The United States Department of Justice has charged a man with fraud after he allegedly told clients he could decrypt files locked up by ransomware but actually paid ransoms – and seemingly got away with it for years.
The Feds allege that Zohar Pinhasi – aka “Zack Silver” and “Zack Green” – ran a Florida company called “MonsterCloud” that advised ransomware victims not to pay because it had a way to recover encrypted data.
“The charges relate to Pinhasi’s claimed ability to decrypt ransomware without paying cybercriminals, purportedly using ‘proprietary tools’ and ‘advanced decryption techniques’ on behalf of distressed business owners who came to his company,” according to a DoJ press release. “In fact, Pinhasi allegedly used a portion of his clients’ fees to pay off the ransomware attackers, and then kept the rest, often extracting a substantial markup.”
In one case, Pinhasi allegedly charged his client $150,000, paid the $8,200 ransom, and pocketed the rest – but didn’t admit he had paid the ransom.
That scheme allegedly worked so well that Pinhasi charged clients more than $19 million and paid more than $8 million in ransom payments.
The DOJ’s indictment [PDF] says MonsterCloud’s website mentions its use of “advanced decryption techniques and cutting-edge technology” – the same language found on this monstercloud.com page.
The site also contains this claim: “At MonsterCloud, we are not a team of IT Experts. We are the most sophisticated Counter Cyber Terrorism team in the world.”
The indictment suggests MonsterCloud was nothing of the sort, and that its claims rang hollow for years.
“MonsterCloud’s website included ‘testimonials’ and other promotional content, including from at least one compensated spokesperson,” the indictment states. “In May 2019, one such spokesperson – an individual who had provided a paid testimonial for the MonsterCloud website – contacted the defendant Zohar Pinhasi with questions about Pinhasi’s business practices and truthfulness.”
“Among other things, the spokesperson asked Pinhasi whether MonsterCloud actually had any proprietary software that would allow MonsterCloud to decrypt encrypted data. Pinhasi responded: ‘MonsterCloud doesn’t hold any proprietary technology [to] decrypt the ransomware data.’”
Pinhasi faces two counts of wire fraud, and one of wire fraud conspiracy. He could do twenty years on each count, if convicted.
The FBI is investigating this case, and it appears further charges could follow as the indictment states Pinhasi had “multiple co-conspirators, individuals whose identities are both known and unknown to the Grand Jury, including MonsterCloud employees and contractors.” ®