LIVE · cybersecurity feed
Live wire
ransomware

MonsterCloud CEO Zohar Pinhasi Accused of Paying Hackers, Defrauding Victims

Reports indicate that the U.S. Department of Justice (DOJ) has brought accusations against Zohar Pinhasi, the CEO of MonsterCloud, alleging a scheme that involved paying ransomware operators for decryption keys while simultaneously defrauding the victims. The core of the accusation centers on Pinhasi's alleged practice of secretly negotiating with and paying ransomware gangs, then charging the…

ZeroDay News ·

Source: HackRead

Reports indicate that the U.S. Department of Justice (DOJ) has brought accusations against Zohar Pinhasi, the CEO of MonsterCloud, alleging a scheme that involved paying ransomware operators for decryption keys while simultaneously defrauding the victims. The core of the accusation centers on Pinhasi's alleged practice of secretly negotiating with and paying ransomware gangs, then charging the affected organizations for recovery services without disclosing the nature of these payments.

This alleged scheme would involve MonsterCloud presenting itself as a cybersecurity incident response firm assisting victims of ransomware attacks. Instead of solely relying on internal recovery methods or publicly available decryption tools, Pinhasi is accused of engaging directly with the attackers to obtain the necessary keys. This practice, if proven, represents a significant ethical and potentially legal breach within the incident response industry.

The technical mechanism at play here is not an exploit or a vulnerability in software, but rather a deceptive business practice leveraging the existing ransomware ecosystem. Ransomware attacks typically involve encrypting an organization's data and demanding a cryptocurrency payment for a decryption key. Incident response firms are often engaged to help victims navigate this crisis, which can include assessing the damage, containing the spread, and recovering data, sometimes through decryption.

The affected parties in this scenario are primarily the victims of ransomware attacks who engaged MonsterCloud's services. These organizations, already in a vulnerable state, would have been led to believe they were receiving a legitimate, transparent recovery service. The alleged fraud lies in the undisclosed payments to the attackers and the potential markup or misrepresentation of the recovery costs.

Mitigation guidance for organizations facing ransomware attacks typically emphasizes robust backup strategies, strong network segmentation, multi-factor authentication, and comprehensive incident response plans. When engaging third-party incident response firms, due diligence is paramount. Organizations should seek firms with clear ethical guidelines, transparent billing practices, and a strong reputation for integrity. It is crucial to understand the firm's approach to data recovery, including whether they advocate for or engage in ransom payments, and under what circumstances.

This reported incident, if substantiated, highlights a concerning potential conflict of interest within the cybersecurity incident response sector. The industry relies heavily on trust, especially when dealing with organizations under duress from cyberattacks. Any practice that involves undisclosed dealings with malicious actors, particularly when charging victims for services, erodes that trust and can complicate law enforcement efforts to disrupt ransomware operations.

The broader context of this accusation touches upon the ongoing debate within the cybersecurity community regarding paying ransoms. While law enforcement agencies generally advise against paying ransoms to avoid funding criminal enterprises, some organizations, under immense pressure, choose to pay to recover critical data. The alleged actions of MonsterCloud's CEO introduce a new dimension to this debate, focusing on the ethics and transparency of third-party intermediaries in such situations.

ransomwarecloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

FBI Arrests Founder of Ransomware Negotiation Firm

Federal agents have arrested a Canadian cybersecurity professional in Pennsylvania, linking him to an ongoing investigation into the ShinyHunters hacking group. Edward Dubrovsky, co-founder of the Canadian firm CyberSteward, was taken into custody on October 8, facing charges of conspiracy to threaten to impair the confidentiality of information with intent to extort money, and interference…

ransomware

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

saashigh

ASOS Breach Reveals the Risks in Customer-Facing SaaS

A recent security incident involving the British online fashion retailer ASOS has brought to light the inherent risks associated with customer-facing Software-as-a-Service (SaaS) platforms. The breach reportedly showcased how the compromise of a single user identity could serve as an initial access vector, subsequently allowing attackers to achieve broad penetration into a company's internal…

patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.