MonsterCloud charged over fake ransomware recovery
The U.S. Department of Justice says MonsterCloud owner Zohar Pinhasi charged ransomware victims more than $19 million while secretly paying attackers more than $8 million for decryptors. The charges turn a long-running suspicion about recovery middlemen into an alleged wire-fraud scheme with named dollar figures.
According to the DOJ, Pinhasi told clients MonsterCloud had proprietary decryption tools and advanced techniques, but instead went back to the attackers, bought access to a decryptor, and billed the victim at a much higher price. In one case, the filing says, an $8,200 ransom became a $150,000 invoice; in another, a $236,000 payment became a $380,000 bill.
The exposure here sits in outsourced ransomware response: once a third party controls both the negotiation and the recovery story, a customer can end up funding the extortion twice while being told the fix was internal. The reporting does not settle how common that model is, only that this case makes the trust risk concrete.