Federal prosecutors have charged the owner of a Florida-based ransomware recovery company with wire fraud over an alleged scheme in which clients were defrauded twice during a single crisis. Zohar Pinhasi, who owns MonsterCloud, is accused of covertly paying attackers' ransom demands behind his clients' backs — and then, prosecutors say, billing those same clients millions of dollars for a recovery that amounted to little more than buying decryption keys from the criminals who locked up their systems.
According to a Security Affairs report, Pinhasi, 50, is also said to have operated under the alias "Zack Silver" and other names. The charges are allegations; Pinhasi has not been convicted.
A double dip with a familiar shape
What makes this case resonate beyond one Florida defendant is the structure of the alleged betrayal. Ransomware incidents are, by design, moments of maximum organisational stress: systems are down, revenue is bleeding, and decision-makers are under pressure to restore operations fast. That is precisely when independent verification collapses and vendors are trusted on assertion rather than evidence.
A recovery firm that pays the ransom in secret is exploiting the one thing a victim cannot easily check — whether the returned data came from a decryption key purchased from criminals or from backups and forensic work. Clients rarely have visibility into the method, only the outcome. That information asymmetry is the vulnerability the alleged scheme weaponised.
What Hong Kong firms should check before signing
The following is editorial analysis prompted by this case. No specific Hong Kong organisation is known to be implicated in the matter.
The case carries a general lesson for organisations across the region that rely on managed service providers (MSPs) and incident-response vendors. The vetting discipline applies broadly, and four checks are worth embedding in procurement and incident-readiness planning:
-
Ransom-payment authority. Establish in writing whether the vendor has standing authority to pay a ransom on your behalf, and who inside your organisation must approve it. A vendor that can pay without your consent can also profit from doing so. The contract should state that no payment will be made without documented, named approval.
-
Insurer and legal alignment. If you hold cyber insurance, confirm with your insurer which response vendors are pre-approved and what disclosure obligations apply to any ransom payment. Some policies restrict or require notification of payments; sanctions screening may also be required. Ask your insurer directly — do not rely on the vendor's summary.
-
Backup verification claims. Any provider asserting that data was recovered from backups should be able to demonstrate, in a scheduled test you commission independently, that backups exist, are immutable or air-gapped, and restore within an agreed window. "We recovered your data" is an assertion; a restore log and integrity hashes are evidence.
-
Fee transparency. Push for fee structures that decompose cleanly into triage, forensic work, restoration labour, and any third-party costs — including any ransom-related disbursement, which should always appear as a separate, pre-approved line item. Opaque, single-figure "recovery packages" are harder to audit after the fact.
The procurement gap
The uncomfortable truth reflected in this case is that the firm you call during a crisis is rarely the firm you vet during calm. Vendor assessments for recovery services tend to be lighter than those applied to, say, core infrastructure providers, precisely because the service feels episodic rather than continuous.
That should invert. A recovery vendor holds privileged access to your most damaged systems at your most vulnerable moment. It deserves the same — or greater — scrutiny as any other critical supplier, refreshed annually and rehearsed before an incident forces the question.
For organisations that want a starting point, the original report is available via Security Affairs.
聯邦檢察官已就一項被指的欺詐計劃,對佛羅里達州一間勒索軟件復原公司的東主提出電匯詐騙指控,指客戶在同一場危機中兩度受騙。MonsterCloud 東主 Zohar Pinhasi 被指控暗中代客戶向攻擊者支付贖金;檢察官指,其後他又就這場所謂復原向同一批客戶收取數百萬元,而該項復原實際上不過是向鎖定其系統的罪犯購買 decryption key 而已。
據 Security Affairs 報道,50 歲的 Pinhasi 又被指曾以「Zack Silver」等化名行事。上述指控尚未經法院審理;Pinhasi 尚未被定罪。
似曾相識的雙重取利手法
這宗案件之所以超出一名佛州被告的個案範疇而引起廣泛關注,在於其所涉背叛行為的結構。勒索軟件事件本質上是機構壓力最大的時刻:系統停擺、收入流失、決策者面臨盡快恢復運作的壓力。正正就是在這個時候,獨立核實機制會全面崩塌,企業傾向以供應商的說法而非證據作為信任基礎。
一間秘密支付贖金的復原公司,利用的正是受害者無法輕易查證的一點——交還的數據究竟來自向罪犯購買的 decryption key,還是來自備份及取證工作。客戶往往對復原方法一無所見,只能看到結果。這種資訊不對稱,正是該項被指存在的欺詐計劃所利用的漏洞。
香港企業簽約前應查證的事項
以下內容為因本案而引發的編輯分析。暫未知道有任何特定香港機構涉及此案。
本案對各地區依賴 managed service providers(MSP)及 incident-response 供應商的機構具有普遍警示意義。此類審核紀律同樣適用,以下四項查證值得納入採購流程及事件應急預案:
-
贖金支付授權。 應以書面形式確認供應商是否擁有代你支付贖金的常設授權,以及機構內部須由誰批准。能夠在未經你同意下付款的供應商,亦可從中牟利。合約應訂明,未經具名的書面批准,不得作出任何付款。
-
與保險及法律團隊協調。 若你持有 cyber insurance,應向保險公司確認哪些應對供應商屬 pre-approved,以及任何贖金支付涉及哪些披露責任。部分保單限制付款或要求就付款作出通知;亦可能需要進行制裁名單篩查。應直接向保險公司查詢,不要依賴供應商的摘要。
-
備份復原聲明。 任何聲稱數據是從備份復原的服務供應商,應能在由你獨立委託的定期測試中證明:備份確實存在、具不可更改(immutable)或 air-gapped 特性,並可在約定時間內完成還原。「我們已為你復原數據」只是一項聲明;還原紀錄及完整性 hash 才是證據。
-
收費透明度。 應力爭收費架構能清晰拆分為分類處理、forensic 工作、復原人手及任何第三方成本——其中包括任何與贖金相關的支出,該等支出應始終列為獨立及預先批准的項目。模糊不清、單一數字的「復原套餐」,事後難以審計。
採購環節的缺口
本案反映出一個令人不安的事實:你在危機中致電求助的公司,往往不是你在平靜時認真審核的公司。復原服務的供應商評估,通常比核心基礎設施提供商等類別寬鬆得多,正因為此類服務予人感覺是間歇性而非持續性。
這種情況應予扭轉。復原供應商在你最脆弱的時刻,對受損最嚴重的系統擁有特權存取權限。它理應接受與任何其他關鍵供應商相同、甚至更嚴格的審核,每年更新評估,並在事件發生迫使其面對問題之前先行演練。
如欲了解詳情,原始報告可透過 Security Affairs 查閱。
