MonsterCloud Owner Charged With Secretly Paying Ransomware Demands
Florida MonsterCloud owner Zohar Pinhasi was charged with secretly paying ransomware ransoms and billing clients millions.
Federal prosecutors charged Zohar Pinhasi, 50, owner of Florida ransomware-recovery firm MonsterCloud, with wire fraud and conspiracy. He allegedly told clients the firm would not pay ransoms and had proprietary decryption tools, then secretly bought decryption keys from the attackers and billed far more than the ransom. In one August 2023 case he paid about $8,200 and charged roughly $150,000; overall he allegedly collected more than $19 million while paying out over $8 million. Each of the three charges carries up to 20 years; they remain allegations.
- Pinhasi faces two wire-fraud counts and one conspiracy charge, each up to 20 years.
- In August 2023 he allegedly paid about $8,200 and billed the client roughly $150,000.
- Prosecutors say clients paid over $19 million while he paid more than $8 million in ransoms.
- MonsterCloud advertised proprietary decryption and told clients not to pay ransoms.
Full article487 words · extracted from securityaffairs.com · click to collapse

MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery.
Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis.
Pinhasi (50) also used the names “Zack Silver” and “Zack Green,” which is a surprising number of aliases for someone running a legitimate ransomware recovery business. MonsterCloud ’s website told clients not to pay ransoms and promised that its team could recover encrypted data without dealing with cybercriminals. Prosecutors say the company was doing the exact opposite.
According to the indictment, Pinhasi claimed to have proprietary tools and advanced decryption techniques that let him crack ransomware without negotiating with attackers. He allegedly had none of that. Instead, he contacted the same cybercriminals who’d hit his client, paid them for a decryption key, then had MonsterCloud staff use that key and present the recovery as the product of his own technology.
“Pinhasi typically charged MonsterCloud’s clients a fee that was substantially higher than the ransom that MonsterCloud secretly paid.” reads the press release published by DoJ.
The math is where it gets ugly. Prosecutors cite one case from August 2023 where Pinhasi paid a ransom of roughly $8,200, then billed the client about $150,000 for the “service.” Across the whole scheme, he allegedly collected more than $19 million from clients while quietly paying out over $8 million in ransom money himself, pocketing the difference while selling the opposite of what he was actually doing.
“The defendant is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again and committed additional fraud, harming the victim again,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “This prosecution underscores the Department’s commitment to protecting ransomware victims, regardless of how these cyber ransoms occur.”
That phrase captures the real damage here. Ransomware victims are already dealing with locked files, operational chaos, and the gut punch of being extorted. Finding out afterward that your “ethical” recovery firm secretly paid your attacker and marked up the bill nearly twentyfold isn’t a service failure, it’s exploitation dressed up as rescue.
The FBI and CISA have clear guidance on ransomware payments: they do not recommend paying because it does not guarantee that the data will be decrypted, that the attackers will leave the network, or that stolen data will not be leaked.
Pinhasi faces two wire fraud charges and one conspiracy charge. Each charge carries a possible sentence of up to 20 years if he is convicted, but the charges are only allegations at this stage.
For anyone choosing a ransomware recovery company, claims about “proprietary decryption tools” should be a reason to ask more questions, not simply trust the vendor.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, MonsterCloud)