"By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," U.S. Attorney Joseph Nocella, Jr. said.
Zohar Pinhasi and MonsterCloud: the indictment
The U.S. Department of Justice announced charges on Wednesday against a 50-year-old U.S. and Israeli national, identified as Zohar Pinhasi (aka Zack Silver and Zack Green), accusing him of defrauding ransomware victims while operating a Florida company called MonsterCloud. Pinhasi has been charged with two counts of wire fraud and one count of wire fraud conspiracy. Each count carries a potential sentence of up to 20 years in prison if he is convicted.
Alleged method: promises of proprietary tools, secret ransom payments
Prosecutors say the central deception was a mismatch between MonsterCloud’s public claims and its private actions. MonsterCloud’s website marketed "advanced decryption techniques and cutting-edge technology" to restore data and advised clients under a "Should I Pay The Ransom?" heading that "Paying a ransom to cybercriminals does not guarantee a positive outcome. In fact, it only serves to encourage and reward their illegal behavior." In a Q&A on the site, the company answered the question "Do you pay ransoms on behalf of your clients to recover data?," stating: "While we strongly advocate not paying ransoms yourselves, we have extensive experience working with ransomware perpetrators and sometimes resort to other means to resolve the ransomware incident for our clients. All terms are disclosed in our service contract."
According to the indictment, those public statements were false. Rather than possessing "specialized tools" to decrypt files without negotiating with attackers, Pinhasi is alleged to have paid cybercriminals to obtain decryptors and then represented to clients that recovery was accomplished through proprietary techniques.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageFinancial scale and case examples
The government alleges a substantial gap between what MonsterCloud charged clients and what it actually paid to attackers. The indictment states Pinhasi billed clients more than $19 million while making ransom payments of more than $8 million to cybercriminals. Prosecutors highlighted two specific incidents: in August 2023, a ransom payment of approximately $8,200 was followed by a client bill of roughly $150,000; and in or around October 2021, a ransom payment of about $236,000 was accompanied by a charge to the customer of about $380,000.
Government response: DOJ and FBI statements
The U.S. Attorney for the Eastern District of New York framed the case as conduct that compounded victims' harm. "By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," U.S. Attorney Joseph Nocella, Jr. said in the announcement. The Federal Bureau of Investigation also weighed in: Assistant Director James C. Barnacle Jr. said, "As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim's crisis into his own profit center. This deception is unacceptable."
What this means for affected clients, cybersecurity teams, and policymakers
- Affected clients and procurement leaders: Organizations that hired MonsterCloud and were billed for recovery services will now contend with two immediate issues — the legal status of the vendor relationship and the possibility that recovery work relied on paid decryptors rather than internal remediation. The indictment identifies direct monetary differences (e.g., $8,200 vs. $150,000; $236,000 vs. $380,000) that clients can point to when reviewing contracts and seeking remedies.
- Technologists and security teams: Security teams that depended on a vendor’s claim of "proprietary tools" will likely reassess reliance on outside recovery promises and scrutinize contractual language that purports to disclose "all terms" for resolution. The alleged practice of paying threat actors and then billing clients at a premium raises questions about technical transparency, chain-of-custody for decryptors, and whether underlying threats were actually remediated, not merely reversed.
- Policymakers and regulators: For regulators and law enforcement, the case presents a prosecutorial focus on deceptive billing practices tied to cyber incident response. The charges — wire fraud and wire fraud conspiracy — and the public statements by prosecuting authorities signal that vehicles of post-incident recovery and vendor conduct will be subject to criminal scrutiny when client deception is alleged.
The indictment frames an accusation of a business model that, prosecutors say, monetized victims' vulnerability while disguising the true means of recovery. As the legal process unfolds, the record assembled by the DOJ and FBI — specific payment amounts, client bills, and public statements from the vendor’s website — will be central to proving whether those allegations meet the threshold for criminal conviction.




