The U.S. Department of Justice (DoJ) announced charges on Wednesday against Zohar Pinhasi, a 50 year old U.S. and Israeli national, for his alleged role in a scheme to defraud victims of ransomware. Pinhasi, who operated under the aliases Zack Silver and Zack Green, is the owner of the firm MonsterCloud. The charges include two counts of wire fraud and one count of wire fraud conspiracy based on allegations that the firm billed clients over $19 million while secretly negotiating with cybercriminals.
According to federal authorities, Pinhasi claimed to use proprietary software and advanced laboratory techniques to recover encrypted data without paying ransoms. However, the DoJ alleges that MonsterCloud instead contacted the attackers directly to purchase decryptors. The firm then allegedly charged victims significant fees that far exceeded the actual ransom costs, presenting the results as the outcome of their own specialized technical processes. This practice misled organizations into believing they were avoiding financial support of criminal enterprises while the firm allegedly pocketed the difference.
For IT directors and operations leaders, this case highlights the risks associated with third party recovery services that claim to bypass encryption without official keys. The legal action underscores the importance of verifying the methodologies used by data recovery firms and maintaining transparency during incident response efforts. Organizations rely on these providers to navigate complex security breaches, making the integrity of their technical claims a critical factor in recovery strategies.
The BroadVision view
This incident reinforces the need for rigorous due diligence when selecting partners for incident response and data recovery. IT leaders should prioritize providers that offer transparent methodologies and verifiable technical processes to ensure recovery efforts align with organizational ethics and legal requirements. Organizations can improve their resilience by focusing on proactive strategic IT services to mitigate risks before a breach occurs.
