Feds Say Ransomware Expert’s Miracle Cure Was Just Paying the Hackers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker

Zohar Pinhasi spent years telling ransomware victims his Florida company could get their files back without paying the attackers. But federal prosecutors now say Pinhasi’s firm simply paid the ransoms on behalf of victims at marked-up prices.
Pinhasi, 50, a U.S. and Israeli national from Hollywood, Florida, was arraigned Wednesday in federal court in Brooklyn on two counts of wire fraud and one count of conspiracy to commit wire fraud. He owns MonsterCloud LLC, which the charging document calls a purported ransomware remediation company. Each count carries a maximum of 20 years.
FBI Assistant Director in Charge James C. Barnacle Jr., who leads the bureau’s New York field office, said, “As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim’s crisis into his own profit center.”
Pinhasi surrendered Wednesday, pleaded not guilty, and was released on a $2 million bond, the U.S. Attorney’s Office told BleepingComputer.
How the MonsterCloud Ransomware Remediation Business Allegedly Worked
The indictment says the MonsterCloud website claimed “our team specializes in helping businesses recover their data without succumbing to ransom demands,” and that the firm did it with “advanced decryption techniques and cutting-edge technology” and “proprietary tools.” Paying a ransom, the site warned, would not guarantee any data would be recovered, might invite another attack, and reward illegal behavior.
Multiple businesses hired MonsterCloud specifically because they did not want to pay a cybercriminal and would not have authorized a payment, prosecutors allege. Many of them came in through the Contact Us form on the website, which the indictment treats as evidence they had read the firm’s marketing pitch. The companies were often struggling to operate or suffering financial losses because ransomware had locked them out of their files. Hundreds of them, in the United States and Canada, eventually paid the firm.
Prosecutors say neither Pinhasi nor the employees and contractors they describe as co-conspirators had a specialized decryptor. Instead, Pinhasi set the prices and handled ransom payment negotiations with the attackers. After a controller took the intake, MonsterCloud quoted an analysis phase, typically $2,500 to $10,000, with a money-back guarantee.
Next, the client handed over the details of their case, usually with two encrypted sample files. In many instances, Pinhasi then sent those samples to the attacker, received unlocked versions back, and showed them to the client as proof MonsterCloud could decrypt the files. Full recovery, the indictment says, was “a more expensive service, costing up to two or more times the ransom.”
Pinhasi allegedly told staff and contractors to say “recovery tool” instead of “decrypter,” and not to tell clients a ransom had been paid. While the work was underway, he described the method as a trade secret involving “proprietary means and methods.”
Prosecutors allege that hundreds of companies collectively paid MonsterCloud more than $19 million for data recovery and remediation services, while Pinhasi paid cybercriminals more than $8 million in ransom payments. For example, in or around August 2023, Pinhasi allegedly paid an attacker about $8,200 and billed the client about $150,000. The indictment also alleges that many customers were not told that ransom payments had been made.
Some full-recovery contracts said MonsterCloud might communicate with or pay cybercriminals, and only “once all possible means of directly decrypting Client’s files have been exhausted.” The indictment says contact with the attackers was generally the first step, the typical way he got the proofs, and the standard way he got the keys.
“As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” said United States Attorney Joseph Nocella, Jr. “Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity.”
A MonsterCloud Spokesperson Started Asking Questions in 2019
The indictment also quotes Pinhasi answering a paid spokesperson who had already given a testimonial for the site. In May 2019, that person contacted him with questions about his business practices and truthfulness, and asked whether MonsterCloud actually had proprietary software that could decrypt the data. “MonsterCloud doesn’t hold any Proprietary technology [to] decrypt the ransomware data,” he allegedly replied, adding that he would explain further in phone conversations.
That exchange landed the same month ProPublica published an investigation of firms that promised high-tech ransomware recovery and usually just paid the hackers. MonsterCloud was one of two companies in the story. At the time, Pinhasi told ProPublica the methods MonsterCloud used varied by case and were a trade secret, and that the firm never promised a particular method. “If someone is saying that we promised up front that we would be able to decrypt their files, I am certain that this is inaccurate,” he insisted. He also added, “We work in the shadows. How we do it, it’s our problem. You will get your data back. Sit back, relax and enjoy the ride.”
Pinhasi also told ProPublica that MonsterCloud had met with the FBI to share what it knew about ransomware. John Pistole, a former deputy director of the FBI and former administrator of the Transportation Security Administration, was the only named member of MonsterCloud’s Cyber Security Advisory Council at the time and appeared in a promotional video selling the firm’s “proprietary technology.”
The ProPublica piece also covered a number of ransomware cases involving local law enforcement. In Trumann, Arkansas, MonsterCloud restored decades of case notes and payroll for local law enforcement within 72 hours, waived a fee of about $75,000, and assured the department it had not paid a ransom. Chief Chad Henson of the Trumann Police Department called paying with taxpayer money “the nuclear option,” but Pinhasi told ProPublica the law enforcement work was complimentary: “There has never been one cent of taxpayer money used for any ransom we’ve been involved with.” He declined to say how the Trumann files were retrieved.
Incredibly, the MonsterCloud website is still live and selling the same idea, and a ransomware removal page still features former FBI deputy director John Pistole outlining the firm’s recovery process, in addition to testimonials from various police departments. And the homepage still tells victims not to pay. “Don’t Pay the Ransom: Giving money to the threat actors who attacked you guarantees absolutely nothing other than providing them an incentive to return for subsequent attacks,” the site says.


