MonsterCloud CEO charged in secret ransomware payments

Federal prosecutors have charged MonsterCloud founder Zohar Pinhasi with wire fraud, alleging he ran a years-long ransomware recovery scheme that secretly paid extortion gangs while misleading victims about how their data was restored[1][2][7]. The dual U.S.–Israeli national was indicted by a grand jury in the Eastern District of New York on September 23, 2026 and arraigned in Brooklyn on October 7, where he pleaded not guilty and was released on a $2 million bond[2][7][15].

According to the indictment, Pinhasi’s Florida-based company, MonsterCloud LLC, marketed proprietary tools and unique decryption techniques that supposedly allowed it to recover encrypted files without paying cybercriminals[1][2][7]. Prosecutors say no such technology existed; instead, Pinhasi and co-conspirators contacted the same ransomware operators who had attacked their clients, paid the demanded ransoms to obtain decryption keys, and then billed victims for recovery work as if MonsterCloud had cracked the encryption itself[2][6][11].

Distressed organizations were first pitched an analysis service, typically costing between $2,500 and $10,000, during which MonsterCloud staff collected the ransom note and samples of encrypted data from the victim’s environment[7][8][12]. In many cases, the indictment alleges, Pinhasi sent those samples to the attackers, received partially decrypted files as proof, and showed them to prospective clients as evidence of MonsterCloud’s supposed capabilities without disclosing that the decryption came directly from the ransomware gang[2][7][10]. This sales tactic often led victims to sign up for full ransomware recovery engagements priced at up to twice the original ransom demand, believing they were avoiding payments to criminals[6][7][12].

From June 2018 through June 2023, Pinhasi allegedly charged hundreds of organizations in the United States and Canada more than $19 million in fees while quietly facilitating over $8 million in ransom payments to cybercriminals[1][7][12]. In one August 2023 incident highlighted by prosecutors, he is accused of paying a ransomware group about $8,200 to unlock a client’s systems and then invoicing that organization roughly $150,000 for the recovery[7][8]. Court filings say he sometimes used the aliases Zack Silver and Zack Green when dealing with attackers[2][7].

Pinhasi faces two counts of wire fraud and one count of wire fraud conspiracy, each carrying a maximum sentence of 20 years in prison, for a potential total of up to 60 years if the sentences run consecutively[2][11][13]. In announcing the charges, U.S. Attorney Joseph Nocella Jr. for the Eastern District of New York said Pinhasi falsely claimed to decrypt ransomware without paying off the ransomers and in doing so re-victimized his clients while extracting a hefty profit for himself, while FBI official James C. Barnacle Jr. described MonsterCloud’s conduct as turning the victim’s crisis into its own profit center[1][6][15].

The case highlights how opaque ransomware remediation and negotiation services can be abused in an already murky extortion economy, where desperate victims often lack visibility into how third-party firms actually obtain decryption keys or negotiate with attackers[6][7][12]. MonsterCloud had operated for years despite earlier scrutiny; a 2019 investigative report by ProPublica documented how the company claimed unique data-recovery methods while quietly paying ransoms for law-enforcement and other clients, foreshadowing many of the practices now detailed in the federal indictment[6][10]. Security researchers such as Arkem Cyber’s Jon DiMaggio have long warned that some ransomware fixers may simply be repackaging ransom payments behind glossy marketing, leaving victims both overcharged and still exposed to repeat attacks.

For organizations seeking help after a ransomware incident, the MonsterCloud allegations underscore the need for rigorous due diligence: verifying whether a provider is licensed, how it engages with extortionists, what data it collects, and whether its contracts clearly disclose any ransom-payment activities. Companies are increasingly urged to involve trusted incident-response firms, insurers, and legal counsel when negotiating or deciding whether to pay, and to pair any decryption effort with thorough threat-hunting and remediation so the attackers cannot simply return under the cover of another rescue operation.

References

  1. Owner of Florida Ransomware Remediation Company …
  2. Known Cybersecurity Expert and Owner of Florida …
  3. Fake Decryption Tools Masked $11M Markup in Ransomware …
  4. Ransomware recovery CEO charged over secret ransom …
  5. Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims – Help Net Security
  6. MonsterCloud Owner Charged With Secretly Paying Ransomware Demands
  7. MonsterCloud Owner Accused of Billing Over $19M While …
  8. Ransomware remediation company owner charged with defrauding victims
  9. Cybersecurity Expert Charged with Wire Fraud After …
  10. DOJ charges ransomware recovery CEO for secretly paying hackers

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply