databreaches.net 8 Oct 2026, 00:47 UTC

Cybersecurity Firm Owner Accused of Profiting From Ransomware Victims

CyberSIXT Evidence Panel Source marked as original reporting

A U.S. indictment alleges that Zohar Pinhasi, a known cybersecurity figure and owner of MonsterCloud, defrauded ransomware victims by falsely presenting himself as able to decrypt data without paying attackers. He is charged in the Eastern District of New York with two counts of wire fraud and one count of wire fraud conspiracy.

Court filings describe how Pinhasi claimed MonsterCloud had “proprietary tools” and “advanced decryption techniques” to help victims avoid paying ransom, while in reality he did not possess any special decryption capability and instead contacted the cybercriminals who had attacked his clients. He purported to fix the incidents but allegedly failed to remediate the underlying threat, instead turning the victims’ crisis into a profit centre.

Evidence cited in the indictment indicates that Pinhasi’s business model involved charging clients markedly more than the ransom paid to recover data. For example, around August 2023 he paid approximately $8,200 to a cybercriminal and billed the client about $150,000. Over the course of the scheme, he allegedly charged victims more than $19 million and paid more than $8 million in ransoms. If convicted on the charges, he faces a maximum penalty of 20 years’ imprisonment on each count.

The Department of Justice notes that the FBI is pursuing the case, and it follows joint guidance with CISA advising that victims should not pay ransoms, as paying does not guarantee data recovery or system restoration.

View full article

Article by CyberSIXT