MonsterCloud owner charged with secretly paying ransomware gangs while billing victims
US prosecutors say ransomware recovery firm MonsterCloud claimed to decrypt files without paying criminals but quietly bought keys, facilitating more than $8 million in ransom payments.
At a glance
- Zohar Pinhasi, owner of Florida-based MonsterCloud, faces wire fraud conspiracy and two wire fraud counts in Brooklyn, BleepingComputer reported.
- Prosecutors allege the firm had no proprietary decryption technology and paid ransomware operators for keys from 2018 to 2023.
- Hundreds of US and Canadian companies were allegedly charged more than $19 million while over $8 million went to attackers.
- Pinhasi pleaded not guilty and was released on a $2 million bond; he faces up to 20 years if convicted.
The owner of a Florida ransomware recovery company has been charged in New York with defrauding victims by secretly paying ransomware gangs for decryption keys while marketing a service that supposedly restored data without paying criminals. According to BleepingComputer, Zohar Pinhasi, 50, who also used the names "Zack Silver" and "Zack Green," owns MonsterCloud LLC. Prosecutors allege the scheme ran from June 2018 to June 2023 and facilitated more than $8 million in ransom payments, raising questions about how organizations vet the incident response firms they turn to in a crisis.
What happened
A federal grand jury in the Eastern District of New York indicted Pinhasi on September 23, BleepingComputer reported. He surrendered, was arraigned in federal court in Brooklyn, pleaded not guilty and was released on a $2 million bond. He faces one count of conspiracy to commit wire fraud and two counts of wire fraud, each of which can carry up to 20 years in prison if he is convicted.
US Attorney Joseph Nocella Jr. said that by "falsely claiming to decrypt ransomware without paying off the ransomers," the defendant re-victimized his clients, according to BleepingComputer. Pinhasi's lawyers had not responded to the outlet's request for comment at the time of publication. The charges are allegations and have not been proven in court.
How the alleged scheme worked
MonsterCloud advertised decryption services that recovered data without paying attackers. Prosecutors allege the company had no proprietary decryption technology. Instead, it allegedly contacted the ransomware operators, paid them for keys and used those keys to restore customer files.
Some contracts disclosed that the company might contact or pay attackers, but only if other methods failed. Prosecutors say contacting the criminals was usually the first step. The company also allegedly used sample files decrypted by the attackers as "recovery proofs" to persuade victims to sign up.
BleepingComputer cites examples from the case. In one, about $8,200 was allegedly paid to a ransomware gang while the victim was charged about $150,000. In another, roughly $236,000 was allegedly paid and the customer was billed about $380,000. Overall, prosecutors say hundreds of companies in the US and Canada were charged more than $19 million.
Earlier warnings
The concerns are not new. BleepingComputer notes that a 2019 ProPublica investigation raised similar issues after researcher Fabian Wosar posed as a victim and traced ransom payment requests to MonsterCloud and another firm. At the time, Pinhasi disputed that customers were misled and called the company's methods a "trade secret."
What organizations should do
Victims evaluating recovery providers should ask directly whether the firm will contact or pay attackers, require that commitment in writing and be wary of claims of proprietary decryption for ransomware families without a known public decryptor. Legitimate free decryptors are listed by projects such as No More Ransom. Paying ransoms can also carry legal and sanctions risks, so legal counsel and law enforcement should be involved early. The most reliable protection remains tested offline backups.
Sources
- Ransomware recovery CEO charged over secret ransom payments — BleepingComputer
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



