MonsterCloud owner charged over alleged ransomware recovery fraud

US charges allege hidden ransom payments
The US Department of Justice has charged Zohar Pinhasi, the owner and operator of Florida-based MonsterCloud, with two counts of wire fraud and one count of wire fraud conspiracy. Prosecutors allege that Pinhasi, a 50-year-old US and Israeli national also known as Zack Silver and Zack Green, billed ransomware victims more than $19 million while secretly paying attackers more than $8 million to obtain decryptors.
The indictment alleges that MonsterCloud presented itself as able to recover encrypted data with proprietary tools and advanced decryption techniques, without yielding to ransom demands. Instead, prosecutors say Pinhasi contacted cybercriminals, paid them, obtained decryption tools and charged clients amounts substantially higher than the underlying ransom.
If convicted, Pinhasi faces up to 20 years in prison on each count. The case was announced by the Department of Justice and involves the US Attorney's Office for the Eastern District of New York and the Federal Bureau of Investigation.
Claims about recovery methods are central to the case
MonsterCloud's website says it uses advanced decryption techniques and cutting-edge technology to restore data. Its guidance on whether to pay a ransom states that payments do not guarantee a positive outcome and reward criminal behaviour. A separate question-and-answer section says the company sometimes resorts to other means to resolve an incident and that terms are disclosed in its service contract.
Federal prosecutors contend that there were no specialised tools capable of decrypting the affected data in the incidents at issue. Their allegation is that Pinhasi's recovery process depended on arranging payments to the ransomware operators in exchange for a decryptor, rather than on an independent technical capability.
“By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” US Attorney Joseph Nocella, Jr. said.
Two alleged transactions illustrate the billing gap
In one incident in August 2023, Pinhasi allegedly paid a threat actor about $8,200 and then billed the client about $150,000. In another case, around October 2021, he allegedly paid approximately $236,000 and charged the customer about $380,000.
The FBI said Pinhasi claimed to fix ransomware while not remediating the underlying threat. Assistant Director James C. Barnacle Jr. said the alleged conduct turned a victim's crisis into a profit centre.
For organisations selecting ransomware recovery assistance, the allegations underline the need to establish in writing how data recovery will be performed, whether negotiations or ransom payments are possible, what fees apply, and what work will address the underlying compromise. Clear contractual disclosure and technical validation are practical safeguards when a provider is asked to manage an incident under pressure.

