
Zohar Pinhasi built a business on the promise of rescue. His company, MonsterCloud, positioned itself as a sophisticated alternative to capitulation. Victims facing locked servers and encrypted data heard claims of proprietary decryption technology. They paid handsomely. Many walked away with restored files.
But federal prosecutors allege something different. Pinhasi, also known as Zack Silver and Zack Green, didn’t crack the code. He simply paid the criminals. The scheme allegedly ran for five years. From June 2018 through June 2023, according to an indictment unsealed this week.
Pinhasi, 50, faces one count of conspiracy to commit wire fraud and two counts of wire fraud. A federal grand jury in the Eastern District of New York returned the indictment on Sept. 23. He appeared in Brooklyn federal court for arraignment on Oct. 8. The BleepingComputer report laid out the core accusation in stark terms: the MonsterCloud owner defrauded ransomware victims by secretly paying attackers for decryptors while claiming to use in-house technology.
The numbers tell a story of marked-up desperation. Prosecutors say Pinhasi and co-conspirators facilitated more than $8 million in ransom payments to various ransomware operators. They charged hundreds of U.S. and Canadian companies more than $19 million for recovery and remediation services. One example cited in the indictment stands out. Pinhasi allegedly paid a gang about $8,200. The victim paid approximately $150,000. Another case saw a $236,000 payment to attackers met with a $380,000 bill to the client.
But the deception ran deeper than pricing. MonsterCloud contracts sometimes disclosed the possibility of communicating with or paying cybercriminals. That language offered a thin layer of transparency. Yet the company’s marketing told a different tale. Customers believed they bought advanced technical recovery. Instead they funded direct ransom transfers dressed up as innovation.
And the proof-of-recovery tactic? Prosecutors claim MonsterCloud used decrypted sample files provided by the ransomware groups themselves. These “recovery proofs” convinced panicked executives that proprietary tools had succeeded. The files came straight from the attackers. No magic algorithm. Just a transaction.
The Register first highlighted the case with a focus on the fixer who claimed decryption power but allegedly defrauded clients instead. Its coverage noted how the scheme preyed on organizations already reeling from attack. The Register article captured the human cost. Victims sought help. They received what amounted to an expensive middleman service.
Recent developments add context to a troubled industry. On Oct. 7, news emerged of another alleged double-cross inside ransomware circles. An affiliate of The Gentlemen ransomware operation reportedly diverted victims to his own leak site, keeping proceeds. CloudSEK researchers detailed the betrayal, which involved novel use of AI tools in attacks. The Cybernews story from Oct. 7 described exposed infrastructure holding 50TB of data from more than two dozen victims.
These incidents expose fractures in the ransomware economy. Recovery firms occupy a gray zone. Some deliver genuine technical breakthroughs. Others act as paid intermediaries. The line blurs when marketing emphasizes secret sauce that doesn’t exist. Organizations under duress make decisions fast. They rarely pause to verify capabilities.
Pinhasi’s alleged operation exploited that pressure. Companies hit by ransomware often face immediate operational collapse. Downtime costs mount by the hour. Insurance policies sometimes cover ransom payments but push for professional negotiators or recovery specialists. MonsterCloud filled that role for many. Its pitch sounded legitimate. The results looked successful. Files returned. Systems restarted.
Yet the indictment paints a picture of systematic overcharging. The gap between ransom paid and fees collected created substantial profit. Prosecutors documented the pattern across numerous victims. Hundreds of organizations. Millions in alleged excess charges. The scheme didn’t require sophisticated malware development. It required trust. And access to desperate customers.
Broader patterns emerge when examining related cases. Earlier this year, a ransomware negotiator received a 70-month prison sentence for feeding confidential client information to the BlackCat gang. Angelo Martino betrayed victims while employed by DigitalMint. He helped extract higher payments. The Justice Department detailed how his actions contributed to more than $75 million in ransoms from five victims. That case, reported across outlets including PYMNTS in July, revealed insiders working both sides.
The MonsterCloud allegations differ in method but share a theme. They involve profiting from fear. They erode confidence in the very services meant to mitigate harm. Ransomware groups thrive when victims see no alternative. Recovery providers who secretly collaborate with attackers reinforce that perception.
Free decryption tools exist for certain families. Projects like No More Ransom have released dozens of working decryptors over the years. Law enforcement operations occasionally yield master keys. The FBI provided one after disrupting BlackCat. Yet many strains remain resistant. Victims without backups face stark choices.
Industry observers note the lack of regulation around ransomware recovery services. Anyone can advertise decryption expertise. Few mechanisms exist to verify claims before payment. Contracts may include disclaimers. Marketing materials often do not. The result leaves room for exactly the conduct prosecutors now allege.
Pinhasi has not yet entered a plea. His attorneys did not respond to requests for comment in initial coverage. The case remains in early stages. Trial dates have not been set. If convicted, he faces significant prison time. Wire fraud carries up to 20 years per count.
The charges arrive at a moment of heightened scrutiny. Ransomware incidents continue despite law enforcement wins. Groups rebrand. Affiliates shift between operations. Recovery firms multiply. Some provide real value through negotiation expertise, forensic analysis, and restoration support. Others appear to function primarily as payment processors with premium pricing.
Organizations evaluating recovery partners now face additional questions. Does the provider maintain independent technical capabilities? Can they demonstrate decryption without attacker involvement? What exactly does the contract permit regarding communication with threat actors? The MonsterCloud case, if proven, shows how easily those distinctions can be obscured.
Short-term relief. Long-term consequences. Victims pay for speed. They may sacrifice transparency. The alleged fraud didn’t prevent data recovery. It simply made the process far more expensive than necessary. And it undermined the premise that technical solutions could replace ransom payments.
So the indictment lands as both specific accusation and broader warning. The ransomware recovery market demands skepticism. Claims of proprietary decryption deserve examination. Organizations in crisis still need help. They just need to understand exactly what kind of help they’re buying.
Prosecutors built their case on transaction records, communications, and victim statements. The pattern allegedly repeated across years and hundreds of incidents. Pinhasi didn’t invent the model. He stands accused of perfecting it at scale. The outcome of his case could shape how the industry polices itself. Or how regulators step in.
from WebProNews https://ift.tt/HsxY6Ml





