practice, negotiating with the attackers was usually the first step.

The company also allegedly showed victims decrypted sample files as "recovery proofs" to convince them their data could be restored. Prosecutors say those samples actually came from the ransomware operators themselves.

"As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," said U.S. Attorney Joseph Nocella Jr.

"Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity," he added.

Large markups on ransom payments

Prosecutors say MonsterCloud charged customers far more than it paid out in ransoms. In one case cited in the indictment, Pinhasi allegedly paid a ransomware gang about $8,200 and billed the victim roughly $150,000. In another, he allegedly paid around $236,000 and charged the customer about $380,000.

Over the full period, Pinhasi and his co-conspirators allegedly facilitated more than $8 million in ransom payments. At the same time, they charged hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services.

Concerns first raised in 2019

The allegations are not entirely new. A 2019 ProPublica investigation reported similar concerns about MonsterCloud, including claims that the company sometimes paid ransomware operators while saying it offered an alternative to paying.

For that report, security researcher Fabian Wosar told ProPublica that he and another researcher built their own ransomware and approached several recovery companies while posing as victims. They handed over ransom notes listing email addresses they controlled for the fake gang.

According to ProPublica, those inboxes soon received anonymous messages offering to pay the ransom. Wosar traced the requests to data recovery firms, including MonsterCloud and Proven Data. ProPublica reported that MonsterCloud had claimed it could recover the files without telling the supposed victim that it planned to pay the attacker.

At the time, Pinhasi disputed that MonsterCloud had promised in advance it could decrypt the files and denied misleading customers. He said the company's methods varied from case to case and declined to share them, calling them a "trade secret."

Why It Matters

The charges are allegations, and Pinhasi has pleaded not guilty. Still, the case points to a weak spot in the ransomware ecosystem. Victims under pressure often hand the problem to a third party without knowing how their data is actually being recovered or where their money ends up.

For organizations, this suggests that recovery contracts deserve the same scrutiny as any other security vendor agreement. It is worth asking directly whether a provider will pay the attackers and how much of the fee goes to the ransom.

The case also fits a broader pattern of US and international authorities widening their focus beyond the attackers themselves. Recent cases range from the arrest of a suspected KillSec leader to the jailing of an insider who locked company devices.

It will be worth watching whether the trial brings out more detail on how recovery firms deal with ransomware gangs. Another open question is whether the case prompts closer oversight of the remediation industry.