News · Defence & Security

Ransomware recovery CEO charged over secret ransom payments

Ransomware recovery CEO charged over secret ransom payments

MonsterCloud is accused of misleading ransomware victims about how it recovered encrypted files. Prosecutors say the company advertised proprietary tools and techniques, but allegedly lacked such technology. Instead, it contacted the criminals behind attacks and obtained decryption keys. The alleged process was simple but concealed. MonsterCloud reportedly paid attackers for keys, used those keys to unlock customer files, and charged customers for recovery. In one cited case, it allegedly paid about $8,200 and billed the victim approximately $150,000. Some contracts mentioned possible contact with criminals, but prosecutors say that contact was usually the first step, not a last resort. The charges concern an alleged scheme running from June 2018 through June 2023. Prosecutors say it involved more than $8 million in ransom payments and over $19 million in customer charges. Pinhasi pleaded not guilty, so these allegations remain unproven in court.

Based on reporting by Bleeping Computer

What is MonsterCloud accused of doing instead of using its own decryption technology?

MonsterCloud is accused of misleading ransomware victims about how it recovered encrypted files. Prosecutors say the company advertised proprietary tools and techniques, but allegedly lacked such technology. Instead, it contacted the criminals behind attacks and obtained decryption keys.

The alleged process was simple but concealed. MonsterCloud reportedly paid attackers for keys, used those keys to unlock customer files, and charged customers for recovery. In one cited case, it allegedly paid about $8,200 and billed the victim approximately $150,000. Some contracts mentioned possible contact with criminals, but prosecutors say that contact was usually the first step, not a last resort.

The charges concern an alleged scheme running from June 2018 through June 2023. Prosecutors say it involved more than $8 million in ransom payments and over $19 million in customer charges. Pinhasi pleaded not guilty, so these allegations remain unproven in court.

What are ransomware and decryption keys, and how do they affect a victim's files?

Ransomware is malicious software that encrypts files, changing readable data into an unreadable form. Attackers typically demand money in exchange for restoring access. A decryption key is a secret digital value used with the attacker’s encryption method to reverse that change. The key is often unique to a victim or attack.

When ransomware runs, documents, databases, images, and other files may become inaccessible. The files can still exist on the computer, but their contents appear scrambled. Correctly applying the key can restore them. Without it, recovery may be extremely difficult, especially when the encryption is strong and backups are unavailable.

The article says MonsterCloud allegedly obtained such keys from ransomware operators and used them to restore customers’ files. In general, victims may also rely on clean backups, security tools, or weaknesses in particular ransomware strains. Results vary, and no recovery method is guaranteed.

How much money did prosecutors say MonsterCloud facilitate in ransom payments and charge customers for recovery services?

The indictment describes a large financial operation, not just isolated recovery cases. Prosecutors say Zohar Pinhasi and his co-conspirators facilitated more than $8 million in ransom payments during the alleged scheme. They allegedly charged hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services.

The difference between those figures represents the broader amount billed to customers, although it should not be treated as a simple profit calculation. The indictment gives individual examples. In one case, Pinhasi allegedly paid about $8,200 to a ransomware gang while charging the victim approximately $150,000. In another, he allegedly paid about $236,000 and charged about $380,000.

These figures come from federal prosecutors’ allegations. Pinhasi pleaded not guilty, and the charges must be proven in court. If accurate, the numbers show how victims could face both the original attack and substantial service fees afterward.

How did MonsterCloud allegedly use sample files as 'recovery proofs' to persuade customers that it could restore their data?

A recovery proof is a small demonstration meant to reassure a victim that locked files can be restored. Prosecutors allege MonsterCloud used decrypted sample files for that purpose. The samples could make the company’s service appear technically capable before a customer agreed to proceed.

According to the indictment, however, the samples were not produced by MonsterCloud’s claimed proprietary technology. They allegedly came from ransomware operations after the company contacted attackers and obtained decryption help. MonsterCloud then allegedly used the restored samples to persuade victims that it could recover their wider data set.

That matters because a convincing demonstration can influence a desperate customer’s decision and willingness to pay. The alleged conduct formed part of a broader scheme prosecutors say ran from 2018 to 2023. Pinhasi pleaded not guilty, so the claims about the sample files remain allegations rather than established facts.

Why can secretly paying a ransom while claiming to have proprietary recovery tools harm or mislead a ransomware victim?

Secretly paying a ransom can mislead a victim about what service they are purchasing. If a company claims to have proprietary recovery tools, the victim may believe the fee pays for specialized technology rather than an attacker’s decryption key. The victim may also make different decisions if told clearly that criminals will be paid.

The indictment alleges MonsterCloud usually contacted ransomware operators first, despite contracts saying such contact might occur only when other recovery methods failed. Prosecutors say the company then charged much more than the ransom. One alleged example involved an $8,200 payment to attackers and a roughly $150,000 customer bill.

This alleged conduct could increase financial harm and reduce informed consent. It may also fund criminal groups and encourage future attacks. The case is unresolved: Pinhasi pleaded not guilty, and prosecutors must prove the alleged deception and wire-fraud charges in court.

What legal consequences could Zohar Pinhasi face if he is convicted of wire fraud conspiracy and wire fraud?

Pinhasi faces federal criminal consequences because prosecutors charged him with one count of conspiracy to commit wire fraud and two counts of wire fraud. Wire fraud generally involves using electronic communications to carry out a scheme to obtain money or property through deception. A conspiracy charge concerns an alleged agreement to pursue such a scheme.

The article states that a conviction could bring a maximum sentence of 20 years in prison. It does not specify whether that maximum applies to each count or describe any possible fine, restitution, or sentencing calculation. Those outcomes would depend on the court and applicable federal rules.

Pinhasi surrendered, pleaded not guilty, and was released on a $2 million bond. His indictment is not a conviction. The government must prove the charges beyond a reasonable doubt, and the defense may challenge claims about MonsterCloud’s representations, payments, contracts, and customer billing.

Why is encrypted data generally difficult to recover without the correct decryption key, and what alternatives might victims pursue besides paying attackers?

Encryption is designed to make data unreadable to anyone without the required key. Modern ransomware may use strong algorithms, so guessing or reversing the key is usually impractical. The files may remain physically present, but their contents cannot be meaningfully opened until the encryption is reversed.

Victims can pursue alternatives to paying attackers. They may restore clean, offline backups, rebuild affected systems, or seek help from incident-response professionals. Security researchers and law-enforcement agencies sometimes publish free decryptors when a ransomware strain has a flaw or its keys become available. Preserving evidence and isolating infected devices can also support investigation and recovery.

These options are general cybersecurity guidance beyond the article’s specific allegations. They do not guarantee success. Paying may not produce a working key and can support criminals, while professional recovery can be costly. Organizations should maintain tested backups and prepare response plans before an attack occurs.

Key Facts:

📌 Prosecutors say MonsterCloud lacked the proprietary decryption technology it advertised.

📌 The company allegedly bought keys directly from ransomware operators.

📌 MonsterCloud allegedly passed attacker-assisted recovery off as its own service.

📌 Ransomware encrypts files and commonly demands payment for restoring access.

📌 A decryption key reverses the encryption and can unlock affected files.

📌 Strong encryption can make recovery difficult without a key or clean backup.

📌 Prosecutors allege more than $8 million in ransom payments.

More on JupiteX