Critical

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The Hacker News

Overview

Zohar Pinhasi, also known by aliases Zack Silver and Zack Green, faces serious charges from the U.S. Department of Justice for allegedly defrauding victims of ransomware attacks. He is accused of secretly paying ransoms to cybercriminals to obtain decryption keys while misleading clients into believing he was using special tools for data recovery. This scheme reportedly generated over $19 million in fraudulent billing. The case raises significant concerns about the ethics of cybersecurity services and the trustworthiness of companies claiming to assist ransomware victims. It highlights the potential for exploitation in the cybersecurity industry, where victims are often desperate for solutions to regain access to their critical data.

Key Takeaways

  • Affected Systems: Ransomware victims, cybersecurity service users, MonsterCloud customers
  • Action Required: Victims should thoroughly vet cybersecurity providers and verify their claims regarding data recovery methods.
  • Timeline: Disclosed on October 25, 2023

Original Article Summary

The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire

Impact

Ransomware victims, cybersecurity service users, MonsterCloud customers

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on October 25, 2023

Remediation

Victims should thoroughly vet cybersecurity providers and verify their claims regarding data recovery methods.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Ransomware, Critical.

Related Coverage

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

The Hacker News

On October 8, the FBI, along with agencies from six other countries, reported that hackers linked to a Chinese cybersecurity company, Integrity Technology Group, have been stealing emails from various organizations in Southeast Asia. These include government bodies, law enforcement, healthcare systems, and religious institutions. The hackers exploited vulnerabilities in websites to gain access to sensitive information. The U.S. and the UK have already imposed sanctions on Integrity Technology Group due to its involvement. This incident raises concerns about the security of critical sectors and the potential for sensitive data to be misused, highlighting the ongoing risks posed by state-sponsored cyber activities.

Oct 8, 2026

FakeGit malware campaign returns with 17,610 malicious GitHub repos

BleepingComputer

A resurgence of the FakeGit malware campaign has been reported, with over 17,000 fake repositories on GitHub found to be distributing SmartLoader malware. This campaign has been reactivated to push the StealC infostealer, which is designed to steal sensitive information from users. Researchers indicate that both developers and users who download or interact with these fraudulent repositories are at risk. The situation is concerning because it not only affects individual users but also poses a threat to organizations that rely on GitHub for software development. The presence of such a large number of malicious repositories underlines the need for vigilance in verifying the legitimacy of software sources.

Oct 8, 2026

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

The Hacker News

A rise in personal data leaks has been reported in Japan, attributed to attackers exploiting mobile application APIs and known software vulnerabilities. The JPCERT Coordination Center issued an alert on October 8, 2026, based on various incident reports but did not name specific organizations or attackers involved. This increase in data breaches raises concerns for both consumers and businesses, as personal information may be exposed or misused. Organizations need to review their API security and address any software flaws to prevent further incidents. Users should be vigilant about their personal data privacy as these vulnerabilities can lead to significant risks.

Oct 8, 2026

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Hacker News

UAC-0099, a Russia-aligned hacking group, has been linked to a new malware called ASHVEIN, which functions as both an infostealer and a remote access trojan (RAT). This malware is currently being used in targeted attacks against Ukrainian government personnel. Researchers from TrendAI, who are tracking this activity under the name Earth Sirrush, report that ASHVEIN disguises its commands within HTML, making it harder to detect. This development raises concerns about the security of government systems in Ukraine, particularly given the ongoing geopolitical tensions in the region. As these attacks evolve, it highlights the need for enhanced cybersecurity measures among officials and government staff.

Oct 8, 2026

SonicWall and Splunk Patch Critical Vulnerabilities

SecurityWeek

SonicWall and Splunk have recently addressed serious vulnerabilities that could let attackers bypass authentication, execute arbitrary code, or gain higher privileges on affected systems. These vulnerabilities are critical and high-severity, meaning they pose significant risks to organizations using these products. The flaws affect various versions of SonicWall's firewall software and Splunk's data analytics platform, making it essential for users to apply the patches as soon as possible. If left unaddressed, these vulnerabilities could lead to unauthorized access and manipulation of sensitive data. Organizations using these services should prioritize updating their systems to protect against potential exploitation.

Oct 8, 2026

ASOS links data breach to social engineering attack, credential theft

BleepingComputer

ASOS has confirmed that it recently experienced a data breach linked to a social engineering attack, which led to the theft of customer credentials. The company is actively notifying affected customers about the incident, which involved unauthorized access to personal data. This breach raises concerns about the security measures in place to protect user information, especially given the rise in social engineering tactics that trick individuals into revealing sensitive data. Customers are advised to monitor their accounts for any suspicious activity and to change their passwords as a precaution. The incident serves as a reminder of the vulnerabilities that can arise from social engineering and the importance of maintaining strong security practices.

Oct 8, 2026