Federal prosecutors have charged the owner of a Florida ransomware-recovery company with wire fraud, alleging he told clients the firm used proprietary decryption technology when it was in fact paying the ransoms to the attackers.
The US Attorney’s Office for the Eastern District of New York announced the charges on October 8 against Zohar Pinhasi, who is accused of billing victims more than $19 million.
The Charges Against Zohar Pinhasi
Pinhasi, 50, is a US and Israeli national from Hollywood, Florida. He also used the aliases “Zack Silver” and “Zack Green,” according to the charges. He owns MonsterCloud, which marketed itself as a ransomware-recovery firm.
He faces two counts of wire fraud and one count of wire fraud conspiracy. Each count carries a maximum sentence of 20 years. The Eastern District of New York is prosecuting the case together with the FBI.
The Alleged Gap Between Billing and Payments
Prosecutors allege that MonsterCloud billed clients more than $19 million while paying ransomware gangs more than $8 million. The firm marketed proprietary decryption methods that did not involve paying ransoms, according to the allegations, and the misleading marketing is alleged to date back to 2019.
One example in the charges involves a client in August 2023. Prosecutors say MonsterCloud paid the attackers about $8,200 and charged the client about $150,000.
How the Alleged Scheme Worked
According to the charges, victims approached MonsterCloud after ransomware attacks and were told the firm could decrypt their files using its own technology. The prosecution’s account is that the company instead paid the criminals and presented the outcome as its own technical work, billing clients far more than the ransom it had paid.
Why Victims Chose the Service
Companies facing ransomware often look for recovery options that do not require dealing with the attackers. The allegation is that MonsterCloud used that preference to attract clients, while the work it performed was the same payment the clients hoped to avoid. The charges describe victims as having paid inflated fees for what was allegedly a ransom payment.
Prosecution and Next Steps
The case is a federal prosecution under way in the Eastern District of New York. The charges are allegations, and Pinhasi is presumed innocent unless and until he is proven guilty. The announcement does not describe his response to the charges or the status of the company.
Scale of the Money Involved
The difference between the amounts allegedly billed and the amounts allegedly paid to the attackers is more than $11 million, based on the figures prosecutors cite. In the August 2023 example, prosecutors say the payment was about $8,200 against a bill of about $150,000.
The case rests on a contrast between what clients were told and what prosecutors say happened. MonsterCloud marketed proprietary decryption that avoided paying ransoms. The charges say that instead the company paid more than $8 million to ransomware gangs on clients’ behalf, while collecting more than $19 million from those clients. The Eastern District of New York and the FBI are handling the case together, and each wire fraud count carries up to 20 years in prison.
Impact on the Ransomware Recovery Market
The charges touch a part of the ransomware response industry that depends on trust, because victims often cannot verify how a recovery firm unlocked their data. If the allegations are proven, they would show clients paying for technical recovery work that, in prosecutors’ account, did not take place.
The announcement does not state how many clients were affected or how the investigation began. It also does not say whether other individuals are under investigation beyond the one conspiracy count in the charges.
Each wire fraud count carries up to 20 years in prison, and the case is pending.
