Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Government & Policy » US Charges MonsterCloud Owner Over Alleged Ransomware Recovery Scam

US Charges MonsterCloud Owner Over Alleged Ransomware Recovery Scam

By:
Last updated:October 9, 2026
Human Written
  • Federal prosecutors say Zohar Pinhasi, owner of MonsterCloud, told clients he could unlock their files without paying ransom, yet he secretly paid hackers himself.

  • He allegedly has collected more than $19 million from clients, while paying just over $8 million in ransoms.

  • Pinhasi’s arraignment took place on October 7. He faces three charges: two counts of wire fraud and one count of conspiracy.

US Charges MonsterCloud Owner Over Alleged Ransomware Recovery Scam

50-year-old Zohar Pinhasi built his reputation as a ransomware fixer in Florida. He owns MonsterCloud, a cybersecurity company. However, prosecutors say he scammed the very people who came to him for help. On Wednesday, October 7, he stood before a federal judge in Brooklyn.

According to the charges, Pinhasi told his clients he had unique tools to recover their locked data. His promises turned out to be just smoke and mirrors. They say he really paid the criminals and pocketed the difference.

Details of Pinhasi’s Scheme

Pinhasi is a U.S. and Israeli citizen. The Justice Department says he also goes by “Zack Silver” and “Zack Green.”

According to the indictment, business owners came to MonsterCloud after hackers locked their files. Many were scared and short on time. The company’s website warned clients not to pay ransoms. It said the team could get data back without giving in to the attackers.

Pinhasi allegedly claimed he had “advanced decryption techniques” and “proprietary tools.” Prosecutors say he had no special technology at all.

Assistant Attorney General A. Tysen Duva said the defendant offered an alternative to paying ransoms. Instead, Duva said, he allegedly hurt victims a second time. U.S. Attorney Joseph Nocella Jr. of the Eastern District of New York said Pinhasi re-victimized clients while making a hefty profit.

FBI Assistant Director James Barnacle Jr. went further. He said Pinhasi “turned the victim’s crisis into his own profit center.” Barnacle also said Pinhasi never fixed the underlying threat.

How the Alleged Scheme Worked

Prosecutors say Pinhasi instead contacted the very criminals who had hit his client. He paid them for a decryption key, which is a code that unlocks scrambled files. MonsterCloud employees then used the key to try to restore the client’s data.

The client was never told, according to the charges. Pinhasi then billed a fee far above what he had paid the hackers. The Justice Department gave one example from August 2023. Pinhasi allegedly paid a criminal about $8,200 and charged the client about $150,000.

Across the whole scheme, prosecutors say he charged clients more than $19 million. He allegedly paid more than $8 million in ransoms. By our math, that leaves a gap of roughly $11 million before any business costs.

Not the First Warning to Pinhasi

MonsterCloud drew scrutiny years ago. In 2019, the news outlet ProPublica reported that MonsterCloud and another firm, Proven Data Recovery, claimed to use their own methods but instead paid ransoms. ProPublica said MonsterCloud sometimes did this without telling victims, including local police agencies.

One case involved a Houston IT consultant. He said MonsterCloud asked for $2,500 for an analysis and up to $25,000 for recovery. The ransom was a mere $7,000 worth of bitcoins. The consultant reported that the company became evasive after he requested how it would restore its data.

Pinhasi told reporters then that the company’s methods were a trade secret. He said MonsterCloud did not mislead clients. That same year, a security researcher posed as a victim who did not want to pay. He said several recovery firms, including MonsterCloud, contacted the attackers.

ProPublica also noted that paying a ransom is not illegal. Neither is keeping a recovery method secret. Some firms, such as Coveware, openly help clients pay attackers. The Federal Trade Commission had not cited MonsterCloud at that time.

The difference in this case is the alleged lie. Prosecutors say clients were told one thing and sold another.

Why Paying Ransomware Attackers is Risky Anyway

The FBI and CISA warn the victims against paying any ransom. According to their joint guidance on ransomware incidents, it does not ensure the decryption of your data. It also does not guarantee your system will be safe in the aftermath, or that your stolen data won’t be released publicly.

Businesses looking for the services of a recovery firm need to take steps to protect themselves first. You need to ask in writing how the company will restore your data and whether it will communicate or pay off to the attackers. Ask exactly how it sets its fees. A firm that dodges those questions is a warning sign.

What Happens Next

The FBI is investigating. Senior Trial Attorneys Brian Mund and Vasantha Rao of the Justice Department’s Computer Crime and Intellectual Property Section are prosecuting. So are Assistant U.S.

The bureau has also pursued broader efforts to stop online fraud, including cases in which it blocked more than $1 billion in cyber fraud as online scam losses surged. Attorneys Alexander Mindlin and Lindsey Oken of the Eastern District of New York. Pinhasi is presumed innocent unless proven guilty beyond a reasonable doubt in court.

His public bio describes him as a counter-cyberterrorism expert with about 25 years in the field. It also says he served as an IT security intelligence officer in the Israeli military. Those claims will likely draw attention as the case moves forward.

The Justice Department says its cybercrime section has won convictions against more than 180 cyber and intellectual property criminals since 2020. This case adds a new target: the helper who allegedly profited from the crisis.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.