Florida ransomware firm owner charged with secretly paying hackers for decryption keys

Prosecutors allege MonsterCloud CEO Zohar Pinhasi defrauded victims, charging them millions while quietly settling with attackers

By LineZotpaper
Published
Read Time3 min
The owner of a Florida ransomware remediation company has been indicted on federal wire fraud charges for allegedly paying ransom to cybercriminals behind his clients' backs, then billing those clients far more than the payouts, according to court documents and the U.S. Attorney's Office.

Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23 and arraigned Wednesday in federal court in Brooklyn. He faces one count of conspiracy to commit wire fraud and two counts of wire fraud, with prosecutors alleging the scheme ran from June 2018 to June 2023.

Pinhasi owned and operated MonsterCloud LLC, a Florida-based company that advertised proprietary decryption tools and techniques to recover files locked by ransomware without paying attackers. The indictment alleges Pinhasi and his co-conspirators had no such technology. Instead, they contacted ransomware operators, paid for decryption keys, and used those keys to restore customers' data.

While some MonsterCloud contracts reportedly mentioned that the company might communicate with or pay cybercriminals, those contracts allegedly said this would happen only if decryption was otherwise impossible. Prosecutors maintain that dealing with attackers was usually MonsterCloud's first step.

"As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself," U.S. Attorney Joseph Nocella Jr. said in a statement. "Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity."

Prosecutors point to two specific incidents: in one, MonsterCloud allegedly paid a gang about $8,200 and charged the victim around $150,000; in another, the company paid about $236,000 and billed the client roughly $380,000. The indictment also alleges MonsterCloud used decrypted sample files as "recovery proofs" to win trust, even though those samples came from the attackers.

Over the course of the alleged scheme, Pinhasi and his co-conspirators are said to have facilitated more than $8 million in ransom payments while charging hundreds of U.S. and Canadian companies over $19 million for recovery services.

The U.S. Attorney's Office told BleepingComputer that Pinhasi surrendered Wednesday, pleaded not guilty, and was released on a $2 million bond. If convicted, he faces up to 20 years in prison. His attorneys did not respond to requests for comment.

The case echoes concerns raised as early as 2019, when investigative reports suggested some data recovery firms were quietly paying hackers rather than relying on their own technical skill.

§

Analysis

Why This Matters

  • This case highlights a hidden practice in the ransomware remediation industry, where companies may be paying attackers despite marketing themselves as anti-ransom solutions, leaving victims with false assurances and inflated bills.
  • It demonstrates the legal risks for firms that engage directly with cybercriminals, potentially deterring similar practices and forcing greater transparency in the industry.
  • The scale, over $19 million in client charges and $8 million in ransom payments, underscores the financial stakes for both victims and remediation firms.

Background

Ransomware recovery is a niche but critical service. When organisations are hit by encryption attacks, they often turn to specialist firms that claim to have advanced decryption capabilities. These firms market themselves as alternatives to paying ransoms, which is both illegal in some jurisdictions and frowned upon by law enforcement as it funds further criminal activity. The indictment alleges that MonsterCloud's model was based on a false promise: instead of using proprietary tech, it simply negotiated and paid the attackers, then billed clients a markup. This case follows earlier journalistic inquiries that raised similar red flags about the industry's practices.

Key Perspectives

Prosecutors (U.S. Attorney's Office): They argue Pinhasi committed wire fraud by deceiving clients, profiteering from their distress, and potentially aiding criminal enterprises. The case is part of a broader push to hold accountable anyone who facilitates ransom payments. Defense (Pinhasi's attorneys): Pinhasi has pleaded not guilty. While his attorneys have not commented publicly, the defense may argue that contracts permitted contact with cybercriminals in certain circumstances, and that clients received their data back, even if the method was not as advertised. Critics of the industry: Consumer advocates and security researchers may view this as vindication of suspicions that some recovery firms cut corners. They may push for regulatory oversight to ensure such practices are disclosed and to protect victims from double victimisation.

What to Watch

  • The court proceedings: A trial or plea deal could reveal more details about the extent of the scheme and whether other firms engage in similar tactics.
  • Regulatory responses: Law enforcement actions may prompt industry bodies or cyber insurers to demand more verification of remediation claims.
  • Impact on the market: Clients may become more wary of hiring recovery firms without independent audits of their methods, potentially reshaping the industry.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe