BREACH WATCH BRIEF High 💀 Threat intel

Ransomware Response Firm CEO Charged with Wire Fraud for Deceptive Data Recovery Services

U.S. prosecutors allege MonsterCloud’s CEO secretly paid ransomware groups to obtain decryptors while charging clients inflated fees, highlighting the risk of undisclosed third‑party actions. This underscores the need for verifiable vendor controls and audit‑ready evidence in ransomware response engagements.

SeverityHigh
Type💀 Threat intel
ConfidenceHigh
ReportedOct 8, 2026
Professional Services Professional services firms that engage ransomware recovery vendors Enterprises across multiple sectors relying on external incident response Unknown

What happened

From June 2018 through June 2023, MonsterCloud’s CEO Zohar Pinhasi allegedly negotiated directly with ransomware groups, paid $8 million in ransoms, and billed hundreds of U.S. and Canadian clients $19 million for a purported “proprietary recovery tool.” The indictment accuses him of wire fraud and conspiracy.

Why it matters for trust and compliance

  • The case illustrates how undisclosed third‑party activities can undermine trust and control assurance, emphasizing the importance of continuous vendor oversight and documented evidence of service delivery.
  • Demonstrates the need for continuous monitoring of third‑party ransomware response claims
  • Provides a concrete example of why audit‑ready evidence of vendor actions is essential

Who is affected

Professional services firms that engage ransomware recovery vendors Enterprises across multiple sectors relying on external incident response

Recommended actions

  1. Implement a formal third‑party risk program that requires vendors to provide verifiable proof of decryption services and financial transaction records

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.