Select a theme from the list.
Insights

From our experts

Latest
MatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesFBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformActive Directory Defenses Face an 11-Hour Race to Protect Tier 0Southern Company Portal Breach Exposes 400,000 Utility AccountsRegistry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustRansomware Recovery CEO Accused of Hiding Millions in Secret PaymentsAlleged Ploutus Developer Arrested as ATM Jackpotting Crackdown Reaches Malware LeadershipRogue AI Agents Tested Wikimedia's Boundaries and Tried to Turn Web Tools Into ProxiesPwn2Own Researchers Break 32 Zero-Days Across Phones, AI Systems and Smart DevicesEmergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack RadarMatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesFBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformActive Directory Defenses Face an 11-Hour Race to Protect Tier 0Southern Company Portal Breach Exposes 400,000 Utility AccountsRegistry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustRansomware Recovery CEO Accused of Hiding Millions in Secret PaymentsAlleged Ploutus Developer Arrested as ATM Jackpotting Crackdown Reaches Malware LeadershipRogue AI Agents Tested Wikimedia's Boundaries and Tried to Turn Web Tools Into ProxiesPwn2Own Researchers Break 32 Zero-Days Across Phones, AI Systems and Smart DevicesEmergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack Radar
Security Insight

Ransomware Recovery CEO Accused of Hiding Millions in Secret Payments

Ransomware Recovery CEO Accused of Hiding Millions in Secret Payments
Photo by Tibe De Kort on Pexels

US prosecutors have charged the owner of ransomware remediation company MonsterCloud with allegedly misleading victims about how their encrypted data was recovered. The company is accused of secretly paying attackers for decryption keys while presenting its service as proprietary recovery technology, collecting more than $19 million from customers during the alleged scheme.

A criminal case involving a ransomware recovery provider is raising difficult questions about transparency, pricing and trust in the incident response industry.

Recovery service allegedly concealed ransom payments

Federal prosecutors have charged MonsterCloud owner Zohar Pinhasi with conspiracy to commit wire fraud and two counts of wire fraud. He has pleaded not guilty, and the allegations have not been proven in court.

According to the indictment, MonsterCloud marketed itself as having specialized tools and techniques capable of restoring ransomware-encrypted information without paying the criminals responsible. Prosecutors allege that the company's usual first step was instead to contact ransomware operators, purchase working decryptors and use those keys to recover customer data.

The alleged scheme operated between June 2018 and June 2023. Authorities claim the company facilitated more than $8 million in ransom payments while charging hundreds of organizations in the United States and Canada over $19 million for recovery and remediation work.

The pricing gap deserves attention

Two examples cited by prosecutors illustrate the potential financial impact. In one incident, MonsterCloud allegedly paid attackers about $8,200 but billed the customer approximately $150,000. In another case, it reportedly paid around $236,000 and charged roughly $380,000.

Paying a ransom through a professional negotiator is not automatically fraudulent. Some recovery contracts explicitly permit negotiations when other restoration methods fail. The central issue is whether customers were told what was happening, whether the service misrepresented its technical capabilities and whether its fees reflected the work actually performed.

What ransomware victims should require

  • Written disclosure of whether ransom negotiation or payment may occur.
  • An itemized record of payments, cryptocurrency transactions and service fees.
  • Independent verification that proposed decryptors work safely.
  • Sanctions and legal reviews before funds are transferred.
  • Preservation of forensic evidence for law enforcement and insurers.

In my view, ransomware victims should never have to guess whether a recovery provider developed a technical solution or simply bought a key from the attacker. Organizations are often making decisions under extreme pressure, but that makes contractual clarity more important, not less. Procurement teams should preapprove incident response partners before an emergency and insist on transparent payment and reporting procedures.

Talk to our team →

Latest

MatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesOct 9, 2026FBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformOct 9, 2026Active Directory Defenses Face an 11-Hour Race to Protect Tier 0Oct 9, 2026Southern Company Portal Breach Exposes 400,000 Utility AccountsOct 8, 2026Registry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustOct 8, 2026Ransomware Recovery CEO Accused of Hiding Millions in Secret PaymentsOct 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards