Ransomware, Incident Response, Compliance Management, Data Security

Ransomware remediation company owner charged with defrauding victims

The owner of a ransomware remediation company, MonsterCloud, has been charged with allegedly defrauding victims by secretly paying attackers for decryption keys while claiming to use proprietary technology to recover encrypted data, according to Bleeping Computer.

Zohar Pinhasi, owner of MonsterCloud, was indicted on charges of conspiracy to commit wire fraud and wire fraud. Prosecutors allege that from June 2018 to June 2023, Pinhasi and his co-conspirators did not possess proprietary decryption technology. Instead, they contacted ransomware operators, paid them for decryption keys, and then used these keys to restore customers' files.

The indictment notes that while some contracts disclosed potential communication with or payment to cybercriminals, prosecutors claim this was typically MonsterCloud's first step. In one instance, Pinhasi allegedly paid $8,200 to a ransomware gang and charged the victim $150,000. Over the course of the alleged scheme, Pinhasi and his associates facilitated over $8 million in ransom payments while charging companies more than $19 million for recovery services. A 2019 ProPublica investigation had previously raised similar concerns about MonsterCloud's practices.

Source: Bleeping Computer

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds