A federal grand jury in the Eastern District of New York indicted Zohar Pinhasi, owner of ransomware incident response company MonsterCloud, for allegedly defrauding customers who were trying to recover their encrypted data. Pinhasi appeared before a federal court in Brooklyn after surrendering himself, pleaded not guilty, and was then released on $2 million bail.
The case involves two counts of wire fraud and one count of conspiracy to commit wire fraud, in a scheme that prosecutors say lasted from June 2018 to June 2023. If convicted, he could face up to 20 years in prison.
What do prosecutors allege?
According to the indictment, MonsterCloud marketed proprietary decryption tools and techniques for recovering files without paying ransomware operators. But prosecutors allege that Pinhasi and his associates did not possess the advertised technology, and that they typically communicated with malware operators and paid them for decryption keys, then used those keys to recover customers’ files.
The indictment states that some of the company’s contracts disclosed the possibility of communicating with attackers or paying them, but said that this option would be used when the files could not be decrypted by other means. Prosecutors, however, allege that negotiating with attackers was usually the first step in obtaining the keys.
Authorities say the company used decrypted sample files as “proofs of recovery” to convince victims of its ability to restore their data, even though those files had, according to the allegations, been decrypted with the assistance of ransomware operators.
A major difference between the ransom and the service fee
The indictment includes examples of the difference between what MonsterCloud paid attackers and what it charged customers. In one case, the company allegedly paid a ransomware gang about $8,200 and then charged the victim nearly $150,000. In another case, prosecutors say it paid about $236,000 and charged the customer approximately $380,000.
Over the course of the alleged scheme, authorities say Pinhasi and his associates facilitated more than $8 million in ransom payments, while charging hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services.
Why does this matter?
The significance of the case is not limited to accusing a company of concealing how it recovered data; it concerns a sensitive decision organizations make after a ransomware attack: Should they pay the attackers directly, or use an intermediary that claims to have a technical alternative? If the allegations are proven, concealing the payment could prevent a customer from assessing the legal, security, and ethical risks associated with funding attackers, while also making “proof of recovery capability” insufficient on its own to judge the nature of the solution.
The case also brings back concerns raised in a 2019 investigation by ProPublica, which discussed instances in which MonsterCloud paid ransomware operators while presenting the service as a different solution. At the time, ProPublica quoted security researcher Fabian Wosar as saying that researchers tested data recovery companies using simulated ransomware and received anonymous messages offering to pay the ransom, which they traced to data recovery companies, including MonsterCloud and Proven Data.
Pinhasi denied in that investigation that MonsterCloud had misled customers or promised them decryption in advance, and said that recovery methods varied from case to case and that he could not disclose them because they were a “trade secret.” BleepingComputer also requested comment from defense attorneys Christopher Clark and Rodney Villazor regarding the allegations, but the material did not indicate that a response had been received from either of them.