WTF?! Law enforcement agencies have long warned against paying ransomware gangs, given that they could simply demand more money, refuse to hand over a decryption key, or mark you as someone willing to pay. But it seems we might have to be cautious of companies offering to remedy these incidents, too: they could be as bad as the criminals themselves.

The United States Department of Justice has charged Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," with fraud. He ran a Florida-based company called MonsterCloud that told ransomware victims not to pay attackers because it had a way of decrypting their files – for a fee, of course.

But according to the DoJ, MonsterCloud wasn't using "proprietary tools" and "advanced decryption techniques" to achieve this feat; it was allegedly using a portion of its clients' fees to pay off the ransomware attackers, and then keeping the rest, often extracting a substantial markup.

One example case allegedly involves Pinhasi charging a client $150,000 to decrypt a system, paying the hackers $8,200 of that money, then keeping the rest, all without admitting he paid the ransom. In another case, he allegedly paid hackers approximately $236,000 and charged the customer about $380,000, according to prosecutors.

The indictment also alleges that MonsterCloud presented decrypted sample files as evidence of its ability to recover victims' data, despite obtaining those samples from the ransomware operators themselves.

It sounds like a scheme so obvious that it wouldn't work, but Pinhasi is said to have charged clients more than $19 million in fees while paying slightly more than $8 million in ransom payments.

MonsterCloud's website states that "At MonsterCloud, we are not a team of IT Experts. We are the most sophisticated Counter Cyber Terrorism team in the world."

The indictment certainly casts doubt on MonsterCloud's claims. Its website features testimonials and other promotional material, including endorsements from at least one paid spokesperson.

In May 2019, a spokesperson who had supplied a paid testimonial contacted Pinhasi to question his business practices and honesty, according to the indictment. The spokesperson asked whether MonsterCloud really did possess proprietary software capable of decrypting encrypted data. Pinhasi acknowledged that the company had no proprietary technology to decrypt data affected by ransomware.

Pinhasi has pleaded not guilty to the charges and was released on a $2 million bond.

A 2019 investigation by ProPublica into two data recovery firms found that they typically just paid the ransom and charged the victims extra. One of them was MonsterCloud. At the time, Pinhasi denied that MonsterCloud had promised in advance it could decrypt the files or had misled customers.