Cyber Firm Owner Accused of Defrauding Clients in Ransomware Cases
Translated & summarized from 0404 by baba
Israeli-American businessman Zohar Panhasi is accused in the U.S. of defrauding clients through his cyber company, MonsterCloud. The company allegedly claimed to decrypt ransomware-locked data without paying attackers but secretly paid hackers and charged clients vastly inflated fees. In one case, $8,200 paid to hackers resulted in a $150,000 charge to a client. Hundreds of companies allegedly paid over $19 million in total for these misrepresented services, and Panhasi now faces legal proceedings.
The story in 5 lines · by baba
- Zohar Panhasi, owner of Florida-based MonsterCloud, is accused of defrauding clients in ransomware recovery cases.
- The company allegedly paid hackers secretly and charged clients significantly higher fees, misrepresenting the recovery method.
- One client was charged $150,000 after the company paid hackers only $8,200 for decryption keys.
- Hundreds of companies reportedly paid over $19 million in total for these allegedly deceptive services.
- Panhasi faces legal proceedings in the U.S. over the alleged systematic deception and inflated charges.
Zohar Panhasi, a 50-year-old Israeli-American businessman who owns a cyber company based in Florida, is at the center of a large-scale fraud scheme uncovered in the United States. According to the indictment, Panhasi presented to his clients that his company possessed advanced capabilities to recover data locked by ransomware attacks without needing to pay the attackers. However, the prosecution alleges that behind the scenes, a completely different method was employed.
Instead of decrypting the data through specialized technological tools, the company secretly paid hackers, obtained decryption keys from them, and then charged clients significantly higher amounts than what was actually paid to the attackers. The company, MonsterCloud, marketed itself as capable of handling one of the most severe cyber threats: ransomware attacks that disable computer systems and lock sensitive business information. Clients were led to believe the company had technological capabilities to restore data without succumbing to ransom demands.
The prosecution claims that in reality, some incidents were resolved much more simply by direct payment to the attackers. The company allegedly concealed this from clients, presenting the recovery as the result of advanced professional work, thereby creating a substantial gap between the actual cost of the solution and the amount charged. In one documented instance, MonsterCloud allegedly paid hackers approximately $8,200 for decryption keys but charged a client about $150,000 for handling the incident, with the client unaware that the solution involved paying the attacker and believing they were paying for advanced, unique cyber services.
The indictment describes a prolonged operation involving hundreds of companies affected by ransomware attacks, with clients collectively paying over $19 million for recovery services, crisis management, and data access restoration. The authorities contend that a significant part of the business model relied on misleading clients by concealing the fact that payments were being made to attackers and presenting it as advanced technological work. A key issue in the case will be the extent of transparency with clients, as misleading information about data recovery methods could have serious legal and financial implications.
This case highlights the complexities of the ransomware response market, where companies operate under immense pressure. The prosecution's claims, if proven, could lead to increased oversight of companies handling ransomware incidents, including mandatory disclosures about payments to attackers, fees, costs, and the actual methods used for resolution. Panhasi now faces legal proceedings in the U.S. to determine if clients were systematically misled and overcharged while the true nature of the incident resolution was hidden. The case is expected to draw significant attention in the cyber world due to the financial scale and the fundamental question it raises about the required transparency from companies managing ransomware crises.
