MonsterCloud ransomware-recovery fraud: owner Zohar Pinhasi charged in EDNY with secretly paying the hackers
By Sethu Satheesh · 9 Oct 2026 · 16 min read
Source: www.justice.gov
Threat Actor: Unknown — the ransomware operators MonsterCloud paid are unidentified; the accused, Zohar Pinhasi, is a charged defendant, not a threat actor · Target: MonsterCloud's own clients — hundreds of ransomware-victim companies across the US and Canada, including two EDNY firms (a home-decor company and a display manufacturer)
Executive Summary
On October 7, 2026, Zohar Pinhasi — the owner and chief executive of the Florida ransomware-remediation company MonsterCloud LLC — was arraigned in federal court in Brooklyn on wire fraud charges, surrendered to authorities, pleaded not guilty, and was released on a $2 million bond.12 A grand jury in the Eastern District of New York had returned the indictment two weeks earlier, on September 23, 2026, under docket number 26-CR-271 before United States District Judge Ramon E. Reyes, Jr.3 Pinhasi, 50, a dual national of the United States and Israel who used the aliases "Zack Silver" and "Zack Green," is charged with one count of conspiracy to commit wire fraud and two counts of wire fraud, each carrying a statutory maximum of 20 years in prison.13
The charged scheme ran from approximately June 1, 2018 to June 30, 2023.3 According to the indictment, MonsterCloud marketed itself as a principled, technical alternative to paying cybercriminals: its website told victims not to pay ransoms and claimed the company could recover encrypted data using "advanced decryption techniques and cutting-edge technology" and "proprietary tools."13 In fact, prosecutors allege, Pinhasi had no such technology. He secretly contacted and paid the very ransomware operators who had attacked each client, obtained a decryption key, had MonsterCloud employees run it, and then billed the client a fee that was often many times larger than the ransom he had quietly paid. In one cited transaction he paid an $8,200 ransom and charged the client roughly $150,000 — nearly twenty times the ransom; in another he paid about $236,000 and charged roughly $380,000.13 Across the scheme, the indictment alleges, hundreds of companies in the United States and Canada collectively paid MonsterCloud more than $19 million while Pinhasi paid more than $8 million in ransoms, often without informing or consulting the clients before doing so.3
The strongest evidence described in the charging document is Pinhasi's own words. In May 2019 a paid testimonial spokesperson asked Pinhasi whether MonsterCloud actually had proprietary decryption software; he answered in writing, "MonsterCloud doesn't hold any Proprietary technology [to] decrypt the ransomware data," offering to "explain further in [] phone conversations."13 The case is built not on unmasking an anonymous hacker but on a lawful company's own paper trail — its marketing copy, its client contracts, its internal euphemisms, its bank records and that 2019 admission. Those same concerns were documented publicly more than three years before the federal investigation file opened: ProPublica's May 2019 investigation "The Trade Secret" reported that MonsterCloud and similar firms almost always just paid the hackers, a finding Pinhasi disputed at the time.4
The matter also illustrates how a derived number hardens into a reported fact. SecurityWeek headlined its coverage "Fake Decryption Tools Masked $11M Markup," but the indictment never states an "$11 million markup"; the figure is the arithmetic gap between "more than $19 million" charged and "more than $8 million" paid, both qualified as "over," and it conflates markup with profit.53 The charges are allegations, and Pinhasi is presumed innocent unless and until proven guilty.1
Weekly Digest
Get the next investigation in your inbox
New research, once a week. No vendor pitches.
Verification of Claims
-
Claim: Pinhasi was indicted in EDNY on one count of conspiracy to commit wire fraud and two counts of wire fraud. → Verified → The indictment (26-CR-271, filed September 23, 2026) charges Count One (conspiracy to commit wire fraud, 18 U.S.C. § 1349) and Counts Two and Three (wire fraud, 18 U.S.C. § 1343); the DOJ press release and BleepingComputer report the same structure.132
-
Claim: Pinhasi pleaded not guilty and was released on a $2 million bond. → Verified → The DOJ press release states he was arraigned on October 7, 2026 before Magistrate Judge Peggy Cross-Goldenberg but does not give the plea or bond.1 BleepingComputer reports that he surrendered, pleaded not guilty, and was released on a $2 million bond.2
-
Claim: The scheme produced an "$11 million markup." → Unverified (as a stated figure) → No primary source states $11 million. It is the difference between two "over" figures — "more than $19 million" charged and "more than $8 million" in ransoms — appearing only in SecurityWeek's headline, not its body or the indictment.35
-
Claim: Pinhasi secretly paid ransomware operators and billed clients a large markup while claiming proprietary decryption technology. → Partially verified → This is the core allegation of the indictment, supported by Pinhasi's quoted May 2019 admission and specific transaction examples.13 It remains an allegation; no trial or conviction has occurred, and Pinhasi previously disputed the equivalent 2019 reporting.4
-
Claim: ProPublica reported the same conduct in 2019. → Verified → ProPublica's May 15, 2019 investigation "The Trade Secret" named MonsterCloud and reported it paid ransoms while professing proprietary recovery; researcher Fabian Wosar's sting traced ransom-payment offers back to the firm.4
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| June 1, 2018 | Pinhasi / MonsterCloud | Start of the charged scheme to defraud | 3 |
| May 15, 2019 | ProPublica | "The Trade Secret" published, reporting MonsterCloud paid ransoms while claiming proprietary recovery | 4 |
| May 2019 | Pinhasi | Paid spokesperson asks if MonsterCloud has proprietary decryption software; Pinhasi replies in writing it holds no proprietary technology to decrypt ransomware data | 13 |
| April 26, 2021 | Victim 1 / Pinhasi | Count Two wire: ~$175,000 transferred from Victim 1 (EDNY home-decor company) to Pinhasi's Florida bank account | 3 |
| August 2, 2021 | Victim 2 / Pinhasi | Count Three wire: telephone call between a Victim 2 representative (EDNY display manufacturer) and Pinhasi in Florida | 3 |
| October 2021 | Pinhasi | Pays ~$236,000 ransom, charges client ~$380,000 (markup of nearly $150,000) | 3 |
| August 2023 | Pinhasi | Pays ~$8,200 ransom, charges client ~$150,000 (nearly twenty times the ransom) | 13 |
| September 23, 2026 | EDNY grand jury | Indictment returned and filed (not sealed); case assigned to Judge Ramon E. Reyes, Jr. | 3 |
| October 7, 2026 | DOJ / Pinhasi | Pinhasi arraigned in Brooklyn, surrenders, pleads not guilty, released on $2M bond; charges announced | 12 |
| October 7-8, 2026 | Press | BleepingComputer, The Register and SecurityWeek report the charges | 256 |
Operation Anatomy
The indictment describes a two-stage commercial process layered on top of a simple deception: MonsterCloud bought decryption keys from the attackers and resold the result as the product of its own technology.
Intake and the "no-ransom" pitch
Prospective clients were businesses already in crisis — their files encrypted by ransomware (the operators' use of Data Encrypted for Impact, T1486) and often unable to operate.3 Many found MonsterCloud through its website, which discouraged paying ransoms — warning that payment would not guarantee recovery, might encourage further attacks, and "rewarded illegal behavior" — and claimed MonsterCloud could "recover their data without succumbing to ransom demands" using "advanced decryption techniques and cutting-edge technology."13 The Register noted the site also billed MonsterCloud as "the most sophisticated Counter Cyber Terrorism team in the world."6 Multiple clients engaged the company specifically because they did not want to pay a criminal and would not have authorized any such payment.3
The analysis phase and "recovery proofs"
A MonsterCloud "Controller" (identified in the indictment as Employee-1) handled intake and, at Pinhasi's direction, quoted an "analysis" fee of roughly $2,500 to $10,000, backed by a money-back guarantee.3 MonsterCloud obtained the attacker's ransom note and a sample of encrypted files (usually two) from the client, then returned decrypted samples as "recovery proofs" — presented as evidence that MonsterCloud's technology could recover the data. In many instances, prosecutors allege, Pinhasi had simply forwarded the sample files to the cybercriminal and received the decrypted samples back, without disclosing that no proprietary technology was involved.3
Upsell to "full" recovery
The analysis "success" was the hook. It induced clients to contract for "full" ransomware recovery — a far more expensive service that the indictment says could cost up to two or more times the ransom.3 Pinhasi represented that MonsterCloud possessed specialized decryption methods it could not disclose because they were "trade secrets" involving "proprietary means and methods." It had no such methods.3
Paying the attacker, concealing the payment
To actually recover data, Pinhasi contacted and paid the ransomware operators in exchange for a decryption key (or keys), which MonsterCloud employees then ran against the client's files.3 He generally did not disclose that MonsterCloud paid the criminals, and directed employees and contractors to call the attacker's decryptor a "recovery tool" rather than a "decryptor."3 Some client contracts stated MonsterCloud would contact a cybercriminal "only once all possible means of directly decrypting Client's files have been exhausted"; in fact, dealing with the criminals was generally Pinhasi's first step and the standard way he obtained both "recovery proofs" and decryption keys.3
Billing the markup
MonsterCloud's fee was typically far higher than the ransom it had quietly paid, and the difference — plus the ransom — was passed to the client as the cost of "remediation," without disclosing the ransom payment or the spread.3 Over the scheme, the indictment alleges, Pinhasi facilitated dozens of ransom payments totaling more than $8 million, while hundreds of companies collectively paid MonsterCloud more than $19 million.3
Loading diagram...
Accused
Name: Zohar Pinhasi, 50, of Hollywood, Florida1 Aliases: "Zack Silver" and "Zack Green"13 Nationality: Dual citizen of the United States and Israel13 Role: Owner and Chief Executive Officer of MonsterCloud LLC; per the indictment he managed employees, set client prices, and personally communicated with cybercriminals on behalf of the company3 Status: Charged, not convicted. Arraigned October 7, 2026; surrendered, pleaded not guilty, released on $2 million bond. Presumed innocent unless and until proven guilty.12
Charges: Count One — conspiracy to commit wire fraud (18 U.S.C. § 1349); Counts Two and Three — wire fraud (18 U.S.C. § 1343, and § 2). Each count carries a statutory maximum of 20 years' imprisonment; the DOJ release frames the exposure as "up to 20 years," while The Register notes each of the three counts carries up to twenty years.136 The indictment also carries a criminal forfeiture allegation under 18 U.S.C. § 981(a)(1)(C), 28 U.S.C. § 2461(c) and 21 U.S.C. § 853(p).3
Co-conspirators: The indictment refers to "multiple co-conspirators" whose identities are "both known and unknown to the Grand Jury," including MonsterCloud employees and contractors; none is charged in this indictment, and the record does not state whether any is cooperating.3
Attribution and naming basis: Named because charged by a federal grand jury and publicly identified by the Department of Justice. This is the accused in a fraud prosecution, not a "threat actor" in the intrusion sense; the ransomware operators MonsterCloud paid are unidentified in the record.
MITRE ATT&CK: No ATT&CK table is forced here. ATT&CK is an adversary-behaviour framework for intrusions, and the charged conduct is a white-collar wire-fraud scheme rather than a technical compromise carried out by the accused. The only ATT&CK-relevant element is the ransomware the clients had already suffered — Data Encrypted for Impact (T1486) — which is context for the victims' predicament, not a technique attributable to Pinhasi.
Technical Indicators
# This is a wire-fraud prosecution, not an intrusion. No file hashes,
# malware samples, C2 domains or network IOCs were disclosed in the
# indictment or the press release. What follows are the behavioural and
# documentary markers of the charged scheme, useful for recognising a
# ransomware-remediation firm operating this way.
marketing_red_flags:
- "'recover their data without succumbing to ransom demands'"
- "'advanced decryption techniques and cutting-edge technology'"
- "'proprietary tools' / 'proprietary means and methods' described as 'trade secrets'"
- "'the most sophisticated Counter Cyber Terrorism team in the world'"
- "website testimonials, including from at least one compensated spokesperson"
internal_euphemism:
- "attacker's decryptor relabelled a 'recovery tool' to avoid the word 'decryptor'"
contract_vs_conduct:
- "contract: contact cybercriminal 'only once all possible means of directly decrypting Client's files have been exhausted'"
- "conduct: contacting the cybercriminal was generally the first step"
documentary_admission:
- "May 2019, Pinhasi in writing: 'MonsterCloud doesn't hold any Proprietary technology [to] decrypt the ransomware data'"
financial_pattern:
- "ransom ~$8,200 billed ~$150,000 (August 2023)"
- "ransom ~$236,000 billed ~$380,000 (October 2021)"
- "Count Two: ~$175,000 wire from Victim 1 (EDNY) to Pinhasi's Florida bank account (April 26, 2021)"
aliases:
- "Zack Silver"
- "Zack Green"
file_hashes: none disclosed
network_iocs: none disclosedLegal and Regulatory Response
Charges and court. United States v. Zohar Pinhasi, E.D.N.Y. Docket No. 26-CR-271 (RER), before United States District Judge Ramon E. Reyes, Jr. (Magistrate Judge Taryn A. Merkl on the indictment). The grand jury returned the indictment on September 23, 2026; it was not sealed, and no arrest warrant was ordered — consistent with Pinhasi's self-surrender at his October 7, 2026 arraignment before Magistrate Judge Peggy Cross-Goldenberg.132 The investigation file number (F. #2022R00375) indicates the matter was opened by 2022.3
Counts. One count of conspiracy to commit wire fraud (18 U.S.C. § 1349) and two counts of wire fraud (18 U.S.C. § 1343); Count Two rests on a ~$175,000 wire from Victim 1 to Pinhasi's Florida account on April 26, 2021, and Count Three on an August 2, 2021 interstate telephone call with a Victim 2 representative. A criminal forfeiture allegation seeks proceeds of the offenses.3
Agencies and prosecutors. The FBI New York Field Office investigated; Assistant Director in Charge James C. Barnacle, Jr. is quoted in the release. The case was announced by EDNY U.S. Attorney Joseph Nocella, Jr. and Criminal Division head A. Tysen Duva, with assistance from the Justice Department's Office of International Affairs. It is handled by the EDNY National Security and Cybercrime Section (Assistant U.S. Attorneys Alexander F. Mindlin and Lindsey R. Oken) with Senior Trial Attorneys Brian Mund and Vasantha Rao of the Computer Crime and Intellectual Property Section; Assistant U.S. Attorney Laura Mantell handles forfeiture.13
Defense. BleepingComputer identifies Pinhasi's attorneys as Christopher Clark and Rodney Villazor; no defense statement had been reported as of October 8, 2026.2
Regulatory. No civil regulatory action (FTC, SEC or state) tied to MonsterCloud had been announced as of October 10, 2026; the matter is a federal criminal prosecution. The 2019 ProPublica reporting did not result in any publicly announced charges at the time.4
Impact Assessment
- Confirmed (by indictment, as allegations): Hundreds of companies across the United States and Canada collectively paid MonsterCloud more than $19 million; Pinhasi facilitated dozens of ransom payments totaling more than $8 million.3
- Confirmed (procedural): Pinhasi charged on three counts, arraigned, released on $2 million bond, pleaded not guilty.12
- Reported, not independently confirmed: The characterization of an "$11 million markup" — a derived figure, not stated in any primary source.5
- Estimated: Individual-transaction harm is illustrated by two examples (roughly 20x and ~1.6x the ransom); the full per-victim distribution is not in the public record.3
- Named victims: Only two are identified by sector and venue — a home-decor company (Victim 1) and a display manufacturer (Victim 2), both in the EDNY. The hundreds of other affected companies are not named.3
- Unknown: Whether any co-conspirator is cooperating; whether further charges or additional defendants will follow; how investigators first identified the scheme and how they matched ransom payments to client charges (the indictment describes no cryptocurrency tracing, seized infrastructure, or cooperating witness).3
- Original observation: The August 2023 markup example in the indictment falls roughly six weeks after the charged conspiracy period's stated end (June 30, 2023); both scheme dates are pleaded as "approximate and inclusive."3
Lessons and Defensive Recommendations
For organizations hit by ransomware (leadership and incident response):
- Treat a vendor's promise to decrypt without paying as a claim to be tested, not a differentiator to be trusted. The indictment alleges MonsterCloud's "proprietary" recovery was, in practice, buying the attacker's key and reselling it at a markup.3
- Read the contract clause on attacker contact literally and demand disclosure. A term permitting contact "only once all possible means of directly decrypting Client's files have been exhausted" is meaningless if, as alleged here, contacting the criminal is the first step. Require written, contemporaneous disclosure of any ransom payment and its amount.3
- Watch the language. An internal instruction to call a decryptor a "recovery tool" is a tell that the real mechanism is being hidden.3
- For public-sector and regulated victims, an undisclosed ransom payment can carry its own legal exposure (for example, sanctions-screening obligations on the recipient). A remediation firm that pays quietly on your behalf may transfer that risk to you without your knowledge.
For insurers, brokers and procurement:
- Require remediation vendors to attest, in writing, whether recovery will or may involve paying the threat actor, and to itemize ransom versus service fees. The charged harm here is precisely the concealed spread between the two.3
For journalists and researchers:
- A derived number is not a reported fact. The "$11 million markup" exists only as the arithmetic gap between two "over" figures and appears in a headline, not in the indictment; repeating it as a stated figure, or equating markup with profit, overstates the record.35
- Investigative reporting can precede prosecution by years. ProPublica documented this conduct in 2019; the federal case followed. Flagging a practice early, with sourcing, retains value even when charges lag.4
Sources
Footnotes
-
U.S. Attorney's Office, Eastern District of New York — Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients — October 7, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21
-
BleepingComputer — Ransomware recovery CEO charged over secret ransom payments — Lawrence Abrams, October 7, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9
-
United States v. Zohar Pinhasi, Indictment, E.D.N.Y. 26-CR-271 (Document 1, filed September 23, 2026) — September 23, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46 ↩47 ↩48 ↩49 ↩50
-
ProPublica — The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers — Renee Dudley and Jeff Kao, May 15, 2019 ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
SecurityWeek — Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme — Ionut Arghire, October 8, 2026 ↩ ↩2 ↩3 ↩4 ↩5
-
The Register — Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead — Simon Sharwood, October 8, 2026 ↩ ↩2 ↩3
Related Research
Two former US airmen got 111 and 78 months for a BEC and card-fraud scheme that diverted $1.68M and $720K wires. The docket shows conspiracy pleas, overlapping restitution and a pending appeal; 15 victims and $2.4M are not DOJ figures.
A $16M forfeiture filing this week named five convicted Scattered Spider defendants. The court docket shows two of them — reported this month as "still facing charges" — were sentenced months ago, and that Elbadawy's own "October 2025 guilty plea" was, on the public record, a not-guilty plea.
LockBit, BlackSuit and Play didn't run their own servers. They rented them from a company in St Petersburg that answered no abuse reports and no takedown requests, and billed like any other host.