Opens in a new tab

MonsterCloud Ransomware Recovery Fraud Charges

US indicts 'ransomware fixer' for secretly paying ransoms and pocketing markups

The alleged MonsterCloud ransomware recovery fraud has led to federal charges against the company’s owner. US prosecutors say clients were promised specialist decryption, but attackers were secretly paid for the keys.

The US Department of Justice announced the case on 7 October 2026, the same day Pinhasi was arraigned in Brooklyn. The accusations concern how ransomware recovery services were marketed and delivered, rather than a newly discovered malware strain or software vulnerability.

MonsterCloud ransomware recovery fraud allegations

Zohar Pinhasi, also known as Zack Silver and Zack Green, owns Florida-based MonsterCloud. The company offered services to organisations whose files had been encrypted by ransomware and presented itself as capable of restoring data without paying the criminals responsible.

According to prosecutors, MonsterCloud promoted its supposed use of proprietary tools and advanced decryption techniques. Its website also described the business as a highly sophisticated counter cyber terrorism team and referred to advanced decryption techniques and cutting-edge technology.

The Department of Justice alleges that these claims concealed a different process. Rather than independently defeating the ransomware encryption, Pinhasi and MonsterCloud allegedly communicated with the attackers, paid their ransom demands and obtained decryption tools or keys from them.

Clients were allegedly not told that their fees were being used to pay the criminals. Prosecutors say MonsterCloud instead represented that the recovery resulted from its own capabilities, while retaining the substantial difference between the ransom payment and the amount invoiced.

This alleged discrepancy sits at the centre of the ransomware recovery fraud case. It is not an accusation that the company simply charged expensive professional fees. The prosecution alleges that clients made payments based on false statements about the recovery method and whether their money would reach ransomware operators.

More than $19 million allegedly charged

The scale described by prosecutors is significant. MonsterCloud allegedly charged affected clients more than $19 million in total while paying more than $8 million in ransoms. The remaining amount would include any legitimate operating costs, but prosecutors allege that substantial mark-ups were retained through the deception.

One transaction from around August 2023 illustrates the alleged model. MonsterCloud reportedly charged a client approximately $150,000, while paying the ransomware attackers roughly $8,200. The client was allegedly not informed that a ransom payment had secured the decryption capability.

The indictment also reportedly describes promotional testimonials, including material involving at least one compensated spokesperson. In May 2019, that spokesperson questioned Pinhasi about whether MonsterCloud possessed proprietary decryption software. Pinhasi allegedly responded that the company did not hold proprietary technology capable of decrypting ransomware data.

Timeline of the MonsterCloud criminal case

A federal grand jury in the Eastern District of New York returned the indictment on 23 September 2026. Pinhasi was subsequently arraigned in federal court in Brooklyn on 7 October 2026, according to the US Attorney’s Office and the court calendar.

The key events established by the public record are:

  • May 2019: A paid spokesperson allegedly questioned whether MonsterCloud possessed proprietary ransomware decryption technology.
  • August 2023: MonsterCloud allegedly billed one client about $150,000 while paying attackers approximately $8,200.
  • 23 September 2026: A grand jury returned the federal indictment.
  • 7 October 2026: Pinhasi was arraigned in Brooklyn, and the Department of Justice publicly announced the charges.

Pinhasi faces two counts of wire fraud and one count of conspiracy to commit wire fraud. Each count carries a maximum statutory penalty of 20 years in prison if he is convicted. A maximum penalty is not necessarily the sentence that would be imposed.

The FBI is investigating the ransomware recovery fraud allegations. Reporting on the indictment also indicates that prosecutors referred to multiple alleged co-conspirators, including MonsterCloud employees and contractors whose identities were described as known and unknown to the grand jury. No additional charges were confirmed in the available announcements.

The allegations have not been proven at trial. Pinhasi is entitled to the presumption of innocence unless and until proven guilty.

How the alleged ransomware payment process worked

Legitimate ransomware recovery can involve several possible routes. A responder might restore clean backups, locate a publicly available decryptor, exploit a flaw in the ransomware’s encryption, rebuild affected systems or negotiate with attackers as an explicitly disclosed last resort.

In the alleged MonsterCloud model, the critical difference was disclosure. Prosecutors describe a process in which clients were encouraged to believe that technical expertise could recover their data without funding the attackers. MonsterCloud then allegedly paid those attackers and used the supplied decryptor while presenting the outcome as its own technical solution.

The alleged ransomware recovery fraud can be summarised as follows:

  • A ransomware victim contacted MonsterCloud for urgent assistance.
  • The company allegedly claimed to have proprietary recovery tools or advanced decryption capabilities.
  • MonsterCloud allegedly contacted the ransomware operators without fully disclosing that step to the client.
  • A portion of the client’s fee was allegedly used to pay the ransom and obtain a decryptor.
  • The company allegedly restored or attempted to restore the files and retained the difference between its fee and the ransom.

This distinction matters because a ransom payment creates legal, financial and operational consequences. It can expose an organisation to sanctions risks, affect insurance coverage and support further criminal activity. A supplied decryptor may also be unreliable, and payment does not guarantee that stolen information will be deleted.

No CVE, affected product or technical indicator

The MonsterCloud ransomware recovery fraud case does not involve a CVE, vulnerable software product or affected version. The alleged victims were organisations purchasing ransomware remediation services, but the Department of Justice has not identified them, their industries or the ransomware groups involved.

No indicators of compromise, malware hashes, domains or attacker infrastructure have been published in connection with the case. There is also no proof of concept because the alleged wrongdoing concerns commercial representations and undisclosed payments, not exploitation of a technical weakness.

The current status is therefore a live federal criminal case, not an actively exploited vulnerability alert. Organisations do not need to patch a product because of these charges, but those that previously used the provider may need to examine contractual records, invoices and statements about how recovery was achieved.

What UK organisations should check

Although the prosecution is taking place in the United States, the ransomware recovery fraud allegations are relevant to UK organisations buying emergency services internationally. During a ransomware incident, urgency and operational pressure can make impressive decryption claims difficult to scrutinise.

Before authorising recovery work, organisations should require a written description of the proposed method and explicit disclosure of any threat actor contact. Contracts should state whether ransom negotiation or payment is permitted, who can authorise it and how sanctions screening will be documented.

Invoices should separate technical work, negotiation costs and third-party payments. If money may pass to an attacker, organisations should demand evidence of the amount, destination and approval process, with escrow or another controlled payment mechanism where appropriate.

Claims of exclusive or proprietary decryption should also be independently validated. The specific lesson from the MonsterCloud ransomware recovery fraud case is straightforward: successful file restoration does not, by itself, prove that a provider defeated the encryption or avoided paying the criminals.

Originally reported by theregister.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call