Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Recovery CEO Charged in Alleged Secret Ransom Payments Scheme

Person in business attire walks into/out of government building with neutral expression.

"As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re‑victimized his clients while extracting a hefty profit for himself," U.S. Attorney Joseph Nocella Jr. said.

U.S. charges and courtroom status

On September 23 a federal grand jury in the Eastern District of New York returned an indictment charging Zohar Pinhasi, 50, also known by the names "Zack Silver" and "Zack Green," with one count of conspiracy to commit wire fraud and two counts of wire fraud. The indictment alleges a scheme that ran from June 2018 to June 2023. Pinhasi surrendered, pleaded not guilty at an arraignment in federal court in Brooklyn, and was released on a $2 million bond. If convicted, he faces up to 20 years in prison.

Allegations about MonsterCloud's recovery methods

Prosecutors say Pinhasi owned and operated MonsterCloud LLC, a Florida‑based ransomware remediation company that marketed tools and techniques for recovering encrypted data without paying cybercriminals. The indictment alleges that, contrary to those claims, Pinhasi and co‑conspirators had no proprietary decryption technology and instead contacted ransomware operators and paid them for decryption keys, then used those keys to restore customers' files.

The indictment notes that some MonsterCloud contracts disclosed the company might communicate with or pay cybercriminals, but it asserts those contracts represented such contact would occur only if MonsterCloud could not decrypt a customer's files by other means. Prosecutors say dealing with the attackers was usually MonsterCloud’s first step in obtaining decryption keys.

Financial examples and totals cited by prosecutors

Prosecutors provided concrete examples to illustrate the alleged mismatch between payments to attackers and fees charged to victims:

  • In one cited incident, Pinhasi allegedly paid a ransomware gang about $8,200 and charged the victim approximately $150,000.
  • In another, prosecutors say he paid roughly $236,000 and charged the customer about $380,000.

Across the scheme, the indictment alleges Pinhasi and his co‑conspirators facilitated more than $8 million in ransom payments while charging hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services. The indictment also alleges MonsterCloud used decrypted sample files obtained from the ransomware operations as "recovery proofs" to convince victims it could restore their data.

2019 ProPublica investigation and security researcher experiment

The indictment and current charges echo concerns previously raised in a 2019 ProPublica investigation. That article reported that security researcher Fabian Wosar and another researcher created a test ransomware, posed as victims, and supplied ransom notes containing email addresses they controlled. According to ProPublica, the attacker‑controlled accounts soon received anonymous messages offering to pay the ransom; Wosar traced the requests to data recovery firms, including MonsterCloud and Proven Data.

Pinhasi disputed the characterization reported by ProPublica, denying that MonsterCloud promised in advance it could decrypt files or that it misled customers. He told ProPublica that MonsterCloud's recovery methods varied by case and declined to disclose them, calling the techniques a "trade secret."

How victims, remediation providers, and federal prosecutors are affected

Victims: Hundreds of companies in the United States and Canada are identified in the indictment as customers; prosecutors say those organizations were charged for recovery services while ransom payments were being made on their behalf, sometimes at orders of magnitude higher than the ransom itself.

Remediation providers: The allegations put a spotlight on transparency around recovery methods—contracts that disclose possible contact with attackers but state it will be a last resort are a specific focus of the indictment, which contends those disclosures did not reflect actual practice.

Federal prosecutors: The U.S. Attorney's Office has framed the case as part of an effort to hold both ransomware operators and those who profit from them accountable. "Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity," the U.S. Attorney said.

What happens next is procedural but consequential: the defendant has pleaded not guilty and remains released on bond pending further proceedings; the indictment lays out a multi‑year timeline and dollar amounts that prosecutors will rely on in court. BleepingComputer reported that attorneys Christopher Clark and Rodney Villazor represent Pinhasi and were contacted for comment.

Original story