Ransomware Recovery CEO Indicted for Defrauding Victims, Pocketing Millions
Zohar Pinhasi, owner of MonsterCloud, faces federal charges for allegedly defrauding ransomware victims by falsely advertising proprietary decryption tools while secretly paying ransoms and pocketing millions.

Zohar Pinhasi, the owner of the so-called ransomware remediation company MonsterCloud, has been indicted on federal charges for allegedly defrauding clients who were already victims of ransomware attacks. Prosecutors claim Pinhasi falsely advertised that he could decrypt and recover victims’ data using specialized, proprietary tools, thereby avoiding the need to pay cybercriminals. However, the Justice Department stated that no such tool existed.
Instead of employing unique decryption technology, Pinhasi allegedly used his clients' fees to pay off cybercriminals directly. He is accused of recovering encrypted data without informing the clients that ransom payments had been made on their behalf. Over a five-year period ending in 2023, Pinhasi allegedly charged hundreds of clients more than $19 million and paid over $8 million in ransom payments. This scheme highlights how the ransomware economy can attract individuals seeking profit, operating in the shadows of recovery and extortion.
Pinhasi faces charges including two counts of wire fraud and one count of wire fraud conspiracy. He pleaded not guilty in a federal court in Brooklyn, New York, and was released on a $2 million bond. The Florida-based executive faces a potential sentence of up to 60 years in prison. Attorneys are reportedly engaged in plea negotiations, and a judge has granted a one-month delay in trial proceedings.
"By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," stated U.S. Attorney for the Eastern District of New York, Joseph Nocella Jr. The indictment details how Pinhasi and a MonsterCloud employee allegedly lured clients with an initial exploratory fee ranging from $2,500 to $10,000. Following this analysis phase, Pinhasi would provide encrypted samples to prospective clients as proof of MonsterCloud's decryption capabilities.
In reality, prosecutors allege that Pinhasi often shared sample files with the cybercriminals themselves to obtain decryption samples, without disclosing this to the client. This deceptive practice reinforced his false claims and induced clients to contract for the more expensive full ransomware recovery service, which could cost two or more times the ransom amount. In one instance in August 2023, Pinhasi allegedly charged a client approximately $150,000 while making a ransom payment of about $8,200.
Officials stated that Pinhasi used aliases such as "Zack Silver" and "Zack Green" in communications with cybercriminals. While MonsterCloud's contracts mentioned contacting cybercriminals as a last resort, it was often Pinhasi's initial step. The company secured contracts with hundreds of businesses in the United States and Canada and maintained an active website featuring testimonials from law enforcement agencies and a former FBI official.
This is not the first time Pinhasi's practices have come under scrutiny. An exposé by ProPublica in 2019 detailed similar allegations, where the company claimed to use its own recovery methods but instead paid ransoms without victim notification, even to law enforcement agencies. "Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim’s crisis into his own profit center," said James C. Barnacle Jr., assistant director of the FBI, emphasizing the commitment to accountability for those who exploit victims' trust.