The owner of ransomware recovery company MonsterCloud has been charged in the United States over allegations that the company secretly paid ransomware operators for decryption keys while presenting its services to customers as an alternative to paying cybercriminals directly.
Zohar Pinhasi, 50, was indicted by a federal grand jury in the Eastern District of New York on September 23. He was arraigned in federal court in Brooklyn, pleaded not guilty and was released on a $2 million bond.
The allegations relate to conduct prosecutors say occurred between June 2018 and June 2023.
Prosecutors Allege MonsterCloud Used Ransom Payments
According to the indictment described in the source report, MonsterCloud advertised ransomware remediation services that were intended to help businesses recover encrypted files without paying attackers.
Prosecutors allege that the company did not possess the proprietary decryption technology it promoted. Instead, they say Pinhasi and his associates contacted ransomware groups and obtained decryption keys by making payments to them.
The charges against Pinhasi include one count of conspiracy to commit wire fraud and two counts of wire fraud.
If convicted, he could face a maximum sentence of 20 years in prison. The charges remain allegations, and Pinhasi is presumed innocent unless proven guilty in court.
Customers Allegedly Paid Far More Than Ransom Amounts
The indictment alleges that MonsterCloud sometimes charged customers substantially more than the amounts allegedly paid to ransomware operators.
In one example cited by prosecutors, the company allegedly paid about $8,200 to a ransomware group while charging a customer approximately $150,000 for recovery services.
In another case, prosecutors allege that around $236,000 was paid as ransom while the customer was charged approximately $380,000.
The indictment also alleges that some customer contracts mentioned the possibility of communicating with or paying cybercriminals. Prosecutors contend, however, that the contracts presented such payments as a measure that would be considered only if other recovery methods failed.
According to the allegations, communications and payments to ransomware operators were instead frequently used as an initial method of obtaining decryption keys.
For businesses examining potentially suspicious payments, recovery charges or financial trails linked to cyber incidents, Financial Investigation can be relevant to understanding transaction flows and financial records.
Decrypted Files Allegedly Used as Recovery Proof
Prosecutors also allege that MonsterCloud provided customers with sample decrypted files as proof that their data could be recovered.
The indictment claims those files had been restored using decryption keys obtained from ransomware operators rather than through proprietary technology developed by the company.
Across the alleged scheme, prosecutors say Pinhasi and his co-conspirators facilitated more than $8 million in ransom payments and charged hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services.
These figures are allegations contained in the federal case and have not been established as facts through a final court judgment.
Earlier Claims About MonsterCloud
The current allegations also resemble concerns raised publicly about MonsterCloud several years ago.
A 2019 ProPublica investigation reported allegations that the company sometimes paid ransomware operators while presenting its services as an alternative to paying attackers.
Pinhasi disputed those earlier allegations. He said MonsterCloud did not guarantee in advance that it could decrypt customers' files and maintained that its recovery methods differed depending on the circumstances.
He also declined to disclose the company's techniques, describing them as trade secrets.
Federal Case Now Moves Forward
The latest federal prosecution focuses on alleged conduct between 2018 and 2023. Pinhasi has pleaded not guilty, meaning the government's allegations will have to be tested through the judicial process.
The case highlights the financial and operational complexities that can arise when companies offer ransomware recovery services, particularly when payments to attackers, customer billing and claims about proprietary recovery capabilities intersect.
For now, the indictment represents the prosecution's allegations rather than a finding of guilt.