AI-generated summary
Ransomware is a type of cyberattack in which criminals encrypt files, making them inaccessible, and demand payment to provide a decryption key. MonsterCloud presented itself as a company that could recover such files without giving money to the attackers.
Prosecutors allege that Pinhasi secretly paid hackers for decryption keys while charging clients much higher fees.
A Florida cybersecurity expert who claimed his company could recover data locked by ransomware without paying hackers has been charged with fraud in the United States. Federal prosecutors allege that Zohar Pinhasi, 50, secretly paid cybercriminals to obtain decryption keys while charging his clients much higher fees. According to the US Department of Justice, his company collected more than $19 million from clients and paid over $8 million in ransom payments. Pinhasi, who also used the names “Zack Silver” and “Zack Green,” owns MonsterCloud LLC, a Florida-based ransomware remediation company. He was arraigned on wire fraud charges in a federal court in Brooklyn on Wednesday after a grand jury in the Eastern District of New York indicted him on September 23. The allegations concern businesses that had already suffered ransomware attacks and approached MonsterCloud for help. Ransomware is a type of cyberattack in which criminals encrypt files, making them inaccessible, and demand payment to provide a decryption key. MonsterCloud presented itself as a company that could recover such files without giving money to the attackers. However, prosecutors allege that Pinhasi did not have the special technology he advertised. Instead, he contacted the same cybercriminals who had attacked his clients, paid them for decryption keys and charged the businesses substantially more than the ransom amounts.
MonsterCloud claimed to recover encrypted data
According to the indictment, MonsterCloud promoted its services as an alternative to paying ransomware attackers. Its website warned businesses against paying ransom and claimed that its team could help recover encrypted information through specialised technology. The company said it used “proprietary tools” and “advanced decryption techniques” to restore access to affected files. These claims were particularly relevant to businesses whose data had become inaccessible following cyberattacks. MonsterCloud's website also stated that “our team specializes in helping businesses recover their data without succumbing to ransom demands.” Federal investigators, however, allege that the company did not possess the technology it claimed to use. Instead of independently decrypting the files, Pinhasi allegedly negotiated with the attackers and paid them to obtain decryption keys. MonsterCloud employees then used those keys in an attempt to restore the clients' encrypted files. Prosecutors say the clients were not told that their payments were being used to pay the criminals responsible for the original attacks.
$150,000 for an $8,200 ransom
One transaction highlighted by prosecutors took place in August 2023. According to the Justice Department, Pinhasi paid approximately $8,200 to a cybercriminal to obtain a decryption key. However, he allegedly charged the affected client approximately $150,000 for the service, significantly more than the ransom payment. Investigators say this was part of a broader scheme in which MonsterCloud collected large fees while secretly paying ransomware attackers. Over the course of the alleged scheme, prosecutors say Pinhasi charged clients more than $19 million and sent over $8 million to cybercriminals. The indictment also raises questions about the company's advertising. MonsterCloud's website featured testimonials, including some from paid spokespersons. According to prosecutors, one such spokesperson contacted Pinhasi in May 2019 to ask whether MonsterCloud actually possessed proprietary software capable of decrypting ransomware-affected data. Pinhasi allegedly responded, “Monstercloud doesn’t hold any Proprietary technology [to] decrypt the ransomware data.”
What US prosecutors said
US Attorney Joseph Nocella Jr. for the Eastern District of New York accused Pinhasi of taking advantage of businesses that were already victims of cybercrime. “As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” Nocella said. FBI Assistant Director in Charge James C. Barnacle Jr. also alleged that Pinhasi failed to address the underlying cybersecurity threat while profiting from clients seeking assistance. “As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim's crisis into his own profit center,” Barnacle said.
What charges does Pinhasi face?
Pinhasi, a US and Israeli national from Hollywood, Florida, faces two counts of wire fraud and one count of wire fraud conspiracy. If convicted, he faces a maximum prison sentence of 20 years on each count. The case is being prosecuted by the US Attorney's Office for the Eastern District of New York and the Justice Department's Computer Crime and Intellectual Property Section. The Justice Department also referred to joint guidance from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA), which advises ransomware victims against paying attackers. The agencies warn that paying a ransom does not guarantee that encrypted data will be recovered, compromised systems will become secure or stolen information will not be leaked.
AI outlook — possibilities, not facts
Pinhasi will face trial on wire fraud charges in the Eastern District of New York
Very likely · Within months
Additional civil lawsuits may be filed by affected clients seeking restitution
Likely · Within months
Federal prosecutors have charged Zohar Pinhasi, a Florida-based cybersecurity expert and owner of MonsterCloud LLC, with wire fraud for allegedly deceiving clients by claiming to recover ransomware-encrypted data without paying hackers, while secretly paying cybercriminals for decryption keys and charging clients significantly inflated fees, collecting over $19 million and paying more than $8 million to attackers.
Delhi Police has restricted a planned Cockroach Janta Party protest at Jantar Mantar, citing lack of permission, public safety concerns, and past instances of violence. Authorities emphasized the need to balance protest rights with city functionality.
The Enforcement Directorate alleges that the Karnataka Public Service Commission recruitment process for veterinary officers was manipulated through an organised syndicate that leaked question papers and answer keys to candidates for bribes of Rs 40-50 lakh each, leading to the arrest of former KPSC chairman Shivashankarappa, member B V Geetha, and IAS officer Gyanendra Gangwar, with evidence showing candidates were taken to resorts/Airbnb villas to memorise leaked papers.
The CBI has gathered evidence of compromised transfers of at least 21 senior Punjab government and police officers as part of its probe into the cash-for-postings scam, including alleged influence by Punjab CM Bhagwant Mann's OSD Rajbir Singh Ghuman and accused Nitin Gohal, who reportedly used his friendship with Ghuman to facilitate postings and tender manipulations.

Former CIA officer David Rush has pleaded guilty to $200 million government fraud and leaking classified information to a foreign government. During his arrest, 298 gold bricks and luxury items were recovered from him.
CBI has included purported WhatsApp chats mentioning alleged monetary transactions and postings of senior Punjab government officials in its dossier on CM Bhagwant Mann's OSD Rajbir Singh Ghuman as part of the 'cash-for-transfers' FIR, with Ghuman and five others named as accused in a corruption case involving intermediaries, policy leaks, and real estate irregularities.