Abstract:
In recent years, ransomware has posed an increasing threat to enterprises, so many ransomware-based companies have appeared on the market, such as helping customers negotiate lower ransoms with hackers in exchange for keys, helping customers process the purchase and payment of cryptocurrency, and of course some companies claim to have professional technology that can break encryption mechanisms and help customers recover files.

Cracking is impossible. It turns out that you secretly buy the key from a hacker:
The U.S. Department of Justice’s U.S. Attorney’s Office for the Eastern District of New York recently charged Zohar Pinhasi, head of ransomware emergency services company MonsterCloud, with wire fraud and conspiracy to commit wire fraud. The company claims to have professional tools and advanced technology that can crack encrypted files and therefore charges customers high data recovery fees.
But in fact, Zohar Pinghasi quietly contacted the hackers to negotiate a ransom in exchange for the decryption key. For example, in one case, Pinghasi charged a customer up to $150,000 for data recovery, but then paid the hacker $8,200 for the recovery key, and ultimately successfully helped the customer recover the encrypted files.
Also reserve a minimum guarantee clause in the contract:
From a contractual perspective, there seems to be no problem with Pinghasi. In the contract, MonsterCloud states that if the company is still unable to recover the data after all recovery methods have been exhausted, the company has the right to contact the attacker for negotiation or other disposal measures.
The only problem is that the company's only method is to contact hackers to negotiate to purchase decryption keys. It does not have so-called professional tools or advanced technologies, and it has not tried any data recovery measures other than purchasing keys. Therefore, from this perspective, this is indeed a fraud.
Is this business model illegal?
The indictment alleges that Pinghasi charged hundreds of companies in the United States and Canada more than $19 million in data recovery fees and paid hackers more than $8 million in ransom, but Pinghasi pleaded not guilty after appearing in court and was released on a $2 million bail.
Ping Hasi emphasized that the company has never promised customers in advance that it can decrypt, nor does it mislead customers. Data recovery methods vary in different cases, and the specific methods are commercial secrets and should not be disclosed.
However, the prosecutor's office scoffed at Pinghasi's claims, because Pinghasi concealed the actual recovery methods and ransom payments, and there were other legal risks. Some companies were prohibited from paying ransoms to hackers (and conducting any transactions), and Pinghasi's behavior created legal problems for these companies.
Comments