ThreatPaper
Weak Evidence

Fake decryption tools masked an $11M markup

Assessment

SecurityWeek's October 8, 2026 headline states an '$11M markup.' The EDNY indictment never states $11 million or characterizes an '$11 million markup' or profit. The figure is the arithmetic gap between 'more than $19 million' charged and 'more than $8 million' paid in ransoms — both figures explicitly qualified as 'over,' so the true difference is not a fixed $11 million, and the gap also absorbs MonsterCloud's labour, overhead and analysis fees rather than being pure profit. The SecurityWeek body, BleepingComputer and The Register all avoid stating $11 million. The number is a reasonable order-of-magnitude inference presented in a headline as a precise fact.

Where this claim appeared

SecurityWeek · 2026-10-08

https://www.securityweek.com/fake-decryption-tools-masked-11m-markup-in-ransomware-recovery-scheme/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

MonsterCloud ransomware-recovery fraud: owner Zohar Pinhasi charged in EDNY with secretly paying the hackers

Think this assessment is wrong? Report an error.