Ransomware · 3h ago
The U.S. Department of Justice says MonsterCloud owner Zohar Pinhasi charged ransomware victims more than $19 million while secretly paying attackers more than $8 million for decryptors. The charges turn a long-running suspicion about recovery middlemen into an alleged wire-fraud scheme with named dollar figures.
According to the DOJ, Pinhasi told clients MonsterCloud had proprietary decryption tools and advanced techniques, but instead went back to the attackers, bought access to a decryptor, and billed the victim at a much higher price. In one case, the filing says, an $8,200 ransom became a $150,000 invoice; in another, a $236,000 payment became a $380,000 bill.
The exposure here sits in outsourced ransomware response: once a third party controls both the negotiation and the recovery story, a customer can end up funding the extortion twice while being told the fix was internal. The reporting does not settle how common that model is, only that this case makes the trust risk concrete.
5 sources covering this story
Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme
Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation.
MonsterCloud’s owner faces fraud charges for allegedly secretly paying ransomware gangs while overcharging clients for decryption services.
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
MonsterCloud's owner is accused of charging ransomware victims over $19 million while secretly paying attackers over $8 million for decryptors.
Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead
Feds claim he charged clients more than ransoms, paid up, pocketed the difference
Ransomware recovery CEO charged over secret ransom payments
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data.
Part of the PlainSec briefing for 2026-10-08