The owner of MonsterCloud, a ransomware remediation company, has been charged with allegedly defrauding clients by secretly paying ransoms to cybercriminals while claiming to use proprietary technology for data recovery. Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23, 2026, and arraigned on Wednesday in Brooklyn federal court.
Pinhasi faces one count of conspiracy to commit wire fraud and two counts of wire fraud. Prosecutors allege the scheme operated from June 2018 to June 2023. Pinhasi surrendered on Wednesday, pleaded not guilty, and was released on a $2 million bond.
According to the indictment, Pinhasi owned and operated MonsterCloud LLC, a Florida-based company that advertised its ability to recover encrypted data without paying cybercriminals, using specialized tools and decryption techniques. However, prosecutors claim that Pinhasi and his co-conspirators lacked such proprietary technology. Instead, they allegedly contacted ransomware operators, paid for decryption keys, and then used those keys to restore customer files.
While some MonsterCloud contracts reportedly disclosed the possibility of communicating with or paying cybercriminals, these contracts stated this would only occur if other decryption methods failed. Prosecutors contend that engaging with cybercriminals was typically MonsterCloud's primary method for obtaining decryption keys and recovering data.
The U.S. Attorney's Office stated that Pinhasi "re-victimized his clients while extracting a hefty profit for himself" by falsely claiming to decrypt ransomware without paying attackers. The indictment details instances where MonsterCloud allegedly charged customers significantly more than the ransom payments made. In one case, Pinhasi reportedly paid a ransomware gang approximately $8,200 but charged the victim about $150,000. In another, he allegedly paid around $236,000 and charged the customer approximately $380,000.
Prosecutors further allege that MonsterCloud used decrypted sample files as "recovery proofs" to convince victims of its capabilities, even though these samples were obtained directly from the ransomware operations. Over the course of the alleged scheme, Pinhasi and his co-conspirators are said to have facilitated over $8 million in ransom payments, while charging hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services. If convicted, Pinhasi could face up to 20 years in prison.
Similar concerns regarding MonsterCloud's practices were raised in a 2019 investigation. That report indicated that the company sometimes paid ransomware operators despite claiming to offer alternative solutions. As part of that investigation, a security researcher reportedly created a fake ransomware attack and, posing as a victim, approached several recovery companies, including MonsterCloud. The researcher provided ransom notes with email addresses controlled by the fictitious ransomware gang. Soon after, the attacker-controlled accounts allegedly received anonymous offers to pay the ransom, which were traced back to the data recovery firms.
The 2019 investigation claimed that MonsterCloud had stated it could recover encrypted files without informing the supposed victim of its intent to pay the attacker. At the time, Pinhasi disputed that MonsterCloud had made advance promises of decryption and denied misleading customers. He also stated that MonsterCloud's recovery methods varied by case and declined to disclose them, citing them as a "trade secret."






