MonsterCloud Owner Charged After Secretly Paying Ransoms While Billing Clients $19 Million for 'Decryption'

Zohar Pinhasi told ransomware victims his company could unlock their data without paying criminals. Federal prosecutors say he was paying the criminals all along, then marking up the bill by as much as 1,700 percent.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 4 min read
Illustration: A polished corporate office at night
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Zohar Pinhasi, 50, owner of ransomware recovery firm MonsterCloud, appeared in a New York federal court on wire fraud and wire fraud conspiracy charges.
  • Prosecutors allege Pinhasi paid more than $8 million in ransoms to criminal groups while telling clients his firm used proprietary tools that made payments unnecessary.
  • In one documented instance, he paid a ransom of roughly $8,200 and then billed the victim approximately $150,000, a markup of around 1,700 percent.
  • Pinhasi allegedly collected more than $19 million in total client fees across the scheme.
  • Also known as "Zack Silver" and "Zack Green", Pinhasi is a US and Israeli national whose case sits at the uglier end of the ransomware recovery market.

Ransomware works like this: criminals break into a company's systems, scramble every file, and demand payment for a digital key to restore them. The panic is immediate, and a cottage industry of recovery firms has grown up to help. Zohar Pinhasi, federal prosecutors allege, built his business on exploiting that panic.

Pinhasi ran MonsterCloud, a company with offices in the United States and Israel, and marketed it as a way out for victims who didn't want to deal with criminals directly. His pitch, according to the indictment unsealed in New York, was that MonsterCloud used proprietary decryption technology to restore data without ever touching a ransom payment.

The reality, prosecutors say, was the opposite. Pinhasi allegedly contacted the same ransomware groups that had attacked his clients, paid them quietly for decryption keys, then used those keys to restore data while billing the client at a steep premium. The client was told they'd been saved from paying criminals. They'd simply paid more to an intermediary who paid the criminals anyway.

How much did victims overpay?

One case in the indictment is stark: Pinhasi allegedly paid a ransomware affiliate around $8,200 and invoiced the victim $150,000. Across the whole scheme, prosecutors claim he paid out more than $8 million in ransoms while pulling in more than $19 million from clients.

That gap, roughly $11 million, is the alleged fraud. The victims didn't just fund criminal hackers. They paid a premium to do it without knowing.

Figure Amount
Total ransom payments alleged Over $8 million
Total client fees alleged Over $19 million
Alleged margin Approximately $11 million
Single-case ransom paid ~$8,200
Same-case client bill ~$150,000

Assistant Attorney General A. Tysen Duva described it bluntly: "The defendant is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again and committed additional fraud, harming the victim again."

Pinhasi faces wire fraud and wire fraud conspiracy counts, each carrying potential sentences of decades in prison.

What does this mean for ransomware victims shopping for help?

The recovery market carries its own risks. Legitimate incident-response firms exist and do good work, but a vendor's claim to avoid ransom payments is easy to make and hard for a panicked victim to verify. We covered the arrest of a Qilin ransomware suspect on 10 October in our story on the Japan extradition, and the group's continued pace is a useful reminder of how many organisations are under pressure right now and potentially ready to trust any firm that promises a clean exit.

If your organisation is hit, the FBI recommends contacting law enforcement before paying or hiring a recovery vendor. No legitimate firm should discourage that call.

Common questions

Did paying MonsterCloud mean victims also funded the hackers?

That's what prosecutors allege. Pinhasi's company is accused of secretly paying the ransom on the victim's behalf and billing the victim a much larger fee, so the criminal groups collected their money and MonsterCloud collected the difference.

How can someone tell whether a recovery firm is legitimate?

Ask for a written breakdown of the recovery method before signing anything, check whether the firm has a verifiable track record, and report the incident to the FBI's Internet Crime Complaint Center (IC3) first. Legitimate vendors won't object to law enforcement involvement.

© 2026 Threat Vectr