BREACH WATCH BRIEF High 💀 Breach

MonsterCloud Owner Charged with $19 M Fraud After Secretly Paying Ransomware Decryptors

The DOJ has indicted MonsterCloud’s owner for billing ransomware victims while covertly paying attackers to obtain decryption keys, exposing a critical gap in third‑party oversight. Organizations must tighten vendor risk controls to maintain audit‑ready evidence of due diligence.

SeverityHigh
Type💀 Breach
ConfidenceHigh
ReportedOct 8, 2026
Cloud & Infrastructure Providers Technology and cloud‑infrastructure providers Enterprises outsourcing ransomware response or data recovery Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

Zohar Pinhasi, owner of MonsterCloud, was charged with wire fraud for allegedly charging ransomware‑victim customers over $19 million while secretly paying the attackers to obtain decryptors, claiming the recovery was done with proprietary tools.

Why it matters for trust and compliance

  • This incident illustrates how weak vendor oversight can undermine trust and control‑assurance programs, emphasizing the need for transparent, auditable third‑party incident‑response policies.
  • Demonstrates the necessity of continuous monitoring of vendor financial and security activities to detect undisclosed ransom payments.
  • Highlights the importance of contractual safeguards and evidence collection for audit readiness when relying on external recovery services.

Who is affected

Technology and cloud‑infrastructure providers Enterprises outsourcing ransomware response or data recovery

Recommended actions

  1. Audit all vendor contracts for clauses prohibiting undisclosed ransom payments and require full disclosure of incident‑response procedures.
  2. Implement continuous monitoring of third‑party activities, including financial transaction alerts and security log reviews.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.