Ransomware Recovery Scam: Fake Decryption Tools Mask $11M Markup
A U.S. company owner has been charged with orchestrating a ransomware recovery fraud scheme that allegedly generated over $19 million in client fees while paying $8 million in ransoms to cybercriminal groups.
Zohar Pinhasi, 50, who operated MonsterCloud under aliases including ‘Zack Silver’ and ‘Zack Green,’ appeared in a New York court facing wire fraud charges. Prosecutors allege that Pinhasi misrepresented his company’s capabilities by claiming it could recover data from ransomware attacks without paying cybercriminals. Instead, he allegedly facilitated payments to ransomware operators to obtain decryption keys, then resold those keys to victims at inflated prices. In one case, Pinhasi reportedly paid $8,200 to a ransomware affiliate and charged a client $150,000 for the same decryption service. The scheme involved multiple steps, including contacting extortion groups, negotiating ransom payments, and leveraging obtained keys to extract additional revenue from affected organizations. Over the course of the operation, prosecutors state that Pinhasi made more than 100 ransom payments totaling approximately $8 million while collecting over $19 million from clients. The indictment details how victims were misled into believing they could avoid paying cybercriminals through MonsterCloud’s services, only to face secondary financial exploitation. Assistant Attorney General A. Tysen Duva described the case as an instance where victims were “harmed again” through fraudulent recovery practices. Pinhasi faces potential decades in prison if convicted of wire fraud and conspiracy charges. The case highlights vulnerabilities in ransomware response strategies, as victims often seek alternatives to direct payments but may encounter deceptive intermediaries. Cybersecurity experts have previously warned about the risks of third-party recovery services that lack transparency or verifiable technical capabilities. The prosecution underscores the growing scrutiny of entities that exploit ransomware incidents for financial gain, even as law enforcement agencies continue to target both cybercriminals and their enablers.
