← Back to the feed

US charges cybersecurity firm boss over alleged ransomware fraud

The Register ·

The United States Department of Justice has charged Zohar Pinhasi, operator of the Florida-based company MonsterCloud, with fraud for deceiving ransomware victims. Pinhasi allegedly claimed his company could decrypt locked files using proprietary technology and advanced techniques, but actually paid ransomers directly with client funds whilst keeping the substantial difference without disclosure. This matters because it victimised already-compromised businesses and undermined trust in the cybersecurity services meant to help them.

Federal investigators allege Pinhasi extracted over $19 million from clients whilst paying roughly $8 million in ransom payments—netting approximately $11 million through the scheme. In one notable case, he charged a client $150,000 to decrypt their files, paid an $8,200 ransom, and pocketed the remaining $141,800 without admitting the payment. Pinhasi faces two counts of wire fraud and one conspiracy count, each carrying potential 20-year prison sentences. The indictment reveals that when directly asked in 2019 by a paid testimonial provider whether MonsterCloud possessed actual proprietary decryption software, Pinhasi admitted they did not.

  • Ransomware company charged $19 million but allegedly paid ransoms and kept the difference
  • Founder claimed proprietary decryption technology that investigators say didn't exist
  • Faces 20-year sentences on each fraud count if convicted

New here? Start with this

MonsterCloud is a Florida-based cybersecurity company that helps businesses recover after ransomware attacks, where hackers lock up a company's computer files and demand payment to restore access. The company claims to use specialised technology and techniques to decrypt these locked files and recover them without paying the criminals. For affected businesses facing losing their data, such services are essential.

Zohar Pinhasi operates MonsterCloud and stands accused of defrauding his customers about how the company actually works. Rather than deploying proprietary decryption technology as he claimed, federal investigators allege that Pinhasi simply paid the ransomware attackers directly using client funds, then pocketed the remaining difference without telling his customers what had happened.

This matters because victims of ransomware attacks are already in crisis and vulnerable to exploitation. The alleged scheme involved extracting over $19 million from affected businesses whilst paying roughly $8 million in actual ransom payments—leaving approximately $11 million allegedly obtained through fraud. When security firms exploit desperate customers rather than genuinely helping them, it damages trust in an industry that businesses depend on in their most vulnerable moments.

Cybersecurity Technology

Read the full article at the source →

Originally published by The Register as “Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead”.