MonsterCloud CEO charged in alleged ransomware recovery fraud | #ransomware | #cybercrime


  • MonsterCloud owner Zohar Pinhasi was indicted on multiple fraud charges for allegedly misleading ransomware victims about the company’s ability to recover encrypted files without paying cybercriminals.
  • Prosecutors allege Pinhasi secretly paid ransomware operators for decryption keys while charging affected businesses substantially higher fees, including $150,000 in one case involving an $8,200 ransom payment.
  • Pinhasi was released on a $2 mn bond. The indictment does not establish whether the affected businesses had cyber insurance or whether insurers could pursue subrogation claims.

Zohar Pinhasi, owner of Miami-based cybersecurity company MonsterCloud, faces federal fraud charges over an alleged scheme in which he secretly paid ransomware attackers to unlock clients’ encrypted files while charging the victims substantially higher fees for what he represented as proprietary recovery services.

Pinhasi was arraigned in New York this week following a grand jury indictment issued in September. Prosecutors allege that he exploited businesses already affected by ransomware attacks, misleading them about how MonsterCloud restored access to their data and retaining substantial profits from the transactions.

According to the indictment, business owners seeking assistance after ransomware incidents were told that MonsterCloud had specialized software capable of decrypting compromised files without making payments to cybercriminals.

As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself.

US Attorney Joseph Nocella Jr. said in a statement

Prosecutors allege that Pinhasi instead negotiated with the attackers and paid them to obtain decryption keys. He then charged clients considerably more than the ransom amounts without disclosing how their files had been recovered.

In one case described in the indictment, Pinhasi allegedly paid approximately $8,200 to a cybercriminal before billing the affected business $150,000 for the recovery service. The client was not informed that the underlying decryption had been achieved by paying the attacker.

Federal investigators also allege that MonsterCloud’s intervention failed to address the underlying cybersecurity vulnerabilities or threats responsible for the original attacks.

As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim’s crisis into his own profit center.

Assistant FBI Director James Barnacle

Pinhasi, who holds dual US and Israeli citizenship, could not be reached for comment Thursday morning through MonsterCloud’s telephone number. Court records show that he was released from custody after posting a $2 mn bond.

The indictment leaves several insurance-related questions unresolved. Prosecutors did not indicate whether the affected businesses maintained cyber insurance policies, whether insurers reimbursed the disputed recovery fees, or whether insurance companies might seek to recover payments from Pinhasi through subrogation proceedings.

The US Department of Justice could not immediately be reached for additional comment on those questions.



Click Here For The Original Source.

——————————————————–

..........

.

.