MonsterCloud Owner Charged in Alleged $19M Ransomware Recovery Fraud

Federal prosecutors accuse MonsterCloud's owner of secretly paying ransomware attackers for decryptors while charging victims more than $19 million for recovery services.
Cybersecurity workstation illustrating federal allegations involving MonsterCloud ransomware recovery services and secret ransom payments.

The owner of Florida cybersecurity company MonsterCloud has been charged with allegedly turning ransomware victims into victims a second time, secretly paying their attackers for decryption keys while telling customers the company could recover encrypted data using proprietary technology.

Federal prosecutors say MonsterCloud charged ransomware victims more than $19 million during the alleged scheme while paying more than $8 million to cybercriminals behind the attacks.

In one case highlighted by prosecutors, the company’s owner allegedly paid an attacker approximately $8,200 for a decryption key in August 2023, then charged the affected customer approximately $150,000.

The company’s owner was arraigned in federal court in Brooklyn on Oct. 7 after a grand jury in the Eastern District of New York returned an indictment on Sept. 23. He faces 2 counts of wire fraud and 1 count of conspiracy to commit wire fraud.

A business built around not paying attackers

The allegations are particularly significant because MonsterCloud publicly positioned its ransomware recovery service as an alternative to paying cybercriminals.

According to the Justice Department, MonsterCloud told prospective customers that it could recover encrypted data without giving in to ransom demands. Prosecutors say the company promoted proprietary tools, advanced decryption techniques and technology that could supposedly restore victims’ files.

MonsterCloud’s website continues to advertise ransomware recovery services and warns organizations against paying attackers. The company describes itself as a ransomware recovery specialist and says its team can use multiple methods to restore encrypted data.

Federal prosecutors allege the reality was substantially different.

Rather than relying on special technology to decrypt affected systems, the company’s owner allegedly contacted the same cybercriminals responsible for encrypting the customer’s files and paid them for a decryption key.

MonsterCloud employees would then use the key in an attempt to decrypt the customer’s data, according to prosecutors.

The customer allegedly remained unaware that part of the recovery fee had been transferred to the ransomware operators.

Prosecutors allege substantial markups

The Justice Department says MonsterCloud frequently charged customers substantially more than the ransom secretly paid to obtain a decryptor.

The August 2023 transaction cited in the case provides one of the clearest examples. Prosecutors allege approximately $8,200 was paid to a cybercriminal while the ransomware victim was billed approximately $150,000.

Across the broader alleged scheme, prosecutors say MonsterCloud collected more than $19 million from customers and transferred more than $8 million in ransom payments.

That would leave a difference of more than $11 million between the amount allegedly collected from clients and the amount prosecutors say was transferred in ransom payments, although the indictment does not characterize that entire difference as profit. A ransomware recovery company can incur employee, infrastructure and other operating costs while responding to incidents.

The criminal allegations instead focus on whether customers were deceived about how their encrypted data was being recovered and whether the company’s representations influenced the money they paid.

Internal message undercuts proprietary technology claims

Prosecutors also cited an alleged 2019 exchange involving a spokesperson whose testimonial appeared on MonsterCloud’s website.

According to the Justice Department, the spokesperson asked whether MonsterCloud actually possessed proprietary software capable of decrypting ransomware.

The company’s owner allegedly acknowledged that MonsterCloud did not possess proprietary technology for decrypting the affected data.

That exchange could become important to the government’s case because prosecutors allege MonsterCloud was simultaneously marketing advanced or proprietary recovery capabilities to ransomware victims.

The Justice Department also said some testimonials appearing on the company’s website came from paid spokespersons.

Ransomware victims face a difficult recovery market

The case highlights a long-standing problem surrounding the ransomware recovery industry.

Organizations suffering a ransomware attack often need to make decisions while critical systems are offline, employees cannot access data and normal business operations are disrupted. That urgency can make victims dependent on outside incident response and recovery providers whose technical claims can be difficult to independently verify.

Some ransomware infections can be decrypted without paying attackers. Security researchers and law enforcement agencies periodically obtain encryption keys or identify weaknesses that allow free decryptors to be developed. Organizations may also restore systems from uncompromised backups.

Other ransomware families cannot be practically decrypted without access to keys controlled by the attackers.

Recovery companies can also legitimately negotiate or facilitate ransom payments when clients knowingly authorize that approach and applicable laws permit the transaction. The allegations against MonsterCloud center instead on prosecutors’ claim that customers were told the company could avoid paying attackers while ransom payments were allegedly being made without their knowledge.

The ransomware negotiation ecosystem has drawn increasing scrutiny as payments move between victims, intermediaries and criminal groups. In July, BreachNews reported on a separate case involving a ransomware negotiator who pleaded guilty to secretly assisting BlackCat attacks, demonstrating how individuals positioned between victims and attackers can become part of criminal investigations themselves.

FBI says victims were allegedly victimized again

The FBI characterized the MonsterCloud allegations as a case in which organizations already dealing with ransomware were exploited during the recovery process.

Federal investigators allege the company failed to remediate the underlying threat in the manner represented to customers and instead converted ransomware incidents into a source of substantial revenue.

The Justice Department’s Computer Crimes and Intellectual Property Section and the National Security and Cybercrime Section of the U.S. Attorney’s Office for the Eastern District of New York are prosecuting the case.

If convicted, the defendant faces a maximum sentence of 20 years in prison. The charges remain allegations, and prosecutors will have to prove the case in court.

The case could also bring additional scrutiny to companies selling ransomware decryption and recovery services, particularly those claiming proprietary capabilities that customers cannot independently evaluate during an active incident.

For ransomware victims, the allegations illustrate another risk beyond the original attack: determining whether a recovery provider is actually performing the technical work it claims or simply acting as an undisclosed intermediary between the victim and the attacker.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →