Federal prosecutors in the United States have charged the owner of a Florida-based ransomware-recovery company with wire fraud, alleging he spent years telling panicked victims he could decrypt their files with proprietary technology — while secretly negotiating with, and paying, the same criminals who locked up the data in the first place.
Zohar Pinhasi, 50, who ran a company called MonsterCloud under the aliases "Zack Silver" and "Zack Green," faces two counts of wire fraud and one count of wire fraud conspiracy. If convicted, he could be sentenced to up to 20 years in prison.
What happened
According to the charges, MonsterCloud marketed itself to ransomware victims as a company with "advanced decryption techniques and cutting-edge technology" capable of restoring encrypted data without paying attackers. Its public messaging specifically discouraged clients from paying ransoms directly, warning that doing so only emboldens criminals.
Prosecutors allege the opposite was true: MonsterCloud had no working decryption capability of its own. Instead, it is accused of quietly contacting the same ransomware operators who had attacked its clients, paying the demanded ransom, and passing the resulting decryption key back to the victim — while charging fees far above what was actually paid out.
Two incidents cited in the case illustrate the gap. In one, prosecutors say Pinhasi paid an $8,200 ransom in August 2023 and then billed the client roughly $150,000. In another, from around October 2021, he allegedly paid a $236,000 ransom and charged the customer approximately $380,000. Across its operations, authorities estimate MonsterCloud billed clients more than $19 million while funneling over $8 million directly to ransomware gangs.
Why it matters
The case highlights a blind spot many organizations overlook during a ransomware crisis: incident-response vendors are rarely vetted with the same rigor as the attack itself. Under pressure, victims often pick a recovery firm based on marketing promises rather than verifiable capability — exactly the gap prosecutors say Pinhasi exploited.
It also points to a structural risk. A recovery firm that quietly pays ransoms on a client's behalf, without disclosure, doesn't just inflate costs — it can expose that client to sanctions risk if the threat actor turns out to be a sanctioned entity, and it removes any real incentive for the vendor to invest in genuine decryption or prevention capability.
What to do
- Before engaging any ransomware-recovery vendor, ask directly whether they pay ransoms on your behalf, and require the answer in writing — not just in marketing copy.
- Verify decryption claims. A legitimate vendor can explain, at a technical level, how a specific decryptor works for a specific ransomware family; "proprietary technology" with no detail is a red flag.
- Check whether a ransom payment could touch a sanctioned entity — U.S. OFAC guidance applies whether you pay directly or through an intermediary.
- Keep your own incident-response retainer and legal counsel engaged from the start of a ransomware event, so recovery-vendor claims are checked against independent advice rather than taken at face value.
- Invest in backups and tested restoration procedures before an incident — the strongest defense against this kind of fraud is never needing a "miracle decryptor" in the first place.
