A Florida businessman who marketed his company as a high-tech ransomware recovery operation has been indicted on federal charges alleging he quietly paid off cybercriminals while telling clients he used proprietary decryption tools, then kept the difference between what victims paid and what the attackers actually received.
Zohar Pinhasi, 50, a dual U.S.-Israeli national who also went by Zack Silver and Zack Green, faces two counts of wire fraud and one count of wire fraud conspiracy, the U.S. Department of Justice announced Wednesday. Each count carries a maximum sentence of 20 years in prison.
The charges center on MonsterCloud, the Florida-based company Pinhasi owned and operated. Prosecutors say the firm urged ransomware victims not to negotiate with attackers, claiming it possessed “proprietary tools” and “advanced decryption techniques” that could restore encrypted data without capitulating to ransom demands. In reality, according to the indictment, Pinhasi contacted the ransomware operators himself, paid them for decryptors, and then billed clients at rates substantially above what the criminals had received.
“By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” said Joseph Nocella Jr., U.S. Attorney for the Eastern District of New York.
The scale of the alleged scheme was substantial. Prosecutors say Pinhasi charged clients more than $19 million in total while paying out more than $8 million in ransom payments over the course of the operation.
Two transactions cited in the indictment illustrate the alleged markup. In August 2023, Pinhasi reportedly paid a threat actor roughly $8,200 to unlock a victim’s data, then billed that client approximately $150,000. In another incident around October 2021, he allegedly paid about $236,000 in ransom and charged the customer roughly $380,000.
| Case | Ransom Paid to Hackers | Amount Billed to Client |
|---|---|---|
| August 2023 | ~$8,200 | ~$150,000 |
| October 2021 | ~$236,000 | ~$380,000 |
Note: Figures are approximate, as cited in the federal indictment.
MonsterCloud’s public-facing materials presented a starkly different picture. The company’s website touted its use of “advanced decryption techniques and cutting-edge technology” and described itself in sweeping terms: “At MonsterCloud, we are not a team of IT Experts. We are the most sophisticated Counter Cyber Terrorism team in the world.”
The site also directly addressed the question of whether the company paid ransoms on behalf of clients, stating that while it strongly advocated against victims paying ransoms themselves, the firm had “extensive experience working with ransomware perpetrators” and sometimes resorted to “other means” to resolve incidents, with all terms disclosed in service contracts.
Prosecutors allege those representations were misleading. The indictment states that MonsterCloud presented decrypted sample files to prospective clients as evidence of its recovery capabilities, when in fact those samples had been obtained from the ransomware operators themselves.
A paid spokesperson for the company appears to have grown suspicious years before the charges were filed. According to the indictment, in May 2019 the spokesperson contacted Pinhasi directly and asked whether MonsterCloud actually possessed proprietary software capable of decrypting ransomware-locked data. Pinhasi’s response, quoted in court documents, was blunt: “MonsterCloud doesn’t hold any proprietary technology [to] decrypt the ransomware data.”
The alleged scheme was not entirely unknown before this week’s charges. A 2019 investigation by ProPublica examined two data recovery firms and found they typically paid ransoms and charged victims extra; MonsterCloud was one of the companies named. At the time, Pinhasi denied that his firm had promised in advance it could decrypt files or had misled customers.
James C. Barnacle Jr., assistant director of the FBI, framed the case as a betrayal of victims already reeling from cyberattacks. “As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat,” he said. “Instead, he turned the victim’s crisis into his own profit center. This deception is unacceptable.”
Pinhasi has pleaded not guilty to the charges and was released on a $2 million bond, according to court records cited in coverage of the case.
The indictment also signals that the investigation may not be finished. Court documents reference “multiple co-conspirators, individuals whose identities are both known and unknown to the Grand Jury, including MonsterCloud employees and contractors,” suggesting additional charges could follow as the FBI continues its work.
The case underscores a growing concern among cybersecurity professionals and law enforcement: that the ransomware recovery industry itself can harbor bad actors who exploit victims’ desperation. Law enforcement agencies have long advised organizations against paying ransoms, warning that attackers may take the money without delivering a working decryptor or may return for a second payment. The allegations against MonsterCloud suggest that even the firms offering to fix such incidents may not be operating in victims’ best interests.
For businesses hit by ransomware, the implications are sobering. Vetting recovery vendors has become as critical as defending against the initial attack, and the case may prompt more scrutiny of claims about proprietary decryption technology that, in the vast majority of ransomware cases, simply does not exist outside of law enforcement or security-researcher tooling.
The Eastern District of New York is prosecuting the case, with the FBI leading the investigation.
Click Here For The Original Source.
