VYPR
breachPublished Oct 8, 2026· 1 source

Ransomware 'Fixer' Accused of Defrauding Victims Instead of Decrypting Files

A Florida man, Zohar Pinhasi, faces federal fraud charges for allegedly defrauding ransomware victims by claiming to possess decryption tools but instead pocketing client funds after paying ransoms.

The United States Department of Justice has charged Zohar Pinhasi, also known by aliases such as “Zack Silver” and “Zack Green,” with fraud. Pinhasi allegedly operated a Florida-based company named MonsterCloud, which purported to offer advanced decryption services for ransomware victims. Instead of employing proprietary tools as claimed, federal prosecutors allege that Pinhasi used a portion of his clients' fees to pay off the cybercriminals and then retained the remainder, often at a significant markup.

According to the DoJ's press release, MonsterCloud advised distressed business owners not to pay ransomware attackers directly, promising its own sophisticated methods for data recovery. However, the indictment details a pattern where Pinhasi would allegedly charge exorbitant fees while paying a fraction of that amount to the ransomware operators. In one particularly egregious example cited, a client was charged $150,000 for a ransom payment that only cost $8,200, with Pinhasi allegedly pocketing the substantial difference without disclosing the actual ransom payment.

This alleged scheme appears to have been lucrative, with prosecutors stating that Pinhasi charged clients over $19 million in total and paid out more than $8 million in ransom payments. MonsterCloud's website boasted about its use of "advanced decryption techniques and cutting-edge technology," even describing its team as "the most sophisticated Counter Cyber Terrorism team in the world." The indictment, however, paints a starkly different picture, suggesting these claims were hollow and misleading.

The DoJ's indictment includes evidence that Pinhasi himself admitted the lack of proprietary decryption technology. In May 2019, a spokesperson who had provided a paid testimonial for MonsterCloud contacted Pinhasi with questions about the company's practices. When asked directly if MonsterCloud possessed any proprietary software for decryption, Pinhasi allegedly responded, "MonsterCloud doesn't hold any proprietary technology to decrypt the ransomware data."

Pinhasi is facing serious federal charges, including two counts of wire fraud and one count of wire fraud conspiracy. If convicted, he could face up to twenty years in prison for each count. The Federal Bureau of Investigation (FBI) is leading the investigation into this case.

The indictment also suggests that Pinhasi did not act alone, noting that he had "multiple co-conspirators, individuals whose identities are both known and unknown to the Grand Jury, including MonsterCloud employees and contractors." This indicates that the investigation may expand, potentially leading to further charges against other individuals involved in the alleged fraudulent operation.

This case highlights a disturbing trend where individuals exploit the desperation of ransomware victims, not only by failing to provide promised services but by actively defrauding them. The sophisticated nature of ransomware attacks often leaves victims vulnerable and willing to pay significant sums for data recovery, making them prime targets for such scams.

Synthesized by Vypr AI