
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data.
Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire fraud conspiracy. If convicted, the defendant faces up to 20 years in prison for each count.
"By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," said U.S. Attorney Joseph Nocella, Jr. for the Eastern District of New York.
Pinhasi, who owned and operated a Florida company called MonsterCloud, is alleged to have made false representations to ransomware victims, urging them not to pay a ransom and claiming to have "proprietary tools" and "advanced decryption techniques" in possession that could be used to recover encrypted data without yielding to ransom demands.
On its website, MonsterCloud claims it uses "advanced decryption techniques and cutting-edge technology" to restore data. Under a section called "Should I Pay The Ransom?," it states, "Paying a ransom to cybercriminals does not guarantee a positive outcome. In fact, it only serves to encourage and reward their illegal behavior."
In a Q&A published on its site, MonsterCloud also addressed the question "Do you pay ransoms on behalf of your clients to recover data?," stating, "While we strongly advocate not paying ransoms yourselves, we have extensive experience working with ransomware perpetrators and sometimes resort to other means to resolve the ransomware incident for our clients. All terms are disclosed in our service contract."
Contrary to its claims, there were no specialized tools to decrypt the data. Instead, Pinhasi approached the cybercriminals and paid them in exchange for obtaining a decryptor to recover the information.
Pinhasi is said to have charged MonsterCloud's clients a fee that was "substantially higher" than the ransom that was secretly paid to the criminals. In one case in August 2023, the defendant made a ransom payment of approximately $8,200 to a threat actor and billed the client approximately $150,000.
In another incident in or around October 2021, Pinhasi made a ransom payment of approximately $236,000 and charged the customer about $380,000. In all, Pinhasi is accused of charging clients more than $19 million and paying more than $8 million in ransom payments.
"As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat," said Assistant Director James C. Barnacle Jr. of the U.S. Federal Bureau of Investigation (FBI). "Instead, he turned the victim's crisis into his own profit center. This deception is unacceptable."