Ransomware recovery firm accused of paying hackers and profiting from clients' fees
The US Department of Justice has charged Zohar Pinhasi, operating MonsterCloud, with fraud for allegedly deceiving clients by claiming to decrypt files without paying ransom. Instead, the company reportedly paid hackers a portion of the fees and kept the rest, charging over $19 million in total while paying just over $8 million in ransom payments. Evidence suggests MonsterCloud used samples from ransomware operators as proof of decryption ability, despite not having proprietary tools.
GoKawiil's interpretation of the reporting above, not reported fact.
This case highlights potential risks of trusting third-party recovery services that may not be transparent about their methods. It suggests that some companies could be exploiting victims by paying ransom on their behalf and profiting without genuine technical solutions, which could undermine efforts to discourage ransom payments and promote better cybersecurity practices.
- MonsterCloud allegedly paid hackers using client fees and kept the rest.
- The DOJ charges the company with fraud for misrepresenting its decryption capabilities.
- The case raises concerns about the integrity of ransomware recovery services.
Source: techspot.com — Rob Thubron, 2026-10-08
Published there as: “Ransomware recovery firm claimed it could decrypt files, but may have just paid hackers and pocketed the difference”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.