← All posts

The Vendor Who "Never Pays Ransoms" Allegedly Paid Them All

Imagine the worst week of your company's life. Your files are encrypted, operations are stalled, and a ransom note is on the screen. You hire a specialist firm that promises it can unlock your data using proprietary tools, with no need to deal with the criminals.

Now imagine that firm quietly bought the decryption key from those same criminals and billed you many times what it paid.

That is what federal prosecutors allege in a case announced Wednesday. The Justice Department charged Zohar Pinhasi, 50, owner of Florida-based MonsterCloud, with two counts of wire fraud and one count of wire fraud conspiracy. A federal grand jury in the Eastern District of New York indicted him on September 23. These are allegations. Mr. Pinhasi has pleaded not guilty and has not been convicted. He has previously denied misleading customers.

What prosecutors allege

According to the charges, MonsterCloud told victims it had advanced decryption techniques and could recover data without paying attackers. Prosecutors say no such tools existed. Instead, the company allegedly contacted the criminals, paid for decryption keys, and used them to restore files. It allegedly did this without telling clients, even though contracts reportedly said it would approach attackers only if other methods failed.

The reported numbers are striking. Over roughly five years ending in 2023, the company allegedly billed hundreds of U.S. and Canadian businesses more than $19 million while paying more than $8 million in ransoms. In one August 2023 example, it allegedly paid about $8,200 and charged the client about $150,000. In another, from 2021, it allegedly paid about $236,000 and charged about $380,000.

Prosecutors say decrypted sample files were used as "recovery proofs" to convince victims the firm's technology worked. The company's own success, in other words, allegedly came from the criminals' key.

U.S. Attorney Joseph Nocella Jr. said the defendant "re-victimized his clients while extracting a hefty profit for himself." The FBI's James Barnacle Jr. said Pinhasi "claimed to fix ransomware while never remediating the underlying threat."

Why this belongs on a board agenda

Whatever the outcome in court, this case exposes a gap that most boards never examine: the incident response vendor is the person you trust most at the moment you are least able to check their work.

In Cyber Risk Is Business Risk, I argue that every executive should be able to answer three questions about cyber risk: What are we trying to protect? What could go wrong? And what are we doing about it? This case is a reminder that the third answer often includes a vendor, and that "what are we doing about it" has to cover how that vendor operates, not just whether you have one.

Consider four angles.

First, the ransom decision belongs to you. Paying a ransom is a legal, financial, regulatory, and reputational decision. It can raise sanctions questions, insurance questions, and disclosure questions. If a vendor makes that decision for you without telling you, your organization has taken on all of that exposure without ever deciding to. A board that has debated its ransom posture in advance, and written it down, is far harder to quietly route around.

Second, compliance is not security, and a signed contract is not assurance. A retainer agreement promising to avoid contact with criminals unless necessary looks like diligence. It is only meaningful if someone can verify what actually happened. Most organizations never ask to see the vendor's actual actions during an incident, and many vendors would resist handing over negotiation records.

Third, the budget conversation. When a vendor's incentive is to bill as much as possible against a ransom they can quietly pay for less, price becomes a signal worth examining. A multiple of 18 times the underlying demand, as in the August 2023 example, is the kind of number a finance committee should be able to question after the fact. Ask whether your incident response invoices separate the vendor's labor from any payment made on your behalf.

Fourth, personal liability. Directors and officers are increasingly expected to show they exercised reasonable oversight of significant risks. "We hired an expert and trusted them" is a weaker position than "we hired an expert, defined what they were authorized to do, and required reporting on it."

What to ask your CISO this week

You do not need to be technical to ask these questions. You need to ask them before an incident, when the answers are cheap.

  1. Who is our incident response and ransomware negotiation provider, and what does our agreement say about contacting attackers or paying a ransom? Is the authority to pay explicitly reserved to named executives?
  2. If our vendor communicates with an attacker, how and when are we told? Will we receive a complete record of every message and payment, in real time or after the fact?
  3. How do we verify claims about "proprietary" recovery tools? Has anyone independent reviewed what the vendor does, or are we relying on marketing?
  4. Do we have a documented ransom-payment policy that covers legal counsel, insurer involvement, sanctions screening, and board notification?
  5. Do our invoices distinguish professional fees from third-party payments?
  6. Have we tested our backups recently enough that a decryption key is never our only path to recovery? The best defense against a vendor who profits from your desperation is not being desperate.

The larger lesson

Cybersecurity has a trust problem that technology alone cannot solve. We hand extraordinary access and extraordinary discretion to outside specialists during moments of crisis. Most of them are honest and skilled. Some allegedly are not, and this is not the first recent case involving someone in the ransomware response industry accused of working both sides.

Boards do not need to become forensic experts. They need to treat vendor oversight in a crisis the way they treat any other high-stakes delegation: define the authority, demand the records, and verify before they need to rely on it.