discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Ransomware recovery CEO charged over secret ransom payments

MonsterCloud CEO charged with fraud for secretly paying ransomware attackers, charging victims up to $19 million for recovery services.

By Lawrence Abrams·Oct 7·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Ransomware recovery CEO charged over secret ransom payments
Image: bleepingcomputer.com

MonsterCloud CEO Zohar Pinhasi faces up to 20 years in prison for allegedly defrauding ransomware victims by secretly paying attackers for decryption keys.

Why it matters

This case highlights the ongoing challenges in the ransomware recovery industry and the need for transparency and accountability.

A company called MonsterCloud helped people who got their files locked up by bad guys. But they secretly paid the bad guys to unlock the files, and then charged people a lot of money to do it. Now the people in charge of MonsterCloud are in big trouble for tricking people.

Analysis

{"heading_1":"The Alleged Scheme","paragraph_1":"Similar concerns were raised in a 2019 ProPublica investigation, which reported that MonsterCloud sometimes paid ransomware operators while claiming to offer a solution other than paying the attackers.","paragraph_2":"Security researcher Fabian Wosar and another researcher created their own ransomware and approached several recovery companies, including MonsterCloud, while posing as victims.","paragraph_3":"The researchers provided the recovery firms with ransom notes containing email addresses they controlled for the fake ransomware gang, leading to anonymous messages offering to pay the ransom.","heading_2":"The Victims' Perspective","heading_3":"Industry Concerns and Previous Investigations","paragraph_4":"MonsterCloud's CEO, Zohar Pinhasi, disputed that the company had promised in advance it could decrypt the files and denied misleading customers.","paragraph_5":"Pinhasi also told ProPublica that MonsterCloud's recovery methods varied by case and declined to disclose them, describing the techniques as a 'trade secret'."}

Key points

  • MonsterCloud CEO Zohar Pinhasi faces up to 20 years in prison for allegedly defrauding ransomware victims.
  • The company allegedly charged victims up to $19 million for recovery services while facilitating over $8 million in ransom payments.
  • Similar concerns were raised in a 2019 ProPublica investigation, highlighting the need for transparency and accountability in the industry.
The Upside

This case may lead to stricter regulations and better practices in the ransomware recovery industry, helping to prevent similar issues in the future.

The Downside

If this case doesn't lead to changes, it could encourage more ransomware operators to try similar tactics, putting more people at risk.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityransomwarefraudrecoverycybercrime

Author

Lawrence Abrams

Intelligence analysis by

Qwen 2.5 (3B)

Published

Oct 7, 2026

Source

bleepingcomputer.com

Share

Topics

securityransomwarefraudrecoverycybercrime

Related

More from this desk

Oct 7·wired.com

Shaq Got Hacked. Now He’s Pitching for a VPN

Shaq talks about his experience with cyber security and the importance of personal privacy. NordVPN is helping him raise awareness.

Oct 7·bleepingcomputer.com

FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins

FBI warns of ongoing FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways, locking out legitimate administrators.

Oct 7·bleepingcomputer.com

Hackers Hijack Google Domains After Breaching ccTLD Registries

Hackers obtained unauthorized HTTPS certificates for Google domains and hijacked ccTLD domains for Ghana, American Samoa, and Sierra Leone. Google blocked unauthorized certificates and notified affected organizations.

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.