Ransomware Recovery CEO Charged for Secretly Paying Attackers While Billing Clients Over $19M
MonsterCloud owner Zohar Pinhasi is accused of buying decryption keys from ransomware gangs, then billing hundreds of victims far more while claiming his firm could decrypt files without paying. He pleaded not guilty.

A Florida ransomware recovery company told victims not to pay criminals and said its own technology could get their data back. Federal prosecutors now say the company was quietly paying the criminals and charging victims a large markup.
Zohar Pinhasi, 50, owner of MonsterCloud LLC, was arraigned in Brooklyn on Wednesday on one count of conspiracy to commit wire fraud and two counts of wire fraud, BleepingComputer reports. A grand jury in the Eastern District of New York indicted him on 23 September. He pleaded not guilty and was released on a $2 million bond. Pinhasi is a US and Israeli national from Hollywood, Florida, and has also gone by Zack Silver and Zack Green.
The decryption tool prosecutors say didn't exist
MonsterCloud advertised proprietary tools and advanced decryption techniques that could recover encrypted data without paying anyone. Prosecutors say that technology didn't exist.
According to the indictment, from June 2018 to June 2023 Pinhasi and co-conspirators contacted ransomware operators, bought the decryption keys, restored customer files with them and billed far more than the ransom. In one example from August 2023, the firm allegedly paid attackers about $8,200 and billed the victim about $150,000. In October 2021, it allegedly paid around $236,000 and charged about $380,000.
Across the whole period, prosecutors say MonsterCloud facilitated more than $8 million in ransom payments and billed more than $19 million to hundreds of companies in the US and Canada.
Some contracts did say the firm might talk to or pay criminals, but only if other decryption methods failed. Prosecutors say contacting the attackers was usually the first thing it did. The "recovery proofs" shown to clients were allegedly sample files decrypted by the ransomware gangs themselves.
"No proprietary technology"
Help Net Security adds two details from the case. Some testimonials on MonsterCloud's website were allegedly paid for. And in May 2019, when a promoter asked whether the company really had its own decryption software, Pinhasi allegedly replied that MonsterCloud did not hold any proprietary technology to decrypt ransomware data.
US Attorney Joseph Nocella Jr. said the defendant "re-victimized his clients while extracting a hefty profit for himself." FBI Assistant Director James C. Barnacle Jr. said Pinhasi "turned the victim's crisis into his own profit center" and never dealt with the underlying threat, per The Hacker News. Each count carries up to 20 years in prison on conviction. His attorneys, Christopher Clark and Rodney Villazor, were contacted for comment.
ProPublica's 2019 sting
Concerns about this kind of business are not new. A 2019 ProPublica investigation tested recovery firms with a sting: researcher Fabian Wosar and a colleague built fake ransomware, posed as victims, and watched the attacker inbox. Anonymous offers to pay the ransom soon arrived, and they traced some of them to recovery firms including MonsterCloud. Pinhasi disputed ProPublica's framing at the time and called his methods a "trade secret."
The charges are still only allegations. But the case shows how hard it is for a victim to check what a recovery firm actually does once the lights go out, especially as gangs like n0n threaten to destroy backups to leave victims with no way out except paying.
Some offers on this page may be paid placements or contain affiliate links.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free