Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

US charges ransomware 'fixer' for secretly paying $8M in ransoms

The US Department of Justice has charged a Florida-based ransomware recovery firm with defrauding clients of more than $19 million by secretly paying cybercriminals for decryptors instead of using proprietary tools.

TechnologyNewsRachel NwosuPublished: 8 October 20264 min readSources 8
US charges ransomware 'fixer' for secretly paying $8M in ransoms

The indictment, unsealed on Wednesday, accuses Zohar Pinhasi of running a scheme from June 2018 to June 2023. He is charged with two counts of wire fraud and one count of conspiracy.

Pinhasi operated a company called MonsterCloud, which advertised itself as a team of experts capable of recovering encrypted data without paying ransoms. The firm’s website claimed to use "advanced decryption techniques and state-of-the-art technology." In reality, prosecutors allege, the company had no such tools. Instead, Pinhasi and his associates contacted the attackers directly, paid the ransoms, and then kept the difference between the amount paid to the criminals and the amount billed to the victims. This gap formed the core of the alleged fraud, turning a security failure into a personal revenue stream for the firm’s leadership.

The disparity was stark.

In one case cited in the indictment, Pinhasi allegedly paid a ransomware gang approximately $8,200. He then charged the victim $150,000 for the service. In another incident around October 2021, the ransom payment was approximately $236,000, while the client was billed about $380,000. According to The Register, the total amounts involved were substantial: more than $19 million in charges to clients, with over $8 million going directly to ransomware operators.

U.S. Attorney Joseph Nocella Jr. for the Eastern District of New York stated that Pinhasi "re-victimized his clients while extracting a hefty profit for himself." An FBI Assistant Director, James C. Barnacle Jr., added that Pinhasi turned the victims' crisis into his own profit center. Pinhasi surrendered to authorities on Wednesday, pleaded not guilty, and was released on a $2 million bond.

The scheme relied on a specific deception regarding "recovery proofs." BleepingComputer reported that MonsterCloud would provide decrypted sample files to convince victims that their data was safe. However, the indictment suggests these samples came from the ransomware operations themselves, further masking the fact that a ransom payment had occurred. Some contracts did disclose that the company might communicate with cybercriminals, but prosecutors argue that dealing with attackers was usually the first step, not a last resort as the contracts implied.

This case highlights a growing trend in the ransomware ecosystem where the post-incident response phase has become a target for fraud. As ransomware attacks continue to surge, the pressure on IT teams to recover quickly creates an environment ripe for exploitation. The Register noted that Pinhasi’s website included testimonials from at least one compensated spokesperson. In May 2019, that spokesperson contacted Pinhasi with questions about his business practices. Pinhasi reportedly admitted at the time that MonsterCloud did not hold any proprietary technology to decrypt the data.

The broader context of ransomware threats has intensified in recent months. According to a report by Chain Store Age, ransomware attacks jumped 29% to hit a new quarterly high in the third quarter. GuidePoint Security reported that victims have risen 75% year over year. These statistics highlight the critical need for strong backup strategies and clear incident response protocols. Organizations are increasingly finding that their recovery options are compromised not just by the initial attack, but by the actors they hire to fix it.

Security experts have long warned that the ransomware economy extends beyond the initial encryption of files. The payment and negotiation phase is complex, and victims are often desperate enough to accept services from unverified providers. The MonsterCloud case acts as a cautionary tale about the importance of vetting third-party response teams. While the primary threat remains the ransomware group itself, the secondary layer of recovery services introduces its own risks and vulnerabilities.

Pinhasi faces up to 20 years in prison for each count of wire fraud if convicted. The FBI is continuing its investigation, and the indictment notes that there are "multiple co-conspirators, individuals whose identities are both known and unknown to the Grand Jury." The case is part of a broader effort by federal law enforcement to dismantle the infrastructure supporting ransomware operations, including the service providers that facilitate them.

For businesses, the lesson is clear: due diligence is essential when engaging external help during a cyber incident. The line between legitimate recovery and fraudulent exploitation can be thin, and the financial stakes are high. As industrial and critical infrastructure sectors continue to face rising cyber threats, the integrity of the response chain is just as important as the security of the network itself.

Comments 0

Sources

8
  1. 01Ransomware fixer claimed he could decrypt files, allegedly defrauded clients insteadEN
  2. 02MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt DataEN
  3. 03Ransomware recovery CEO charged over secret ransom paymentsEN
  4. 04Ransomware has a new target. Is your backup ready?EN
  5. 05The State of Cybersecurity in 2026: Key Segments, Insights, and InnovationsEN
  6. 06Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and ServersEN
  7. 07Building a safer path to autonomous industrial AIEN
  8. 08An energy-first cybersecurity platform for solar, storage and the gridEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Rachel Nwosu

Rachel Nwosu

AI, models and technology

Rachel Nwosu covers AI, models and technology for FLASH24, working from public model documentation, benchmark releases and repository histories rather than press summaries, and she skips announcements that arrive without reproducible numbers. She checks training-data claims against dataset cards and reruns reported metrics where code is available. She spends much of her week interviewing researchers and engineers, tracking model launch calendars, and comparing vendor benchmarks with independent evaluations. Outside the desk she runs 3D printers, restores old computers, and tests how models learn from internet junk. She does not publish benchmark figures she cannot trace to a source.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.