Full Report
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire
Analysis Summary
# Incident Report: Fraudulent Ransomware Remediation Scheme (MonsterCloud)
## Executive Summary
Zohar Pinhasi, owner of Florida-based firm MonsterCloud, has been charged with wire fraud for orchestrating a scheme that defrauded ransomware victims of over $19 million. Pinhasi allegedly claimed to use proprietary tools to decrypt data while secretly paying threat actors for decryptors and charging victims significantly inflated fees. The outcome is a federal indictment involving two counts of wire fraud and one count of conspiracy, carrying a potential 60-year prison sentence.
## Incident Details
- **Discovery Date:** October 2026 (Announcement of DoJ Charges)
- **Incident Date:** Ongoing from at least October 2021 through August 2023
- **Affected Organization:** Multiple private sector victims (MonsterCloud clients)
- **Sector:** Cybersecurity Services / Ransomware Remediation
- **Geography:** Florida, USA (HQ); Victims nationwide
## Timeline of Events
### Initial Access
- **Date/Time:** Circa 2021 – 2024
- **Vector:** Deceptive Marketing and Fraudulent Misrepresentation.
- **Details:** The subject marketed "MonsterCloud" as a legitimate ransomware recovery firm, using a website and Q&A to claim they could restore data without paying ransoms.
### Lateral Movement
- **N/A:** The subject did not move through networks digitally; instead, he acted as a fraudulent intermediary between the victim and the original threat actor.
### Data Exfiltration/Impact
- **Financial Loss:** Victims were billed $19 million for "proprietary recovery" that was actually a secret ransom payment brokered by the subject.
- **Extended Compromise:** By paying ransoms, the subject funded and incentivized the original cybercriminals, prolonging the threat to the global ecosystem.
### Detection & Response
- **How it was discovered:** Investigation by the FBI and the U.S. Attorney’s Office for the Eastern District of New York.
- **Response Actions Taken:** Federal indictment filed; Zohar Pinhasi charged with three counts of wire fraud/conspiracy.
## Attack Methodology
*Note: This "attack" was a social engineering and financial fraud scheme targeted at organizations already compromised by ransomware.*
- **Initial Access:** Deceptive advertising (SEO/Website) claiming proprietary decryption technology.
- **Persistence:** Maintaining a facade of a legitimate business through service contracts.
- **Defense Evasion:** Using aliases (Zack Silver, Zack Green) and misleading contract language regarding "other means" to resolve incidents.
- **Impact:** Substantial financial extortion of re-victimized organizations.
## Impact Assessment
- **Financial:** Over $19 million charged to victims; $8 million paid to threat actors; massive profit margins (e.g., $142,000 profit on a single $8k ransom).
- **Data Breach:** While the subject did not breach the data himself, he facilitated the ransom of sensitive victim data.
- **Operational:** Victims suffered delayed recovery and significant financial drain during crisis periods.
- **Reputational:** Severe damage to the trust in the ransomware remediation industry.
## Indicators of Compromise
- **Network Indicators:** monstercloud[.]com
- **Behavioral Indicators:**
- Claims of "proprietary decryption" for known unbreakable algorithms.
- Discouraging victims from paying ransoms while charging fees significantly higher than the ransom demand.
- Lack of transparency regarding technical methods used for recovery.
## Response Actions
- **Containment:** U.S. DoJ intervention and unsealing of charges to stop ongoing fraudulent billing.
- **Eradication:** Legal prosecution of the business owner.
- **Recovery:** FBI outreach to affected victims for potential restitution.
## Lessons Learned
- **Key Takeaways:** If a company claims to have a "magic" decryptor for a modern ransomware strain that no one else can crack, it is likely a scam or a secret ransom payment.
- **What could have been done better:** Due diligence on remediation firms. Organizations should verify if a firm is listed as a reputable partner with organizations like "No More Ransom."
## Recommendations
- **Verification:** Before hiring a ransomware recovery firm, demand an explanation of the recovery method. If they claim a proprietary tool, ask for proof of concept or references.
- **Law Enforcement Consultation:** Always report ransomware incidents to the FBI (IC3.gov) before hiring third-party negotiators.
- **Direct Negotiations:** If a ransom must be paid (against federal advice), it is safer to use licensed, transparent negotiators who disclose their fees separately from the ransom cost.