"Pinhasi charged hundreds of clients more than $19 million and paid more than $8 million in ransom payments during a five-year period ending in 2023."
The indictment against Zohar Pinhasi and MonsterCloud
Federal prosecutors charged Zohar Pinhasi, owner and operator of MonsterCloud, with two counts of wire fraud and one count of wire fraud conspiracy, alleging a years‑long scheme to defraud organizations already victimized by ransomware. The indictment asserts that the dual U.S.-Israeli national claimed MonsterCloud had specialized proprietary tools that could decrypt and recover victims’ data without paying criminals — when no such tool existed, prosecutors say.
Pinhasi pleaded not guilty in federal court in Brooklyn, N.Y., was released on a $2 million bond and faces up to 60 years in prison. A federal judge granted a one‑month delay in trial proceedings while attorneys engage in plea negotiations; Pinhasi’s lawyer did not immediately respond to a request for comment, according to court reporting.
How prosecutors say the scheme worked
According to the indictment, MonsterCloud lured victims with an initial "analysis phase" fee between $2,500 and $10,000. After obtaining a client’s ransom note and a sample of encrypted files, Pinhasi or an employee allegedly provided decrypted samples back to the prospective client as proof that MonsterCloud could recover the data.
Prosecutors say that in many instances those decrypted samples were not produced by proprietary MonsterCloud tools but were instead obtained by sharing the sample files with the cybercriminals and receiving decryption samples in return. In practice, they allege, Pinhasi often contacted cybercriminals first and used client funds to pay ransoms without telling clients that a ransom payment had been made on their behalf.
The indictment further alleges that MonsterCloud then induced victims to buy full ransomware recovery services — in some cases charging up to two or more times the ransom — and that, over a five‑year period ending in 2023, Pinhasi charged hundreds of clients more than $19 million and used more than $8 million of that to make ransom payments.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSpecific examples and business practices cited by prosecutors
Prosecutors cite an August 2023 engagement in which Pinhasi charged a client approximately $150,000 while making a ransom payment of about $8,200 to recover the organization’s data. The indictment also notes Pinhasi used the monikers "Zack Silver" and "Zack Green" in some communications with cybercriminals.
MonsterCloud’s contracts allegedly stated the company would contact criminals only after "exhausting all other options," yet officials contend contacting criminals was frequently the first step MonsterCloud took to obtain access to encrypted files and decryption keys. The company’s public site remains active and includes a contact form and testimonials from law enforcement agencies and a former FBI official, according to the reporting.
Statements from law enforcement and outside researchers
U.S. Attorney Joseph Nocella Jr., for the Eastern District of New York, said in a statement: “By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re‑victimized his clients while extracting a hefty profit for himself.”
James C. Barnacle Jr., assistant director of the FBI, added: “Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim’s crisis into his own profit center.”
Independent observers quoted in the reporting were blunt. Jon DiMaggio, principal researcher at Arkem Cyber, told CyberScoop: “It baffles me that companies fall for this. I mean, they just got hacked and they go straight to a shady source.” The article also places Pinhasi’s alleged conduct in a broader context of shadowy ransomware response work, noting that a trio of former ransomware negotiators were sentenced to prison earlier this year for deceiving their employers’ clients and conspiring with ransomware affiliates.
What this means for technologists, affected enterprises, and law enforcement
- Technologists and security teams: The allegations underscore risks in outsourcing incident response. According to the indictment’s account, purported proof of recovery came from the same criminals who created the encryption, and remediation did not address the underlying threat.
- Affected enterprises and procurement leaders: The case highlights how vendors’ contractual language and marketing claims can mask payment practices and post‑incident costs; prosecutors say clients were charged up to two or more times the ransom and sometimes were not told when ransoms were paid on their behalf.
- Law enforcement and prosecutors: The Justice Department’s criminal case and public statements from the U.S. attorney’s office and the FBI signal continued prosecution of actors who exploit victims in ransomware incidents; the indictment and related sentencing of negotiators earlier this year indicate an enforcement focus on deceptive practices in the ransomware ecosystem.
The indictment and the details cited by prosecutors leave concrete, immediate questions for victims and buyers of remediation services: who within a recovery firm actually contacts the criminals, how often ransoms are paid without client disclosure, and whether contractual promises align with operational realities. With plea negotiations underway and a one‑month pause in the proceedings, the answers may emerge in court filings or at trial — and, for hundreds of clients named in the indictment, in damage assessments that have yet to be made public.




