Zohar Pinhasi, the owner and operator of the ransomware recovery firm MonsterCloud, has been indicted on charges of wire fraud and wire fraud conspiracy. Authorities allege that Pinhasi defrauded hundreds of clients by claiming to decrypt their data using proprietary tools without paying ransoms, while in reality, he secretly paid cybercriminals and then charged his clients significantly inflated fees.
The indictment, filed by the U.S. Attorney for the Eastern District of New York, accuses Pinhasi of operating this scheme over a five-year period, ending in 2023. During this time, he allegedly charged clients more than $19 million, while paying out over $8 million in ransom payments to attackers. Pinhasi, a dual U.S.-Israeli national, pleaded not guilty in a federal court in Brooklyn, N.Y., and was released on a $2 million bond. He faces a maximum of 60 years in prison if convicted.
According to prosecutors, Pinhasi and a co-conspirator, an employee at MonsterCloud, would initially charge clients an exploratory fee ranging from $2,500 to $10,000. During this phase, Pinhasi would obtain the ransom note and a sample of encrypted files from the victim. He would then share these samples with the cybercriminals to obtain proof of decryption, which he would present to the prospective client as evidence of MonsterCloud's purported decryption capabilities. This preliminary step, which did not involve any proprietary technology, induced clients to contract for full ransomware recovery services, often costing two or more times the actual ransom.
Officials stated that while MonsterCloud's contracts indicated that contacting cybercriminals would be a last resort, it was frequently Pinhasi's initial method for accessing encrypted files and obtaining decryption keys. He allegedly used aliases such as "Zack Silver" and "Zack Green" in his communications with the attackers. In one instance in August 2023, Pinhasi reportedly charged a client approximately $150,000 for recovery services, while only paying about $8,200 in ransom.
The FBI highlighted that Pinhasi's actions re-victimized clients who had already suffered a ransomware attack, turning their crisis into a profit center for himself without addressing the underlying security threats. The company's website remains active, featuring testimonials from law enforcement agencies and a former FBI official.
This is not the first time MonsterCloud's practices have drawn scrutiny. A 2019 report detailed how the company claimed to use its own data recovery methods but instead paid ransoms without informing victims, including law enforcement agencies. The current indictment underscores a broader concern within the ransomware recovery industry, where some actors have been accused of exploiting victims' vulnerabilities. Earlier this year, a separate group of former ransomware negotiators received prison sentences for conspiring with ransomware affiliates and deceiving their employers' clients.
Plea negotiations are reportedly underway, and a federal judge has granted a one-month delay in trial proceedings. Pinhasi's lawyer has not yet commented on the case.






