WTF?! Law enforcement agencies have long warned against paying ransomware gangs because they could simply demand more money, refuse to hand over a decryption key, or mark you as willing to pay. But it seems we also need to be careful about companies offering remedies for these incidents: they could be just as bad as the criminals themselves.
The U.S. Department of Justice has charged 50-year-old Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” with fraud. He ran a Florida-based company called MonsterCloud that told ransomware victims not to pay attackers because the company had a way to decrypt their files — for a fee, of course.
However, according to the Justice Department, MonsterCloud did not use “proprietary tools” and “advanced decryption techniques” to achieve this feat; The company allegedly used a portion of its customers’ fees to pay the ransomware attackers and then kept the rest, often incurring a significant markup.
One example case allegedly involves Pinhasi charging a customer $150,000 to decrypt a system, paying the hackers $8,200 of that, and then keeping the rest without admitting that he paid the ransom. In another case, prosecutors say he paid the hackers about $236,000 and billed the customer about $380,000.
The indictment also alleges that MonsterCloud presented decrypted sample files as evidence of its ability to recover victims’ data, even though it received these samples from the ransomware operators themselves.
It sounds like a plan so obvious it wouldn’t work, but Pinhasi is said to have charged its customers more than $19 million in fees and paid just over $8 million in ransoms.
MonsterCloud’s website states: “At MonsterCloud, we are not a team of IT experts. We are the most advanced cyber-terrorism team in the world.”
The indictment certainly casts doubt on MonsterCloud’s claims. The website contains testimonials and other promotional material, including endorsements from at least one paid speaker.
In May 2019, a spokesperson who had provided paid testimony contacted Pinhasi to question his business practices and honesty, the indictment says. The spokesperson asked whether MonsterCloud really had proprietary software that could decrypt encrypted data. Pinhasi acknowledged that the company does not have any proprietary technology to decrypt the data affected by ransomware.
Pinhasi pleaded not guilty to the charges and was released on $2 million bail.
A 2019 ProPublica investigation into two data recovery companies found that they typically only paid the ransom and charged victims a surcharge. One of them was MonsterCloud. At the time, Pinhasi denied that MonsterCloud had promised in advance that it could decrypt the files or had misled customers.