THE U.S. Department of Justice has charged Zohar Pinhasi, a 50-year-old American-Israeli national who owned MonsterCloud, with two counts of wire fraud and one count of wire fraud conspiracy. Prosecutors allege he defrauded ransomware victims by telling them he could decrypt data without paying attackers, while secretly paying the criminals to obtain decryptors and then charging clients inflated fees. If convicted, he faces up to 20 years’ imprisonment on each count.
The investigation contends that Pinhasi’s company falsely claimed to possess proprietary decryption tools and advanced techniques, only to reveal that decryptors were obtained by paying ransom actors. MonsterCloud’s own materials claimed to offer “advanced decryption techniques and cutting-edge technology” and to advise clients against paying ransoms; in practice, victims were allegedly billed well above the ransom amounts paid to criminals.
In one August 2023 case, a ransom payment of about $8,200 was made to a threat actor, yet the client was billed around $150,000. Another incident, circa October 2021, involved a $236,000 ransom payment and a bill of about $380,000. Overall, Pinhasi is accused of charging clients more than $19 million while paying more than $8 million in ransoms. The FBI characterised the scheme as turning the victims’ crisis into a profit centre, with compromised remediation steps never actually addressing the underlying threat.