Skip to main content

Morning Overview

Prosecutors say a ransomware recovery firm paid hackers $8,200 and billed one victim about $150,000

In one client engagement in August 2023, federal prosecutors say, Zohar Pinhasi’s ransomware recovery company sent a cybercriminal a ransom payment of approximately $8,200 and then charged the client approximately $150,000. The Eastern District of New York put those two figures side by side in an indictment unsealed on Oct. 7, 2026, as the sharpest single illustration of a business that advertised recovery without paying criminals.

Pinhasi, 50, owns MonsterCloud LLC, a Florida firm that sold itself to companies hit by ransomware. The charges are allegations, and he has pleaded not guilty.

The $8,200 payment and the $150,000 invoice

According to the U.S. Attorney’s Office release, Pinhasi “made a ransom payment of approximately $8,200 to a cybercriminal” and “charged the client approximately $150,000” in the August 2023 example. The release does not name the client. The gap is roughly eighteen times the ransom, and it is the only case the office quantifies at the level of a single invoice.

The indictment, returned on Sept. 23 and docketed as No. 26-CR-271, then widens the frame. Prosecutors allege Pinhasi charged clients more than $19 million over the life of the scheme and paid more than $8 million in ransoms. BleepingComputer’s account of the filing gives a second example with the same shape, about $236,000 paid to a gang and about $380,000 charged to the customer.

The recovery claim and the alleged keys-for-fee model

MonsterCloud’s website told visitors that its team “specializes in helping businesses recover their data without succumbing to ransom demands,” a line the Justice Department attributes to the company. Prosecutors allege the firm had no technology of its own to break ransomware. In a May 2019 reply to a paid spokesperson, the release says, Pinhasi wrote that “Monstercloud doesn’t hold any Proprietary technology [to] decrypt the ransomware data.”

What it did instead, per the charging papers, was contact the attackers, buy the decryption keys and use them. CyberScoop reports that clients paid an initial exploratory fee of $2,500 to $10,000, that sample files went to the criminals to obtain proof that decryption would work, and that the proof was then used to sell full recovery priced at up to two or more times the ransom. Pinhasi allegedly used the names “Zack Silver” and “Zack Green” when dealing with the criminals, and the same report says a MonsterCloud employee took part.

BleepingComputer’s reading of the indictment dates the alleged scheme from June 2018 to June 2023 and says MonsterCloud used decrypted sample files as “recovery proofs” to persuade victims, even though those samples came out of the ransomware operators’ own decryption. The Justice Department release itself cites the May 2019 exchange and the August 2023 example without stating a start or end date, so the multi-year window is the indictment’s allegation as reported, not a finding.

Some contracts reportedly mentioned that MonsterCloud might contact attackers, but only as a last resort. Prosecutors say contacting them was usually the first step.

Charges, the court and the FBI’s statement

The case sits in federal court in Brooklyn, where Pinhasi was arraigned before Magistrate Judge Peggy Cross-Goldenberg. The office’s release describes wire fraud charges and a maximum of 20 years in prison. CyberScoop and Help Net Security both count two wire fraud counts and one wire fraud conspiracy count, and CyberScoop adds that he was released on a $2 million bond.

U.S. Attorney Joseph Nocella Jr. said Pinhasi “re-victimized his clients while extracting a hefty profit for himself.” James C. Barnacle Jr., the FBI’s assistant director in charge of the New York field office, said the alleged deception “is unacceptable” and that the bureau is committed to accountability for people who victimize those who trusted them for help. The case is being prosecuted by Assistant U.S. Attorneys Alexander Mindlin and Lindsey Oken, with senior trial attorneys Brian Mund and Vasantha Rao from the Justice Department’s Computer Crimes and Intellectual Property Section.

The 2019 test that predicted it

None of this is the first public questioning of the company. In May 2019, ProPublica’s Renee Dudley and Jeff Kao reported in “The Trade Secret” that MonsterCloud and another firm, Proven Data, sometimes paid ransoms without telling victims. Emsisoft researcher Fabian Wosar had built his own ransomware, infected a test computer and posed as a victim in December 2016. Anonymous offers to pay the fake ransom were traced back to MonsterCloud and Proven Data.

Pinhasi told ProPublica at the time that his recovery methods were a trade secret and denied misleading customers. His attorneys, Christopher Clark and Rodney Villazor, were asked for comment by BleepingComputer, which said it would update its story if they responded. Wosar’s verdict in 2019 was blunt: “The victims are getting taken advantage of twice.” Still unanswered in the public record is how many of the hundreds of U.S. and Canadian clients behind the $19 million figure were told, before they signed, that a ransom might be paid; the indictment’s own wording on that point governs, and it has not been tested in court.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.