Security

The ransomware rescue firm that allegedly paid the criminals itself

(today) · 3 min read · By Future Technology · Edited by Nath Connell

Key takeaways

  • Zohar Pinhasi, owner of Florida firm MonsterCloud, faces two counts of wire fraud and one of wire fraud conspiracy
  • Prosecutors allege over 19 million dollars was billed to clients while over 8 million dollars went to ransomware operators
  • Examples cited include about 8,200 dollars paid and 150,000 dollars billed in August 2023
  • The case is an allegation and has not been tested in court

Imagine being hit by ransomware, hiring a specialist firm that promises to recover your files without paying criminals, and then learning the firm was paying them all along. That is what the US Department of Justice alleges about MonsterCloud, a Florida ransomware remediation company. The charges were announced on 8 October 2026 by the US Attorney's Office for the Eastern District of New York. Everything below is an allegation, and the case has not been tested in court.

The charges

Owner Zohar Pinhasi, also known as Zack Silver and Zack Green, is 50 and holds US and Israeli nationality. He faces two counts of wire fraud and one count of wire fraud conspiracy, each carrying up to 20 years in prison.

According to the report, MonsterCloud told victims not to pay ransoms and claimed to have proprietary tools and advanced decryption techniques. Prosecutors say it had no such tools. Instead, Pinhasi allegedly contacted the criminals, paid them for a decryptor, and billed his client far more. The firm's website said it sometimes used "other means" to resolve incidents, with terms set out in its contracts.

The numbers

The examples are stark. In August 2023, about $8,200 allegedly went to a threat actor while the client was billed about $150,000. In October 2021, about $236,000 allegedly went in ransom against a bill of about $380,000. Across the scheme, prosecutors allege more than $19 million was charged to clients and more than $8 million was paid to ransomware operators.

The uncomfortable part

Paying a ransom is legal in many places, though it carries sanctions risk and no guarantee of getting data back. The allegation here is about honesty. Clients who chose not to pay were allegedly steered into paying anyway, without knowing it, and with a markup. That is the opposite of informed consent, and it feeds the very criminals the clients were trying to avoid funding.

How to vet a recovery firm

If you ever need one, ask direct questions before signing:

  • How exactly will you recover the data, and can you show it working?
  • Do you ever communicate with or pay the attackers? Get the answer in writing.
  • Will you itemise any third-party costs at cost?
  • Report the incident to the FBI via ic3.gov, or to your national cyber agency, whatever the firm says.

The best defence is boring: offline, tested backups, so you never need a rescue firm at all. Our zero-day network device checklist covers the entry points ransomware crews still use.

More from Future Technology