"Pinhasi charged clients more than $19 million and paid more than $8 million in ransom payments," reads the Department of Justice's account of a scheme that, if the allegations are proven, traded on victims' hopes and industry language while concealing a simple reality: ransoms were being paid and a middleman kept the markup.
The DOJ indictment: wire fraud and an alleged deception
The United States Department of Justice has charged Zohar Pinhasi — who has used the names "Zack Silver" and "Zack Green" — in connection with an alleged long-running fraud tied to a Florida company called MonsterCloud. According to a DoJ press release quoted in the indictment, the charges "relate to Pinhasi’s claimed ability to decrypt ransomware without paying cybercriminals, purportedly using 'proprietary tools' and 'advanced decryption techniques' on behalf of distressed business owners who came to his company."
Rather than possessing such tools, the indictment alleges, "In fact, Pinhasi allegedly used a portion of his clients’ fees to pay off the ransomware attackers, and then kept the rest, often extracting a substantial markup." Pinhasi faces two counts of wire fraud and one count of wire fraud conspiracy; each count carries a potential maximum sentence of 20 years in prison if convicted.
How MonsterCloud presented itself, and what the record shows
MonsterCloud's website is cited directly in the indictment. The site uses language promising advanced technical capabilities and grand claims about the organization's nature: "At MonsterCloud, we are not a team of IT Experts. We are the most sophisticated Counter Cyber Terrorism team in the world." The indictment suggests those claims "rang hollow for years" and points to promotional material including paid testimonials.
The indictment notes that "MonsterCloud's website included 'testimonials' and other promotional content, including from at least one compensated spokesperson." That spokesperson reportedly contacted Pinhasi in May 2019 with questions about the firm's technical claims; Pinhasi is recorded in the indictment as responding, "MonsterCloud doesn't hold any proprietary technology [to] decrypt the ransomware data."

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageA documented example: $150,000 fee and an $8,200 ransom payment
The indictment offers at least one concrete client example to illustrate the alleged scheme. Prosecutors say Pinhasi charged a client $150,000, paid the ransomware operator $8,200, and "pocketed the rest" while not disclosing to the client that a ransom had been paid. That transaction is cited as representative of a pattern that the government alleges persisted for years, during which MonsterCloud billed more than $19 million and made more than $8 million in ransom payments.
FBI investigation and the possibility of co-conspirators
The Federal Bureau of Investigation is investigating the matter, and the indictment states that Pinhasi had "multiple co-conspirators, individuals whose identities are both known and unknown to the Grand Jury, including MonsterCloud employees and contractors." The language in the indictment leaves open the prospect of additional charges or further developments as the investigation continues.
What this means for ransomware victims, security teams, and insurers
- Ransomware victims: Businesses that sought help from third-party recovery firms will want to review invoices, receipts for ransom payments, and contracts closely to determine whether they were informed of ransom payments and whether fees matched services rendered.
- Security teams and incident responders: The case underscores a need to scrutinize vendor claims of "proprietary" decryption tools and to seek documentation and independent verification of techniques before relying on a single remediation pathway.
- Insurers and legal counsel: Where vendors acted as intermediaries in ransom payments, insurers and counsel will likely examine whether payments were authorized, disclosed, and consistent with policy terms or regulatory obligations.
The indictment paints a picture of a firm that sold a technical narrative while allegedly operating as a dealer between victim and criminal. The Department of Justice has framed the case as deception rather than successful innovation: promotional claims of "advanced decryption techniques" and "proprietary tools" contrast sharply with the government's portrayal of payments routed to attackers and profits retained by the service provider. With the FBI investigating and the indictment identifying potential co-conspirators, one clear question remains from the record the government has presented: how many corporate victims paid both ransoms and substantial fees without knowing the full transaction — and what will restitution, enforcement, or regulatory scrutiny look like if the allegations are proven?




