THE article reports on allegations surrounding MonsterCloud, a ransomware incident response firm led by Zohar Pinhasi, who has been charged by the United States Attorney’s Office for the Eastern District of New York with wire fraud and conspiracy to commit wire fraud.
Prosecutors accuse Pinhasi of running a deceptive data-recovery operation in which the company claimed to possess tools capable of decrypting modern, advanced encryption, while in reality it primarily relied on negotiating with attackers for decryption keys and paying ransoms. The piece cites a documented case in which MonsterCloud charged a client about $150,000 for data recovery, but Pinhasi allegedly paid hackers just $8,200 to obtain the necessary decryption key. The article notes that, although files were eventually restored, the vast price discrepancy is presented as evidence of deceptive practices.
The piece goes on to describe contractual and methodological gaps: MonsterCloud’s contracts reportedly included a fallback clause allowing the company to contact attackers for negotiation if other recovery methods failed, while the firm allegedly used no proprietary recovery tools beyond purchasing keys.
The legal ramifications are highlighted, including the claim that Pinhasi allegedly collected over $19 million in data-recovery fees from numerous victims across the United States and Canada, while secretly paying over $8 million in ransoms to hackers. The article notes Pinhasi pled not guilty and was released on a $2 million bail. It also emphasises that paying ransoms or engaging with designated hacking groups can expose organisations to legal risk.