Read as article
Ransomware Recovery CEO Charged for Secretly Paying Hackers
By @sharedot · · 8 pages
- Cybersecurity
- Ransomware
- Wire Fraud
- Monstercloud
- Zohar Pinhasi
Justice Department charged MonsterCloud owner Zohar Pinhasi with wire fraud for billing ransomware victims $19 million while secretly paying hackers.
What prosecutors say happened
The Justice Department on Wednesday charged Zohar Pinhasi, the 50-year-old U.S. and Israeli owner of Florida-based ransomware recovery firm MonsterCloud, with two counts of wire fraud and one count of wire fraud conspiracy. Prosecutors say he told victims he had "proprietary tools" and "advanced decryption techniques" that could restore their encrypted data without paying ransomware gangs. No such tools existed, according to the indictment — instead, Pinhasi allegedly contacted the same criminals who attacked his clients, paid their ransoms, and presented the purchased decryptors as the product of his own technology. U.S. Attorney Joseph Nocella Jr. said Pinhasi "re-victimized his clients while extracting a hefty profit for himself."
The math behind the alleged scheme
The alleged markup was dramatic. In another incident around October 2021, he allegedly paid approximately $236,000 and charged the customer about $380,000. Across all clients, prosecutors say he collected more than $19 million in fees while quietly paying out over $8 million in ransoms. FBI Assistant Director James C. Barnacle Jr. said Pinhasi "claimed to fix ransomware while never remediating the underlying threat" and "turned the victim's crisis into his own profit center."
A reversal exposed years earlier
The charges land with particular force because MonsterCloud's business model had already been scrutinized. A 2019 ProPublica exposé, cited by The Record, spotlighted the firm among companies defrauding ransomware victims. A researcher quoted in that article staged a sting by infecting his own device with ransomware and contacting MonsterCloud, which claimed it could decrypt the files and immediately offered to pay the fake attacker. Even a former deputy FBI director, John Pistole, who was paid to be the firm's spokesperson, told ProPublica in 2019 that paying ransoms "was the business model." At the time, Pinhasi denied lying to clients, calling his methods trade secrets.
The pitch contradicted its own website
MonsterCloud's public messaging told victims the opposite of what prosecutors say it did. A website section titled "Should I Pay The Ransom?" warned that paying "only serves to encourage and reward their illegal behavior," and the site advertised "advanced decryption techniques and cutting-edge technology." Yet a Q&A on the same site acknowledged the firm had "extensive experience working with ransomware perpetrators" and sometimes used "other means" to resolve incidents. According to Security Affairs, Pinhasi also used the aliases "Zack Silver" and "Zack Green." That contractual hedging language now sits at the center of the government's fraud case.
Why the concealment hurt victims twice
The alleged scheme stripped victims of informed decisions during a crisis. A client who never learns their attacker was paid never sees the negotiation history, never knows which ransomware group hit them, and never learns whether attackers retained stolen data or left backdoors behind. Paying a decryptor ransom also does nothing to fix how intruders got in. Local governments and police departments were among the defrauded victims, per ProPublica reporting cited by The Record. The FBI and CISA have long advised against paying ransoms, warning it does not guarantee decryption, network removal, or non-disclosure of stolen data.
What comes next and how to vet a recovery firm
Pinhasi faces up to 20 years per count if convicted, but the charges remain allegations that must be proved at trial; MonsterCloud did not respond to requests for comment. The case is the latest Justice Department push against the murky ransomware recovery industry — in May, two negotiators received four-year sentences for covertly running their own ransomware attacks while purporting to negotiate for victims. Organizations seeking incident response should ask how decryption actually works, require written disclosure of any ransom payment in contracts, verify insurer authorization early, and request references — because claims of proprietary decryption tools should prompt questions, not trust.
Sources
- therecord.media › DOJ charges ransomware recovery CEO for secretly paying hackers
- thehackernews.com › MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
- news.lavx.hu › MonsterCloud owner charged with billing victims $19 million while secretly paying ransoms
- securityaffairs.com › MonsterCloud Owner Charged With Secretly Paying Ransomware Demands