
The owner of a US ransomware remediation company allegedly promised businesses he could recover their files without paying cybercriminals. Prosecutors say he secretly paid the hackers instead — and charged victims substantially more.
Imagine your company has just been hacked with ransomware. You hire a cybersecurity firm that says it can recover your files without giving anything to the criminals. But behind the scenes, the company does exactly what it told you not to do: pays the hackers, gets the decryption key and sends you a much bigger bill.
US prosecutors say that is essentially how a Florida-based ransomware remediation business operated for years.
Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” was arraigned Oct. 7 in federal court in Brooklyn on two counts of wire fraud and one count of wire fraud conspiracy.
Pinhasi owned and operated MonsterCloud LLC, a Florida ransomware remediation company that marketed itself to businesses hit by cyberattacks.
According to the US Department of Justice, MonsterCloud presented itself as an alternative to paying ransomware operators. Its website warned victims against paying ransoms and claimed the company could recover data using “advanced decryption techniques” and other technology.
Prosecutors say those capabilities didn't exist.
Instead, Pinhasi allegedly contacted the very cybercriminals who had attacked his clients, paid them for decryption keys, then used them in an attempt to restore the encrypted files.
The alleged scheme ran from June 2018 through June 2023 and affected hundreds of companies in the United States and Canada, according to reporting on the indictment.
The difference between what MonsterCloud allegedly paid attackers and what it charged victims could be enormous.
In one example cited by prosecutors, MonsterCloud paid a ransomware operator approximately $8,200 in August 2023. The affected customer was allegedly charged approximately $150,000.
Another incident reportedly involved a ransom payment of roughly $236,000 and a bill of about $380,000 to the customer.
Overall, prosecutors allege Pinhasi and his company charged clients more than $19 million while paying more than $8 million in ransoms.
The allegations go beyond simply acting as a middleman.
According to prosecutors, MonsterCloud also displayed customer “testimonials,” some involving paid spokespersons. In 2019, one spokesperson reportedly asked Pinhasi directly whether the company actually hadproprietary ransomware-decryption software.
According to the indictment, Pinhasi acknowledged that it did not.
Getting a decryption key can be part of recovery after an attack, but it doesn't mean the underlying security problem has been fixed.
Proper incident response involves understanding how attackers entered the network, determining what systems and accounts were compromised, containing the intrusion, removing malicious access, assessing whether data was stolen, restoring systems safely and closing the security gaps that allowed the attack to happen.
Simply obtaining a decryptor does not accomplish all of that.
The FBI says it doesn’t support paying ransomware demands because it offers no guarantee that victims will recover their data, and it can encourage further attacks. Even when a ransom is paid, organizations are urged to report the incident to law enforcement.
Before an incident happens, organizations should identify reputable incident-response providers and establish a response plan rather than searching for emergency help for the first time in the middle of a crisis.
Pinhasi has been charged, but not yet convicted. He is presumed innocent unless proven guilty. If convicted, he faces up to 20 years behind bars.
On topic:
IT engineer gets 32 months in prison after sabotaging employer and demanding $750,000
Police dismantle ransomware gang allegedly run by a 16-year-old
Alleged teen ransomware hustler faces US charges after arrest in Finland
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts