Issue #193 | October 2026, Week 2
October 8, 2026Five cases this week: MonsterCloud LLC owner accused of cooperation with ransomware gangs, KillSec cybercriminal gang dismantled, Qilin member extradited to Germany, Former CIA officer pleads guilty to financial fraud scheme.

Ransomware recovery company owner charged with fraud for secretly paying cybercriminals
- Jurisdiction
- United States
- Threat Actor
- Individual
- Incriminated Activity
- Wire fraud
- Estimated Damage
- $11 million
- Enforcement Action
- Arrest
- Case Status
- Investigation pending
The owner of a ransomware recovery company has been charged with allegedly defrauding victims by secretly paying cybercriminals for decryption keys while claiming his company had its own technology to recover encrypted files.
Prosecutors say Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” owned MonsterCloud LLC, a Florida-based company that helped businesses recover from ransomware attacks. The company claimed it could restore encrypted data without paying hackers. However, prosecutors allege that Pinhasi and his partners often contacted ransomware groups, paid for decryption keys and used the keys to recover customers’ files.
In one case, Pinhasi allegedly paid a ransomware group about $8,200 but charged the victim around $150,000. In another case, prosecutors say he paid about $236,000 and charged the customer roughly $380,000.
The indictment says MonsterCloud also used recovered sample files to convince customers that it could decrypt their data, even when the files had been decrypted using keys obtained from attackers.
Over the five-year period from June 2018 to June 2023, Pinhasi and his co-conspirators allegedly helped facilitate more than $8 million in ransom payments and charged more than $19 million for recovery services.
Pinhasi faces one count of conspiracy to commit wire fraud and two counts of wire fraud. If convicted, he could face up to 20 years in prison.
Former engineer gets nearly 3 years for a ransomware attack against his employer
- Jurisdiction
- United States
- Threat Actor
- Individual
- Incriminated Activity
- Ransomware-style attack
- Estimated Damage
- Thousands of devices disrupted
- Enforcement Action
- 32-month prison sentence
- Case Status
- Court judgement
A former infrastructure engineer has been sentenced to 32 months in prison for carrying out a ransomware-style attack against his former employer, locking thousands of devices and demanding a $750,000 ransom.
Daniel Rhyne, 57, of Kansas City, Missouri, pleaded guilty to the attack on the New Jersey-based industrial company where he previously worked. He was arrested in August 2024.
According to court documents, Rhyne accessed the company's network using an administrator account. He changed passwords, deleted administrator accounts, and blocked access to hundreds of servers and thousands of workstations.
Rhyne also shut down servers and workstations and sent employees an email claiming the company's backups had been deleted and demanding 20 bitcoin (worth about $750,000 at the time). He threatened to shut down 40 servers each day unless the ransom was paid.
The investigation found that Rhyne had searched online for ways to change administrator passwords, delete network accounts, clear Windows logs, and remotely shut down computers.
Rhyne didn’t receive any ransom, but the attack caused major disruption to the company's network, leaving employees unable to access many systems.
Police target the KillSec ransomware gang, arrest an alleged leader
- Jurisdiction
- International (10 countries)
- Threat Actor
- Ransomware group
- Incriminated Activity
- Ransomware extortion
- Estimated Damage
- 110 TB of stolen data
- Enforcement Action
- Three arrests, infrastructure seizure
- Case Status
- Investigation pending
An international law enforcement operation has disrupted the KillSec ransomware group, with authorities seizing its data leak site and servers and arresting three suspects.
The operation, called “Operation KillSwitch,” took place on September 30 and involved authorities from 10 countries, including Germany, the United States, Belgium, Finland, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom.
Police identified a 16-year-old as the suspected main operator of KillSec. Another suspected member, described as a developer, turned 18 in August 2026 but was still a minor when some of the alleged crimes took place. Authorities have also identified suspected members involved in negotiations and affiliate operations. Police searched eight properties in Greece, Romania, Spain and the UK. Authorities also shut down five servers linked to the group and seized at least 110 terabytes of stolen data.
US authorities have charged a KillSec member, identified as Fouad Eltibrizi (aka Archduke), with unauthorized access to a computer system, causing damage to a computer, and extortion. Eltibrizi, a Dutch national, was arrested on September 30, 2026, in the UK.
Authorities believe KillSec carried out around 1,000 suspected attacks worldwide, with about 500 considered successful so far. At least 70 attacks targeted organizations in Germany.
KillSec has been active since around 2024. The group allegedly exploited software vulnerabilities and poorly secured systems to breach corporate systems and steal sensitive information. The stolen data was then used to pressure victims into paying ransoms, with threats that the information would be published online. The gang also used artificial intelligence to help build their ransomware systems and identify potential victims.
Suspect linked to Qilin ransomware gang reportedly extradited to Germany
- Jurisdiction
- Japan, Germany
- Threat Actor
- Ransomware group
- Incriminated Activity
- Ransomware attack
- Estimated Damage
- Major system outage of Asahi Group Holdings
- Enforcement Action
- Extradition to Germany
- Case Status
- Investigation pending
Japanese police have arrested a Russian national believed to be a key member of the international ransomware group Qilin and extradited him to Germany, according to local media.
Qilin is suspected of carrying out ransomware attacks on companies around the world, encrypting data and causing major damage. In 2025, the group claimed responsibility for a major system outage at Japanese food and beverage company Asahi Group Holdings.
German authorities had been searching for the Russian man over his suspected involvement in a ransomware attack on a German company. After learning that he was in Japan, Japanese authorities located and detained him before handing him over to Germany at the request of German authorities.
A former CIA officer pleads guilty to a $193M fraud scheme
- Jurisdiction
- United States
- Threat Actor
- Individual
- Incriminated Activity
- Financial fraud
- Estimated Damage
- $193.6 million
- Enforcement Action
- Arrest
- Case Status
- Judicial proceedings
Former CIA officer David J. Rush has pleaded guilty to stealing nearly $194 million from the US government through a fake top-secret intelligence program.
According to media reports, Rush had worked since 2010 in a CIA division responsible for developing hacking tools and techniques used in espionage operations. Court filings say that Rush held significant authority over government intelligence programs and related spending.
Prosecutors said Rush used his position and security clearance to create a fraudulent special access program and direct government money to himself. He had reportedly lied about parts of his education and military background to help secure his position at the CIA.
The FBI searched Rush’s Virginia home in May 2026 and found 298 gold bars worth about $46 million, more than $2.1 million in cash, euros, luxury watches and other valuables. Prosecutors said Rush also used the stolen money to buy luxury properties, cars and watches.
In total, Rush fraudulently obtained about $193.6 million in government funds. Under his plea agreement, he will forfeit the gold, cash, properties, watches and two luxury BMW vehicles.
Rush is scheduled to be sentenced on January 28, 2027. He faces up to 20 years in prison, along with fines, restitution and forfeiture.
Disclaimer: The information in this blog is provided from open and governmental sources. We respectfully remind our readers about the presumption of innocence. The information herein is provided for educational purposes only and does not constitute legal opinion or advice.