Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23 and arraigned Wednesday in federal court in Brooklyn. He faces one count of conspiracy to commit wire fraud and two counts of wire fraud, with prosecutors alleging the scheme ran from June 2018 to June 2023.
Pinhasi owned and operated MonsterCloud LLC, a Florida-based company that advertised proprietary decryption tools and techniques to recover files locked by ransomware without paying attackers. The indictment alleges Pinhasi and his co-conspirators had no such technology. Instead, they contacted ransomware operators, paid for decryption keys, and used those keys to restore customers' data.
While some MonsterCloud contracts reportedly mentioned that the company might communicate with or pay cybercriminals, those contracts allegedly said this would happen only if decryption was otherwise impossible. Prosecutors maintain that dealing with attackers was usually MonsterCloud's first step.
"As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," U.S. Attorney Joseph Nocella Jr. said in a statement. "Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity."
Prosecutors point to two specific incidents: in one, MonsterCloud allegedly paid a gang about $8,200 and charged the victim around $150,000; in another, the company paid about $236,000 and billed the client roughly $380,000. The indictment also alleges MonsterCloud used decrypted sample files as "recovery proofs" to win trust, even though those samples came from the attackers.
Over the course of the alleged scheme, Pinhasi and his co-conspirators are said to have facilitated more than $8 million in ransom payments while charging hundreds of U.S. and Canadian companies over $19 million for recovery services.
The U.S. Attorney's Office told BleepingComputer that Pinhasi surrendered Wednesday, pleaded not guilty, and was released on a $2 million bond. If convicted, he faces up to 20 years in prison. His attorneys did not respond to requests for comment.
The case echoes concerns raised as early as 2019, when investigative reports suggested some data recovery firms were quietly paying hackers rather than relying on their own technical skill.