Business

MonsterCloud charges expose risk in ransomware recovery market

US charges against MonsterCloud’s owner over secretly paid ransoms are a warning for UK firms buying incident response and recovery services.

Scales of justice graphic with the headline Ransomware recovery firm boss charged with fraud

The owner of a US ransomware recovery firm is accused of selling “decryption” that was really a quietly paid ransom with a large markup on top. For UK boards, insurers and procurement teams, the case is a sharp reminder that the incident response market needs the same scrutiny as any other critical supplier.

What happened

US federal prosecutors have charged Zohar Pinhasi, the 50-year-old owner of Florida-based MonsterCloud, with conspiracy to commit wire fraud and two substantive wire fraud counts. Pinhasi, a US and Israeli national, appeared before a New York court this week. Insurance Journal reports that the indictment was returned in September and that he was released after posting a $2 million bond.

MonsterCloud marketed itself to ransomware victims as a way out that did not involve paying criminals. Its website talked up proprietary tooling and advanced decryption. According to the Department of Justice, the reality was simpler and far more cynical: the company allegedly contacted the ransomware operators, bought the decryption key, and billed the client a fee far larger than the ransom, without telling them a payment had been made.

The figures cited across the coverage are consistent. Prosecutors allege that clients were charged more than $19 million while a little over $8 million went to criminals, leaving roughly $11 million as margin. One example in the indictment dates from August 2023, when an $8,200 ransom was allegedly paid and the client was invoiced $150,000. Each count carries a maximum of 20 years in prison. The Record says MonsterCloud did not reply when asked to comment, and the allegations have yet to be tested in court.

The detail

Perhaps the most damaging passage in the indictment, as reported by The Register, concerns a 2019 exchange with one of the firm’s own paid spokespeople. Asked directly whether MonsterCloud had software capable of decrypting ransomware, Pinhasi allegedly replied that the company did not hold any such technology. The firm’s marketing continued regardless.

None of this is entirely new. The Record notes that MonsterCloud featured in a 2019 ProPublica investigation into recovery firms that paid ransoms behind the scenes while charging steep fees, and that a former FBI deputy director who fronted the company told reporters at the time that paying was “the business model”. What is new is a grand jury indictment. The indictment also refers to multiple co-conspirators, including MonsterCloud employees and contractors, so further charges cannot be ruled out.

The Record also places the case in a wider pattern of US action against the murkier end of the recovery and negotiation trade, pointing to two ransomware negotiators who received four-year sentences in May after admitting to running their own attacks while supposedly representing victims.

Commercially, the alleged model relied on three things: a victim under severe time pressure, a technical claim the buyer could not verify, and a fixed fee that hid the real cost.

Flow diagram of the alleged MonsterCloud scheme, from victim contact through secret ransom payment to a marked-up invoice

Why it matters for UK organisations

The UK position on ransom payments is clear in principle. The NCSC’s ransomware guidance states that neither it nor UK law enforcement will encourage, endorse or condone paying, and warns that victims who pay are more likely to be targeted again. Its joint guidance with the ABI, BIBA and the IUA asks organisations to consider every recovery option first, keep a careful record of decisions, and draw on objective external experts.

The problem the MonsterCloud case exposes is that a victim can follow that advice to the letter, hire a third party specifically because it promises not to pay, and still end up funding criminals without knowing it. That has consequences for UK organisations that go beyond wasted money. If a payment reaches a sanctioned group, the victim may carry legal exposure. If an insurer is footing the bill, it may have been paying inflated invoices; Insurance Journal points out that the indictment does not say whether any victims were insured or whether insurers might pursue recovery.

There is also a policy dimension. In July 2025 the Home Office set out plans to ban public sector bodies and critical national infrastructure operators, including the NHS, councils and schools, from paying ransoms, and to require other businesses to notify government before paying. Computer Weekly reports that the proposed public sector ban appears to have lost momentum. Whatever its timetable, any such regime only works if organisations actually know when a payment has been made on their behalf. A supplier that disguises payments as “decryption” undermines both the ban and the reporting that underpins it.

Expert view

In my experience, the moment an organisation discovers encrypted servers is the worst possible time to start vetting suppliers. Claims about “proprietary decryption” sound plausible to a board that has never had to evaluate one. Genuine free decryptors do exist for some ransomware families, usually where researchers or law enforcement have found a flaw or seized keys, but they are the exception. For modern, well-run operations, a reputable responder will tell you plainly that recovery means backups, rebuilds or, in the last resort, a payment decision that you make knowingly.

When we test incident response readiness, the gap is rarely technical. It is contractual and procedural: no pre-agreed responder, no clarity on who authorises payments, and no requirement for the supplier to disclose how recovery was achieved. The NCSC already runs an assured Cyber Incident Response scheme, and recommends that UK organisations use an assured provider. Alongside insurer panels, that is a far better starting point than a search engine at 2am.

What to do now

  1. Pre-select your responder. Agree an incident response retainer or insurer panel provider before you need one, ideally from the NCSC-assured Cyber Incident Response scheme.
  2. Write transparency into the contract. Require the supplier to disclose in writing how data was recovered, whether any payment was made to a threat actor, and to whom. Make undisclosed payments a material breach.
  3. Separate the payment decision. Any ransom payment should need explicit sign-off from named executives after legal and sanctions checks, never delegated to a third party by default.
  4. Challenge decryption claims. Ask which ransomware families a supplier can decrypt, and on what basis. Vague answers citing “trade secrets” are a warning sign.
  5. Involve your insurer early. Report incidents through your policy’s notification route and use its approved providers, so invoices and decisions are scrutinised.
  6. Reduce the chance you ever face the choice. Cyber Essentials controls, particularly security update management, secure configuration and malware protection, close the routes most ransomware crews still rely on. Pair them with tested, offline or immutable backups, which the NCSC repeatedly stresses.
  7. Report to the authorities. UK victims should report ransomware through the official reporting route linked from the NCSC’s ransomware pages, whether or not a supplier is handling recovery.

Bottom line

The MonsterCloud allegations describe a supplier that sold victims exactly what they wanted to hear and quietly did the opposite. For UK organisations, the takeaway is not to distrust incident responders as a profession but to buy them as carefully as any other critical service: in advance, from assured or insurer-approved providers, under contracts that demand full disclosure of how recovery happened. Resilience includes knowing exactly where your money goes.

Sources

One thought on “MonsterCloud charges expose risk in ransomware recovery market”

Comments are closed.