LIVE · cybersecurity feed
Live wire
ransomware

Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Zohar Pinhasi, the owner and operator of the ransomware recovery firm MonsterCloud, has been indicted on charges of wire fraud and wire fraud conspiracy. Authorities allege that Pinhasi defrauded hundreds of clients by claiming to decrypt their data using proprietary tools without paying ransoms, while in reality, he secretly paid cybercriminals and then charged his clients significantly…

ZeroDay News ·

Source: CyberScoop

Zohar Pinhasi, the owner and operator of the ransomware recovery firm MonsterCloud, has been indicted on charges of wire fraud and wire fraud conspiracy. Authorities allege that Pinhasi defrauded hundreds of clients by claiming to decrypt their data using proprietary tools without paying ransoms, while in reality, he secretly paid cybercriminals and then charged his clients significantly inflated fees.

The indictment, filed by the U.S. Attorney for the Eastern District of New York, accuses Pinhasi of operating this scheme over a five-year period, ending in 2023. During this time, he allegedly charged clients more than $19 million, while paying out over $8 million in ransom payments to attackers. Pinhasi, a dual U.S.-Israeli national, pleaded not guilty in a federal court in Brooklyn, N.Y., and was released on a $2 million bond. He faces a maximum of 60 years in prison if convicted.

According to prosecutors, Pinhasi and a co-conspirator, an employee at MonsterCloud, would initially charge clients an exploratory fee ranging from $2,500 to $10,000. During this phase, Pinhasi would obtain the ransom note and a sample of encrypted files from the victim. He would then share these samples with the cybercriminals to obtain proof of decryption, which he would present to the prospective client as evidence of MonsterCloud's purported decryption capabilities. This preliminary step, which did not involve any proprietary technology, induced clients to contract for full ransomware recovery services, often costing two or more times the actual ransom.

Officials stated that while MonsterCloud's contracts indicated that contacting cybercriminals would be a last resort, it was frequently Pinhasi's initial method for accessing encrypted files and obtaining decryption keys. He allegedly used aliases such as "Zack Silver" and "Zack Green" in his communications with the attackers. In one instance in August 2023, Pinhasi reportedly charged a client approximately $150,000 for recovery services, while only paying about $8,200 in ransom.

The FBI highlighted that Pinhasi's actions re-victimized clients who had already suffered a ransomware attack, turning their crisis into a profit center for himself without addressing the underlying security threats. The company's website remains active, featuring testimonials from law enforcement agencies and a former FBI official.

This is not the first time MonsterCloud's practices have drawn scrutiny. A 2019 report detailed how the company claimed to use its own data recovery methods but instead paid ransoms without informing victims, including law enforcement agencies. The current indictment underscores a broader concern within the ransomware recovery industry, where some actors have been accused of exploiting victims' vulnerabilities. Earlier this year, a separate group of former ransomware negotiators received prison sentences for conspiring with ransomware affiliates and deceiving their employers' clients.

Plea negotiations are reportedly underway, and a federal judge has granted a one-month delay in trial proceedings. Pinhasi's lawyer has not yet commented on the case.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

IDC Frontier, a prominent Japanese cloud and digital infrastructure provider, has confirmed that its IDCF Cloud service was targeted in a ransomware attack. The incident, which began on October 7 at 3:40 AM local time, led to an outage at a data center cluster serving Japan's eastern region.

vulnerability

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

A recently disclosed vulnerability, dubbed 'AgentCorruption,' reportedly allowed attackers to compromise AWS environments through a single prompt directed at an AI chatbot. The flaw, now patched, was identified within AWS Bedrock AgentCore and could have enabled an attacker to gain control over an organization's entire fleet of AI agents.

ai

Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal

More than 100 members of Congress have urged Google and Spirit Airlines to halt a proposed $10 million deal that would transfer Spirit's internal data to Google for the purpose of training artificial intelligence models. The lawmakers expressed significant concerns that even with de-identification safeguards, the data could still expose sensitive employee information.

security

DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub

The U.S. Justice Department and FBI have announced the seizure of two hacking tools, Microscan and FishHub, which are linked to the Chinese government-affiliated group Flax Typhoon and the China-based firm Integrity Technology Group. The seizures, authorized by a court in the Western District of Pennsylvania, aim to disrupt access to these tools by denying hackers their domain names.

security

Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review

Italy's Ministry of Foreign Affairs confirmed on October 8, 2026, that its website was under cyberattack. The ministry stated that its protection systems successfully mitigated the incident, preventing any disruption to its services.

malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.