Prosecutors allege that Pinhasi secretly paid hackers for decryption keys while charging clients much higher fees.
Federal prosecutors allege that Zohar Pinhasi, 50, secretly paid cybercriminals to obtain decryption keys while charging his clients much higher fees. His company collected more than $19 million from clients and paid over $8 million in ransom payments, according to the US Department of Justice. He was arraigned on wire fraud charges in a federal court in Brooklyn on Wednesday after a grand jury in the Eastern District of New York indicted him on September 23. One transaction highlighted by prosecutors took place in August 2023. Pinhasi paid approximately $8,200 to a cybercriminal to obtain a decryption key, according to the Justice Department. However, he allegedly charged the affected client approximately $150,000 for the service, significantly more than the ransom payment. Over the course of the alleged scheme, prosecutors say Pinhasi charged clients more than $19 million and sent over $8 million to cybercriminals. One such spokesperson contacted Pinhasi in May 2019 to ask whether MonsterCloud actually possessed proprietary software capable of decrypting ransomware-affected data, according to prosecutors.
Pinhasi, who also used the names “Zack Silver” and “Zack Green,” owns MonsterCloud LLC, a Florida-based ransomware remediation company. MonsterCloud promoted its services as an alternative to paying ransomware attackers, according to the indictment. The company said it used “proprietary tools” and “advanced decryption techniques” to restore access to affected files. Prosecutors say the clients were not told that their payments were being used to pay the criminals responsible for the original attacks. “As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” Nocella said.
A Florida cybersecurity expert who claimed his company could recover data locked by ransomware without paying hackers has been charged with fraud in the United States. The allegations concern businesses that had already suffered ransomware attacks and approached MonsterCloud for help. Ransomware is a type of cyberattack in which criminals encrypt files, making them inaccessible, and demand payment to provide a decryption key. MonsterCloud presented itself as a company that could recover such files without giving money to the attackers. However, prosecutors allege that Pinhasi did not have the special technology he advertised. Instead, he contacted the same cybercriminals who had attacked his clients, paid them for decryption keys and charged the businesses substantially more than the ransom amounts. Its website warned businesses against paying ransom and claimed that its team could help recover encrypted information through specialised technology. These claims were particularly relevant to businesses whose data had become inaccessible following cyberattacks. MonsterCloud’s website also stated that “our team specializes in helping businesses recover their data without succumbing to ransom demands. Federal investigators, however, allege that the company did not possess the technology it claimed to use. Instead of independently decrypting the files, Pinhasi allegedly negotiated with the attackers and paid them to obtain decryption keys. MonsterCloud employees then used those keys in an attempt to restore the clients’ encrypted files. Investigators say this was part of a broader scheme in which MonsterCloud collected large fees while secretly paying ransomware attackers. The indictment also raises questions about the company’s advertising. MonsterCloud’s website featured testimonials, including some from paid spokespersons. Pinhasi allegedly responded, “Monstercloud doesn’t hold any Proprietary technology [to] decrypt the ransomware data. US Attorney Joseph Nocella Jr. for the Eastern District of New York accused Pinhasi of taking advantage of businesses that were already victims of cybercrime. FBI Assistant Director in Charge James C. Barnacle Jr. also alleged that Pinhasi failed to address the underlying cybersecurity threat while profiting from clients seeking assistance.
Instead, he turned the victim’s crisis into his own profit center,” Barnacle said. “As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Pinhasi, a US and Israeli national from Hollywood, Florida, faces two counts of wire fraud and one count of wire fraud conspiracy.
If convicted, he faces a maximum prison sentence of 20 years on each count. The case is being prosecuted by the US Attorney’s Office for the Eastern District of New York and the Justice Department’s Computer Crime and Intellectual Property Section. The Justice Department also referred to joint guidance from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), which advises ransomware victims against paying attackers. The agencies warn that paying a ransom does not guarantee that encrypted data will be recovered, compromised systems will become secure or stolen information will not be leaked. You use AI every day. Now get your AI Quotient. Take the AIQ test.

