Full Report
Zohar Pinhasi Allegedly Paid Cybercriminals More Than $8M in Ransom Payments While Charging Clients $19M Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” a U.S. and Israeli national, was arraigned today in the Eastern District of New York on wire fraud charges relating to Pinhasi’s false representations that he could decrypt ransomware without paying cybercriminals. Pinhasi claimed to prospective clients that his company, MonsterCloud, offered a principled alternative to paying off ransomware attackers. “The defendant is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again and committed additional fraud, harming the victim again,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “This prosecution underscores the Department’s commitment to protecting ransomware victims, regardless of how these cyber ransoms occur.” “As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” said U.S. Attorney Joseph Nocella, Jr. for the Eastern District of New York. “Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity.”
Analysis Summary
# Incident Report: Fraudulent Ransomware Remediation Scheme by MonsterCloud
## Executive Summary
Zohar Pinhasi, owner of the cybersecurity firm MonsterCloud, was indicted for wire fraud after allegedly deceiving ransomware victims by claiming his firm could decrypt data using proprietary tools without paying attackers. In reality, Pinhasi secretly paid cybercriminals for decryption keys using a portion of the exorbitant fees charged to his clients. The scheme resulted in over $19 million in fraudulent charges to victims and approximately $8 million in secret ransom payments to attackers.
## Incident Details
- **Discovery Date:** Arraignment occurred October 7, 2026.
- **Incident Date:** Ongoing; specifically noted incidents in August 2023.
- **Affected Organization:** MonsterCloud (Service Provider); multiple unnamed business clients.
- **Sector:** Cybersecurity Services / Ransomware Remediation.
- **Geography:** Eastern District of New York / Florida, USA.
## Timeline of Events
### Initial Access
- **Date/Time:** Variable (during the period leading up to 2023–2026).
- **Vector:** Deceptive Marketing and Fraudulent Misrepresentation.
- **Details:** Pinhasi targeted businesses already victimized by ransomware, using his reputation as a "cybersecurity expert" and the MonsterCloud website to solicit clients seeking an alternative to paying ransoms.
### Lateral Movement
- **Details:** Not applicable in a traditional network sense; however, Pinhasi moved between the victimized client and the cybercriminals, acting as an unauthorized and deceptive intermediary.
### Data Exfiltration/Impact
- **Details:** The primary impact was financial fraud. Pinhasi would collect a "remediation fee" from clients, secretly negotiate with the original attackers to purchase the decryption key, and then present the recovered data as the result of his firm's "proprietary tools."
### Detection & Response
- **How it was discovered:** Investigation led by the FBI and the Department of Justice (DOJ) Computer Crime and Intellectual Property Section (CCIPS).
- **Response Actions Taken:** Pinhasi was arrested and arraigned in the Eastern District of New York on two counts of wire fraud and one count of wire fraud conspiracy.
## Attack Methodology
- **Initial Access:** Fraudulent solicitation of ransomware victims via MonsterCloud's website.
- **Persistence:** Maintained the facade of a legitimate cybersecurity firm through public appearances and expert branding ("Zack Silver").
- **Defense Evasion:** Used aliases and "proprietary" claims to mask the fact that he was simply paying the original attackers.
- **Impact:** Financial exploitation of victims. For example, paying an $8,200 ransom while charging the client $150,000 for "decryption services."
## Impact Assessment
- **Financial:** Charged clients over $19 million; paid over $8 million in ransoms to criminal elements.
- **Data Breach:** While the "remediation" often restored data, the underlying threat was never properly mitigated, and client funds were funneled to criminal groups.
- **Operational:** Victims suffered delayed recovery and significant financial loss due to inflated service costs.
- **Reputational:** Severe damage to the trust in the ransomware remediation industry and Pinhasi’s public standing.
## Indicators of Compromise
- **Behavioral indicators:** Service providers who explicitly guarantee decryption of modern ransomware without original keys; providers who discourage direct contact with attackers solely to control the negotiation/payment flow for their own profit.
- **Web Presence:** MonsterCloud[.]com (defanged).
## Response Actions
- **Containment measures:** U.S. government intervention and indictment of the principal actor.
- **Recovery actions:** Prosecution seeking to hold the defendant accountable for $19M in fraudulent gains.
## Lessons Learned
- **Key takeaways:** Claims of "guaranteed decryption" for advanced ransomware without paying the ransom are often fraudulent, as modern encryption is mathematically infeasible to break without a key.
- **What could have been done better:** Victims should vet remediation firms through official channels (e.g., CISA/FBI guidance) and be wary of firms that charge massive premiums without transparently explaining their technical process.
## Recommendations
- **Prevention measures:** Organizations should follow the FBI/CISA StopRansomware guide. Focus on offline backups and robust EDR/MDR solutions to prevent the need for remediation services.
- **Due Diligence:** Perform background checks and request technical whitepapers from remediation firms to ensure they are not simply acting as a "ransom broker" in disguise.