A Florida cybersecurity company owner who allegedly told ransomware victims that his firm could recover encrypted data without paying hackers is now facing federal wire fraud charges. According to the US Department of Justice (DOJ), Zohar Pinhasi, 50, owner of ransomware remediation company MonsterCloud, claimed to have proprietary tools and advanced techniques for decrypting files. Prosecutors allege that his company instead paid the cybercriminals behind the attacks and charged clients substantially more for the recovery. The DOJ said Pinhasi allegedly collected more than $19 million from clients while secretly paying over $8 million in ransom.
What prosecutors allege
Pinhasi, who is also known as “Zack Silver” and “Zack Green,” was arraigned in federal court in Brooklyn on October 7 after being indicted by a grand jury in the Eastern District of New York on September 23. He is accused of defrauding clients who turned to MonsterCloud after their businesses were hit by ransomware. Ransomware attacks typically lock or encrypt a victim’s computer files and demand payment in exchange for restoring access. According to the indictment described by the DOJ, Pinhasi presented MonsterCloud as an alternative to paying those demands. The company’s website reportedly advised businesses not to pay ransomware attackers and said its team could recover data without giving in to ransom demands.Pinhasi allegedly told prospective clients that MonsterCloud used “proprietary tools” and “advanced decryption techniques” to recover encrypted information. Prosecutors, however, allege that the company did not possess any special technology capable of decrypting the ransomware as represented. Instead, Pinhasi allegedly contacted the cybercriminals who had attacked his clients and paid them for decryption keys. MonsterCloud employees then used those keys in attempts to restore the affected files, according to the DOJ. Pinhasi allegedly concealed the ransom payments from clients while charging them fees that were substantially higher than the amounts paid to the attackers.
$8,200 ransom, $150,000 client bill
One example cited by prosecutors illustrates the alleged markup. In August 2023, Pinhasi allegedly paid approximately $8,200 to a cybercriminal for a decryption key. The client whose files had been encrypted was reportedly charged approximately $150,000 by MonsterCloud. The difference between the ransom payment and the amount billed to the client was part of what prosecutors say made the alleged scheme profitable. Overall, Pinhasi allegedly charged MonsterCloud clients more than $19 million during the scheme. More than $8 million of that money was allegedly used to make ransom payments to cybercriminals.The allegations also raise questions about the representations made to customers about MonsterCloud’s technology. The DOJ said that in May 2019, a paid spokesperson for the company asked Pinhasi whether MonsterCloud actually had proprietary software capable of decrypting ransomware. Pinhasi allegedly responded that the company did not have proprietary technology to decrypt ransomware data.
Charges and possible penalty
Pinhasi faces two counts of wire fraud and one count of wire fraud conspiracy. If convicted, each count carries a maximum penalty of up to 20 years in prison, according to the DOJ. The FBI is investigating the case, while prosecutors from the Justice Department’s Computer Crime and Intellectual Property Section and the Eastern District of New York’s National Security and Cybercrime Section are handling the prosecution. The case also comes against the backdrop of federal warnings about ransomware payments. The FBI and the Cybersecurity and Infrastructure Security Agency have said they do not recommend paying ransomware demands because payment does not guarantee that files will be decrypted, systems will be restored or stolen information will not be leaked.For businesses facing a ransomware attack, the allegations in this case highlight another risk beyond the original cyberattack: relying on a service provider that may misrepresent how it is recovering encrypted data. Prosecutors allege that instead of providing the promised alternative to ransom payments, Pinhasi’s company secretly paid the attackers and passed the cost on to already distressed victims at a substantial markup. Pinhasi has not been convicted. The charges are allegations, and he is presumed innocent unless and until proven guilty beyond a reasonable doubt.

