DOJ charges ransomware recovery CEO for secretly paying hackers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The owner of a ransomware recovery firm was hit with wire fraud charges Wednesday for allegedly falsely claiming he could help victims decrypt their systems without paying ransoms. 

The Justice Department said 50-year-old U.S. and Israeli national Zohar Pinhasi was the owner of a company called MonsterCloud that purported to provide incident response to help victims of ransomware attacks. 

The Florida-based company said it could help organizations recover their encrypted data without paying ransomware gangs, claiming to have “proprietary tools” and “advanced decryption techniques.”

In court documents, prosecutors said Pinhasi simply paid ransoms and charged victims a fee that was significantly more than the original ransom demand. After paying the ransomware gangs, he would get a decryption key and MonsterCloud employees would try to decrypt the organization’s files. 

U.S. Attorney Joseph Nocella Jr. said Pinhasi “re-victimized his clients while extracting a hefty profit for himself.”

In total, he charged clients $19 million and paid about $8 million in ransom payments to cybercriminals. In one 2023 incident cited in the indictment, Pinhasi allegedly paid a $8,200 ransom and charged the client $150,000. 

Pinhasi is facing up to 20 years if convicted of wire fraud and wire fraud conspiracy. MonsterCloud did not respond to requests for comment. 

MonsterCloud was spotlighted in a 2019 ProPublica exposé on companies defrauding ransomware victims by paying ransoms and charging exorbitant fees on the backend. 

Pinhasi — who at the time told the news outlet he was a former Israeli military IT security intelligence officer — denied lying to clients, arguing that he could not share his methods because they were a trade secret.  

A researcher quoted in the article set up a sting where he infected his own device with ransomware and contacted MonsterCloud for assistance. MonsterCloud claimed it could decrypt the files and immediately reached out to the fake ransomware attacker offering to pay the ransom. Pinhasi claimed he did not remember the incident. 

According to ProPublica, local governments and police departments were among the defrauded victims who sought Pinhasi’s help. 

Pinhasi paid a former deputy director of the FBI, John Pistole, to be a spokesperson of the firm. Pistole openly admitted that Pinhasi was simply paying the ransoms, telling ProPublica in 2019 that it “was the business model.”

“The model I’m used to is, you pay the ransom,” he told ProPublica. “Based on my experience and knowledge, ransom is paid and they facilitate the best practices moving forward.”

The FBI and Cybersecurity and Infrastructure Security Agency (CISA) have repeatedly advised organizations over the last decade to never pay ransoms but companies like MonsterCloud emerged as secondary options for victims willing to simply pay for a restoration of critical business tools and data by any means. 

The indictment of Pinhasi is the latest effort by the Justice Department to target the murky industry of ransomware recovery and cybercriminal mediation. 

Two ransomware negotiators were given four-year sentences in May after pleading guilty to conducting their own covert ransomware attacks and coordinating with ransomware gangs while purportedly negotiating ransoms on behalf of at least five victims.

——————————————————–


Click Here For The Original Source.

.........................