The owner of a Florida cybersecurity company has been charged with fraud after allegedly misleading ransomware victims into paying inflated fees for data recovery services. Federal prosecutors claim he secretly paid the hackers responsible for the attacks while telling customers that his company could restore their files without paying a ransom.
Zohar Pinhasi, 50, a US and Israeli national, operated MonsterCloud LLC, a company offering ransomware recovery services to businesses whose systems had been encrypted by cybercriminals. He was arraigned in federal court in Brooklyn on October 7, following an indictment issued in September.
According to the US Department of Justice, MonsterCloud advertised specialized technology capable of recovering encrypted files without negotiating with ransomware operators. The company presented its services as an alternative to paying criminals and promoted its supposedly advanced decryption capabilities.
Prosecutors allege that these claims were false. Rather than using proprietary recovery tools, Pinhasi reportedly contacted the attackers directly, paid their ransom demands, and obtained decryption keys that MonsterCloud employees then used to attempt to restore customer data.
Customers were allegedly unaware that their payments were being used to compensate the same criminals who had attacked their systems. Investigators say MonsterCloud charged significantly more than the amounts demanded by the ransomware operators.
One example involved a customer who was billed approximately $150,000 in August 2023. According to prosecutors, Pinhasi had paid the attackers only about $8,200 to obtain the necessary decryption key.
Across the alleged scheme, MonsterCloud collected more than $19 million from customers while making over $8 million in ransom payments to cybercriminals. Authorities believe Pinhasi kept substantial amounts of the difference.
Investigators also examined how the company promoted its services. MonsterCloud’s website featured customer testimonials, including endorsements from paid spokespersons, while emphasizing its ability to recover files without giving in to ransom demands.
Court documents describe a 2019 exchange in which one spokesperson questioned whether MonsterCloud actually possessed its advertised decryption technology. Pinhasi allegedly acknowledged that the company did not have proprietary software capable of decrypting ransomware-locked data.
Pinhasi faces two counts of wire fraud and one count of wire fraud conspiracy. Each charge carries a maximum potential prison sentence of 20 years, although any sentence would depend on the outcome of the proceedings.
