Authorities accuse the owner of a so-called ransomware remediation company of swindling clients victimized by ransomware attacks into paying the company inflated fees under false pretenses. Zohar Pinhasi, owner and operator of MonsterCloud, claimed he could decrypt and recover victims’ data with specialized, proprietary tools and avoid paying cybercriminals. Yet, no such tool existed, the Justice Department said Wednesday.

Pinhasi allegedly used MonsterCloud clients’ fees to pay off cybercriminals and recover encrypted data without telling clients ransom payments were made on their behalf. The dual U.S.-Israeli national is accused of charging hundreds of clients more than $19 million and paying more than $8 million in ransom payments during a five-year period ending in 2023. Pinhasi’s alleged criminal acts illustrate how the ransomware economy attracts money-seeking professionals of all types.

Advertisement Ransomware response and remediation occurs in the shadows, providing cover for cybercriminals who fuel the scourge of extortion and, sometimes, those hired by victims to help put one of their worst days behind them. A trio of former ransomware negotiators were sentenced to prison earlier this year for deceiving their employers’ clients and conspiring with ransomware affiliates to extort those organizations — effectively playing both sides and victimizing clients’ twice over. Prosecutors charged Pinhasi with two counts of wire fraud and one count of wire fraud conspiracy.

He pleaded not guilty Wednesday in a federal court in Brooklyn, N.Y., and was released on a $2 million bond. The Florida resident, where MonsterCloud is also based, faces up to 60 years in prison. A federal judge granted a one-month delay on trial proceedings, noting that attorneys are engaged in plea negotiations.

Pinhasi’s lawyer did not immediately respond to a request for comment. “By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” Joseph Nocella Jr., U.S. attorney for the Eastern District of New York, said in a statement. Advertisement Pinhasi and one of his co-conspirators, an employee at MonsterCloud, allegedly drew clients into their scheme with an initial exploratory fee between $2,500 and $10,000. Pinhasi or an employee at MonsterCloud then obtained the ransom note sent to their client and a sample of encrypted files on the client’s system, according to the indictment.

After this “analysis phase,” Pinhasi allegedly provided encrypted samples to the prospective client as proof MonsterCloud could decrypt the files. “However, in many instances, Pinhasi had actually shared the sample files with the cybercriminal and obtained decryption samples without informing or revealing to the client that MonsterCloud had not employed any proprietary technology,” prosecutors wrote in the indictment. This preliminary phase reinforced Pinhasi’s false claims and “induced clients to contract for full ransomware recovery — a more expensive service, costing up to two or more times the ransom,” prosecutors added. In August 2023, Pinhasi charged a client approximately $150,000 and allegedly made a ransom payment of about $8,200 to recover the organization’s data.

He allegedly used the monikers “Zack Silver” and “Zack Green” in some of his communications with cybercriminals. Advertisement Officials said MonsterCloud’s contracts noted that the company would contact a cybercriminal after exhausting all other options, but dealing with cybercriminals was often Pinhasi’s first step in accessing encrypted files and the typical way he obtained proof of recovered data and decryption keys. MonsterCloud landed deals with hundreds of companies based in the United States and Canada.

The company still has an active site with a contact form for prospective clients, packaged with testimonials from law enforcement agencies and a former FBI official. Pinhasi and MonsterCloud reportedly operated this scheme for years. An exposé in ProPublica in 2019 detailed how the company professed to use its own data recovery methods but instead paid ransoms without informing victims, including law enforcement agencies. “Pinhasi claimed to fix ransomware while never remediating the underlying threat.

Instead, he turned the victim’s crisis into his own profit center,” James C. Barnacle Jr., assistant director of the FBI, said in a statement. “This deception is unacceptable, and the FBI is committed to ensuring accountability for those who choose to victimize the very people who trusted them for help.” You can read the full indictment below. Advertisement Zohar-Pinhasi-indictment-Sept-23-2026Download