Connect with us

Security

Unveiling the Dark Secrets of MonsterCloud’s Alleged Billing Scam: $19M in Ransoms Paid for Data Decryption

Published

on

US-Israeli National Charged for Defrauding Ransomware Victims

The U.S. Department of Justice (DoJ) has brought charges against a 50-year-old US and Israeli national, Zohar Pinhasi, for allegedly defrauding ransomware victims. He is accused of secretly paying ransomware attackers to obtain decryptors while misleading victims into thinking he had proprietary tools to recover their data.

Pinhasi, also known as Zack Silver and Zack Green, faces two counts of wire fraud and one count of wire fraud conspiracy, with each count carrying a potential prison sentence of up to 20 years upon conviction.

According to U.S. Attorney Joseph Nocella, Jr., Pinhasi deceived his clients by falsely claiming to decrypt ransomware without paying the ransom demands, ultimately profiting from the situation at the expense of the victims.

Operating a company called MonsterCloud in Florida, Pinhasi allegedly misrepresented his capabilities to ransomware victims, advising them against paying ransoms and assuring them of his possession of “proprietary tools” and “advanced decryption techniques” to recover their encrypted data.

Despite MonsterCloud’s claims of using advanced decryption techniques, it has been revealed that Pinhasi did not have specialized tools to decrypt the data. Instead, he reportedly paid the cybercriminals to obtain decryptors, charging his clients exorbitant fees in the process.

For instance, in August 2023, Pinhasi paid approximately $8,200 to a threat actor for a ransom and billed the client around $150,000. In another case around October 2021, he paid about $236,000 for a ransom and charged the customer close to $380,000. Overall, Pinhasi is accused of charging clients over $19 million while paying more than $8 million in ransom payments.

See also  Windows 11 Update Resolves File Explorer Freezes and Search Problems

Assistant Director James C. Barnacle Jr. of the FBI condemned Pinhasi’s actions, stating that he exploited victims’ crises for personal gain without addressing the underlying threat, which is deemed unacceptable.

It is essential for businesses and individuals to exercise caution when seeking assistance with ransomware incidents and to verify the authenticity and credibility of service providers to avoid falling victim to fraudulent schemes.

Trending