The Allegation
Zohar Pinhasi, 50 — known in business dealings as "Zack Silver" and "Zack Green" — has been indicted on charges of defrauding ransomware victims through his Florida-based recovery firm, MonsterCloud LLC. Federal prosecutors allege that instead of using proprietary decryption technology as marketed, Pinhasi's actual recovery method was to quietly contact the same ransomware operators who attacked his clients and pay them directly for decryption keys — then bill the victims far more than what he paid out.
What the Indictment Describes
| Detail | Value |
|---|---|
| Defendant | Zohar Pinhasi (aka Zack Silver, Zack Green) |
| Company | MonsterCloud LLC |
| Charges | Conspiracy to commit wire fraud, two counts of wire fraud |
| Alleged scheme window | June 2018 – June 2023 |
| Ransom payments facilitated | Over $8 million to ransomware operators |
| Amount billed to victims | Over $19 million across hundreds of US and Canadian companies |
| Indicted | September 23, 2026 |
| Arraigned | October 8, 2026 |
| Maximum penalty | 20 years in prison |
Two examples cited in the case illustrate the alleged markup: in one instance, prosecutors say Pinhasi paid an $8,200 ransom to get a decryption key, then charged the victim $150,000 for the "recovery." In another, a $236,000 ransom payment was allegedly billed out at $380,000.
How the Scheme Allegedly Worked
MonsterCloud marketed itself as a cybersecurity and ransomware-response firm with proprietary recovery capability — the pitch was that clients wouldn't need to pay off attackers. According to the indictment, that pitch was false. Instead, Pinhasi allegedly reached out to the same threat actors who had encrypted a client's systems and simply paid for the decryption key as the primary (and apparently only) recovery method.
To maintain the appearance of in-house technical capability, prosecutors allege Pinhasi used decrypted sample files obtained from the criminal operators themselves as "proof" that MonsterCloud's own tools were working. Clients were billed as if a specialized recovery service had been performed, when the underlying mechanism was a ransom payment they were never told about — and on which they were allegedly significantly overcharged.
U.S. Attorney Joseph Nocella Jr. framed the harm bluntly: "by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients."
Current Status
Pinhasi has pleaded not guilty and was released on a $2 million bond following his arraignment. The case remains in early pretrial stages; no trial date has been reported as of this writing.
Why This Matters
Ransomware recovery firms occupy a position of significant trust: victims hire them precisely because they're desperate to avoid paying criminals directly, and the specialized, technical framing of "proprietary decryption" is part of what justifies premium fees. If the allegations hold up, this case shows that framing can mask the exact behavior clients were trying to avoid — and at a steep markup, with victims kept in the dark about where their money actually went.
It's also a reminder that the ransomware "recovery" market is largely unregulated. There's no license or certification that verifies a firm's claimed decryption capability, which leaves victims — already under pressure during an active incident — with limited ability to independently confirm how a recovery vendor is actually getting their data back.
Recommended Actions
- Ask recovery vendors directly whether their method involves paying the attacker, and get it in writing — if a vendor is vague about mechanism, treat that as a red flag
- Request an itemized breakdown of fees versus any ransom amount paid, before engaging a recovery firm
- Involve law enforcement and your cyber insurer early in any ransomware incident — both can provide an independent check on recovery vendor claims
- Treat "proprietary decryption" claims with skepticism unless the vendor can explain, at a technical level, how it differs from simply paying the attacker