The owner of a ransomware remediation company, MonsterCloud, has been charged with allegedly defrauding victims by secretly paying attackers for decryption keys while claiming to use proprietary technology to recover encrypted data, according to Bleeping Computer.
Zohar Pinhasi, owner of MonsterCloud, was indicted on charges of conspiracy to commit wire fraud and wire fraud. Prosecutors allege that from June 2018 to June 2023, Pinhasi and his co-conspirators did not possess proprietary decryption technology. Instead, they contacted ransomware operators, paid them for decryption keys, and then used these keys to restore customers' files.
The indictment notes that while some contracts disclosed potential communication with or payment to cybercriminals, prosecutors claim this was typically MonsterCloud's first step. In one instance, Pinhasi allegedly paid $8,200 to a ransomware gang and charged the victim $150,000. Over the course of the alleged scheme, Pinhasi and his associates facilitated over $8 million in ransom payments while charging companies more than $19 million for recovery services. A 2019 ProPublica investigation had previously raised similar concerns about MonsterCloud's practices.
Source: Bleeping Computer
