Ransomware consultant said he would decrypt data, is accused of paying ransoms instead

Computerworld · · g5128581

Ransomware consultant said he would decrypt data, is accused of paying ransoms instead

The owner of a ransomware remediation company is facing trial for defrauding customers. Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” has been arraigned in New York on wire fraud charges for allegedly defrauding clients of his ransomware remediation company, MonsterCloud. Pinhasi falsely claimed he could recover documents encrypted by ransomware without paying a ransom, according to district attorney Joseph Nocella. “The defendant re-victimized his clients while extracting a hefty profit for himself,” Nocella said. MonsterCloud claimed to offer an alternative to paying the ransom. Its website said that, thanks to its decryption techniques, “our team specializes in helping businesses recover their data without succumbing to ransom demands.”  However, the indictment alleges that rather than using any technology, Pinhasi simply paid the cybercriminals in exchange for a decryption key with which MonsterCloud employees would then an attempt to unlock their clients’ files. It is alleged that Pinhasi typically charged clients a fee that was substantially higher than the ransom payment. For example, in 2023, he made a payment of $8,200 to a cybercriminal while charging a client $150,000. There may be several reasons why clients chose to use MonsterCloud. US government advice (echoed by other governments) is not to pay ransoms as it may encourage more attacks, and victims may not get their data back. In addition, in some cases, if the attackers are from a country or group subject to trade sanctions, making a payment may actually be illegal , leaving the victim facing criminal charges. There may be other factors at play. “Cases vary; sometimes negotiators simply overcharge for their services. In other cases, they may inflate the final amount, saying, for instance, that 50 percent extra is to ensure a third-party validation of secure data erasure or something similar that the client would buy,” said Ilia Kolochenko of cybersecurity company ImmuniWeb. He warned that there were several techniques being used to extract additional money from ransomware victims. “Some will be contacted by fake law enforcement agencies, which typically promise to find and arrest the hackers, but also mention the victim’s civil liability for the data breach and ask to prepay a bond for an eventual regulatory fine. Other victims may be contacted by fake cybersecurity companies, which claim that they have already found their stolen data on the Dark Web and ask for money to ‘securely erase’ the data from the dark web to avoid bad publicity and regulatory sanctions,” he said. Similar cases have come to court recently, said Kolochenko, one in July involving a Florida business and another targeting a Latvian national in May. This article first appeared on CSO .

The owner of a ransomware remediation company is facing trial for defrauding customers. Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” has been arraigned in New York on wire fraud charges for allegedly defrauding clients of his ransomware remediation company, MonsterCloud. Pinhasi falsely claimed he could recover documents encrypted by ransomware without paying a ransom, according to district attorney Joseph Nocella. “The defendant re-victimized his clients while extracting a hefty profit for himself,” Nocella said. MonsterCloud claimed to offer an alternative to paying the ransom. Its website said that, thanks to its decryption techniques, “our team specializes in helping businesses recover their data without succumbing to ransom demands.”  However, the indictment alleges that rather than using any technology, Pinhasi simply paid the cybercriminals in exchange for a decryption key with which MonsterCloud employees would then an attempt to unlock their clients’ files. It is alleged that Pinhasi typically charged clients a fee that was substantially higher than the ransom payment. For example, in 2023, he made a payment of $8,200 to a cybercriminal while charging a client $150,000. There may be several reasons why clients chose to use MonsterCloud. US government advice (echoed by other governments) is not to pay ransoms as it may encourage more attacks, and victims may not get their data back. In addition, in some cases, if the attackers are from a country or group subject to trade sanctions, making a payment may actually be illegal , leaving the victim facing criminal charges. There may be other factors at play. “Cases vary; sometimes negotiators simply overcharge for their services. In other cases, they may inflate the final amount, saying, for instance, that 50 percent extra is to ensure a third-party validation of secure data erasure or something similar that the client would buy,” said Ilia Kolochenko of cybersecurity company ImmuniWeb. He warned that there were several techniques being used to extract additional money from ransomware victims. “Some will be contacted by fake law enforcement agencies, which typically promise to find and arrest the hackers, but also mention the victim’s civil liability for the data breach and ask to prepay a bond for an eventual regulatory fine. Other victims may be contacted by fake cybersecurity companies, which claim that they have already found their stolen data on the Dark Web and ask for money to ‘securely erase’ the data from the dark web to avoid bad publicity and regulatory sanctions,” he said. Similar cases have come to court recently, said Kolochenko, one in July involving a Florida business and another targeting a Latvian national in May. This article first appeared on CSO .

Источник: Computerworld