The DOJ accuses MonsterCloud CEO Zohar Pinhasi of secretly paying ransomware gangs for decryption keys while charging victims hefty recovery fees.
Zohar Pinhasi, owner of Florida-based ransomware recovery firm MonsterCloud LLC, faces federal charges over allegations that he misled businesses about how the company recovered encrypted data. Pinhasi, who also used the names Zack Silver and Zack Green, appeared in federal court in Brooklyn on October 7 to face charges over his company’s ransomware recovery services.
According to the indictment (PDF), Pinhasi claimed MonsterCloud could recover encrypted files without paying a ransom. Prosecutors allege he instead paid the attackers for decryption keys and charged clients much higher fees.
Pinhasi faces two wire fraud charges and one count of conspiracy to commit wire fraud. If convicted on all three counts, he could face a maximum of 60 years in prison, with each count carrying a potential sentence of up to 20 years.
Earlier Scrutiny of MonsterCloud
The charges also create an unusual link to Hackread.com’s own archive. In February 2019, Hackread.com published a ransomware prevention article written by Pinhasi as a guest author in his capacity as MonsterCloud’s CEO. In that article, he warned readers about ransomware risks and discussed ways to protect systems from attacks.
Pinhasi’s author profile on Hackread.com described him as an ethical hacker, cyber counter-cyberterrorism expert, ransomware recovery expert, former IT security intelligence officer for the Israeli military and CEO of MonsterCloud, with more than 25 years of cybersecurity and enterprise IT experience.
Pinhasi also appeared in earlier public interviews discussing ransomware recovery and MonsterCloud’s work, including a 2019 video interview in which he spoke about ransomware incidents, recovery services and victim response.
Later that same year, ProPublica investigated MonsterCloud and other recovery firms that advertised their ability to restore encrypted files. The investigation found that MonsterCloud paid ransomware attackers in some cases, sometimes without telling clients.
The US Department of Justice (DOJ) now alleges that Pinhasi claimed to have proprietary decryption technology when, in fact, he paid attackers for decryption keys. The indictment also cites a May 2019 exchange in which an allegedly paid MonsterCloud spokesperson asked Pinhasi whether the company had proprietary decryption software. Pinhasi allegedly replied that it did not.
Secret Payments and Inflated Fees
According to the DoJ’s press release, MonsterCloud claimed it could recover data using proprietary tools and advanced decryption techniques. Pinhasi allegedly lacked specialized technology to decrypt the affected files and instead contacted the attackers for decryption keys, which employees then used in attempts to recover clients’ files.
In August 2023, Pinhasi allegedly paid a ransomware attacker $8,200 and charged the customer $150,000. In a separate case, he allegedly paid $236,000 but billed the customer $380,000. According to the indictment, he charged clients more than $19 million and paid over $8 million to attackers.
“As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim’s crisis into his own profit center,” said FBI Assistant Director James C. Barnacle Jr. “This deception is unacceptable, and the FBI is committed to ensuring accountability for those who choose to victimize the very people who trusted them for help.”
The FBI and CISA advise against paying ransoms (PDF), as payment does not guarantee that files will be recovered or that stolen data will not be leaked. The FBI is investigating the case. Although Pinhasi has been charged but is presumed innocent unless proven guilty in court.

