The U.S. Department of Justice has charged Zohar Pinhasi, 50, owner of the Florida ransomware remediation firm MonsterCloud, with wire fraud. Prosecutors say he told ransomware victims his company could recover their data without paying the attackers, then quietly paid those same attackers for decryption keys. According to the DOJ's own announcement, Pinhasi charged clients $19 million while paying more than $8 million in ransoms. That leaves a gap of roughly $11 million. The indictment covers June 2018 to June 2023. Pinhasi, a U.S. and Israeli national also known as "Zack Silver" and "Zack Green," pleaded not guilty and was released on a $2 million bond, according to BleepingComputer. These are allegations only and have not been proven in court.
What Happened
A federal grand jury in the Eastern District of New York returned the indictment on September 23, 2026 (BleepingComputer, BreachNews, Threadlinqs). Pinhasi was arraigned in federal court in Brooklyn on Wednesday, October 7, 2026. The DOJ press release is dated October 7. The Record's coverage, published October 8, also says he was charged "Wednesday." The U.S. Attorney's Office told BleepingComputer that Pinhasi surrendered that day.
The charges are one count of conspiracy to commit wire fraud and two counts of wire fraud (BleepingComputer, The Hacker News, BreachNews). The sources describe the possible sentence slightly differently. The Record says he faces "up to 20 years" if convicted. The Hacker News says up to 20 years for each count. MonsterCloud did not respond to The Record's request for comment.
The DOJ says MonsterCloud presented itself as "a principled alternative to paying off ransomware attackers." The Hacker News reports that the company's website still warns visitors that paying ransoms "only serves to encourage and reward their illegal behavior." BreachNews says the site is still advertising recovery services.
Officials did not soften their language. U.S. Attorney Joseph Nocella Jr. said Pinhasi "re-victimized his clients while extracting a hefty profit for himself." FBI Assistant Director James C. Barnacle Jr. said Pinhasi "turned the victim's crisis into his own profit center" and "never remediat[ed] the underlying threat."
This is not the first time MonsterCloud has faced these accusations. A 2019 ProPublica investigation, cited by The Record and SC Media, named the firm among recovery companies that paid ransoms while charging victims large fees. In that piece a researcher ran a sting: he infected his own machine and asked MonsterCloud for help. Pinhasi denied lying to clients at the time and said his methods were a trade secret.
What Was Taken
No data was stolen in this case. What was lost was money, and the trust of victims who were already in a crisis.
- Total billed to clients: $19 million according to the DOJ. Some outlets (The Hacker News, BreachNews) say "more than $19 million."
- Ransoms paid to attackers: The DOJ headline says "more than $8M." The Record says "about $8 million." The roughly $11 million markup is the difference between the two totals. Prosecutors have not published it as a separate figure.
- Example case: Pinhasi allegedly paid a ransom of about $8,200 and billed the client about $150,000, which is more than 18 times the ransom. The Record dates this to 2023. Security Affairs and BreachNews give August 2023.
- Victim profile: The DOJ has not published a victim count or a list of sectors. Threadlinqs (OTHER tier) lists government, law enforcement, small business and enterprise targets in North America. No primary source confirms this.
The victims also paid twice. Money they believed was buying a principled, no-ransom recovery actually went to the criminals who had attacked them. That has direct consequences for sanctions exposure, insurance claims, and their own public statements about whether they paid.
Why It Matters
Third-party IR is part of your attack surface. Organizations bring in recovery vendors at their weakest moment: under time pressure, without their usual systems, and often without legal review. This case shows that a vendor's marketing claims can be completely false, and the victim may never be able to tell.
Undisclosed payments create legal risk. If a vendor pays a ransomware group without telling the client, the client could be linked to a payment to a sanctioned group without knowing it. The client may also give inaccurate information to insurers, regulators or its board about whether a ransom was paid.
Disclosure clauses are not enough. BleepingComputer reports that the indictment acknowledges some MonsterCloud contracts did say the company might talk to or pay cybercriminals. According to prosecutors, those contracts said this would happen only if other decryption methods failed, yet paying the attackers was usually the firm's first step. A contract clause offers little protection if nobody checks what the vendor actually does.
Enforcement signal. The DOJ is treating people who profit from the ransomware economy as part of that economy. Assistant Attorney General A. Tysen Duva said the case shows the Department's commitment to protecting victims "regardless of how these cyber ransoms occur."
The Attack Technique
This was fraud, not an intrusion. As described in the indictment and reported across the sources, the alleged scheme worked like this:
- Pitch: MonsterCloud said it had "proprietary tools" and "advanced decryption techniques" that could restore data without paying a ransom (DOJ, The Record, The Hacker News). The aliases "Zack Silver" and "Zack Green" are named in the DOJ release. The sources do not say how they were used.
- Covert negotiation: Prosecutors say no such technology existed. Instead, MonsterCloud contacted the ransomware operators and bought the decryption key.
- Laundered recovery: Staff used the purchased key to decrypt the client's files, then presented the result as the product of MonsterCloud's own technology (Security Affairs, BleepingComputer).
- Markup: The client was charged a fee that the DOJ describes as "substantially higher than the ransom that MonsterCloud secretly paid."
Threadlinqs, an OTHER-tier source, connects the case to the Dharma, Gotcha and Nozelesn ransomware families. It maps the case to MITRE ATT&CK techniques, including T1585 (Establish Accounts) and T1657 (Financial Theft), and says it has 9 detection rules and 14 IOCs. Neither the DOJ nor the established outlets confirm those ransomware families as part of the indicted conduct. Treat that mapping as one vendor's view.
What Organizations Should Do
- Vet IR and recovery vendors before an incident happens. Keep a pre-approved retainer with established firms, preferably through your cyber insurer's panel. Treat any claim of a "proprietary decryptor" for current ransomware strains with skepticism unless the vendor can point to a public decryptor (for example, from No More Ransom) or a reference you can verify.
- Require written, specific disclosure about payments. Contracts should state that the vendor will not contact, negotiate with or pay a threat actor without the client's explicit, documented approval for that specific incident. Ask for transaction records (wallet addresses, amounts, timestamps) for any payment made.
- Run OFAC and sanctions checks yourself. Do not leave sanctions screening to the vendor. Involve counsel and law enforcement (FBI or IC3) before any payment, so that you know whether, and to whom, money is going.
- Benchmark the fees. Ask for an itemized invoice that separates labor, tooling and any pass-through costs. An $8,200 ransom billed as a $150,000 "recovery" should have been caught by a basic cost breakdown.
- Lower the stakes of decryption. Immutable, offline and tested backups make the recovery vendor's decryption claims far less important and remove most of the pressure fraudulent vendors exploit.
- Look back at past incidents. If you used MonsterCloud between 2018 and 2023, review your incident records, invoices and any insurance or regulatory filings that said no ransom was paid. Contact counsel and the FBI if anything you reported may have been inaccurate.
Sources: DOJ charges ransomware recovery CEO for secretly paying ... | Office of Public Affairs Known Cybersecurity Expert and Owner of... | Ransomware recovery CEO charged over secret ransom payments | MonsterCloud Owner Charged With Secretly Paying ... | Ransomware remediation company owner charged ... - SC Media | MonsterCloud Owner Accused of Billing Over $19M While Secretly Payi... | MonsterCloud Owner Charged in Alleged $19M Fraud | MonsterCloud CEO Zohar Pinhasi charged with Threadlinqs