Threat reportThreat IntelligenceTL-2026-3024
MonsterCloud CEO Zohar Pinhasi charged with wire fraud over secretly paying ransoms while claiming proprietary decryption
MonsterCloud CEO Zohar Pinhasi charged with wire fraud over (TL-2026-3024), also tracked as MonsterCloud ransomware recovery fraud, is a medium-severity tracked intrusion set, first published 2026-10-07 and last reviewed 2026-10-08. It is attributed to Zohar Pinhasi with medium confidence, affects MonsterCloud LLC Ransomware remediation / data recovery services, maps to 4 MITRE ATT&CK techniques (T1585, T1585.001, T1657), and is covered by 9 detection rules and 14 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 4MITRE ATT&CK
- Actors
- 2Zohar Pinhasi
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-3024
- Threat ID
- TL-2026-3024
- Also known as
- MonsterCloud ransomware recovery fraud, United States v. Zohar Pinhasi
- Severity
- MEDIUM
- Status
- TRACKING
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- Zohar Pinhasi, MonsterCloud LLC
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- government administration, police - law enforcement, small-business, enterprise
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 14
- Updates
- 2026-10-08 · revalidated 1× · latest source
Malware and tooling in MonsterCloud CEO Zohar Pinhasi charged with wire fraud over
Malware and tooling: Dharma Ransomware, Gotcha, Nozelesn, dharma
How MonsterCloud CEO Zohar Pinhasi charged with wire fraud over works
A US indictment (EDNY, returned Sept 23, 2026) charges Zohar Pinhasi, aka "Zack Silver"/"Zack Green", CEO of Florida-based ransomware recovery firm MonsterCloud LLC, with conspiracy to commit wire fraud and two counts of wire fraud. Prosecutors allege he told victims the firm used proprietary decryption technology while actually contacting attackers and buying decryption keys, facilitating over $8 million in ransom payments and billing victims over $19 million between June 2018 and June 2023.
On September 23, 2026 a federal grand jury in the Eastern District of New York indicted Zohar Pinhasi, 50, a US and Israeli national also known as "Zack Silver" and "Zack Green", owner and CEO of MonsterCloud LLC, a Florida-based ransomware remediation company. He was arraigned on October 7, 2026 and, per BleepingComputer, released on a $2 million bond. The charges are one count of conspiracy to commit wire fraud and two counts of wire fraud, each carrying a statutory maximum of 20 years. These are allegations; the defendant has not been convicted.
According to the Justice Department, MonsterCloud advertised that it could decrypt ransomware using "proprietary tools" and "advanced decryption techniques" and presented itself as an alternative to paying the attackers. Prosecutors allege that in practice Pinhasi and co-conspirators usually contacted and paid the cybercriminals who had victimized the client in exchange for a decryption key, did not disclose this, and then billed the client far more than the ransom. Between June 2018 and June 2023 the scheme allegedly facilitated more than $8 million in ransom payments while billing hundreds of companies in the United States and Canada more than $19 million. Two examples in the indictment: a ransom of about $8,200 billed to the victim at about $150,000, and a ransom of about $236,000 billed at about $380,000. US Attorney Joseph Nocella Jr. said that by falsely claiming to decrypt ransomware without paying the ransomers, the defendant re-victimized his clients. The FBI investigated; prosecutors are Brian Mund and Vasantha Rao (DOJ CCIPS) and AUSAs Alexander Mindlin and Lindsey Oken.
The conduct was publicly questioned years earlier. A 2019 ProPublica investigation ("The Trade Secret") reported that MonsterCloud and Proven Data Recovery claimed in-house technology but typically obtained decryption tools by paying attackers, and that MonsterCloud refused to explain its methods as "trade secrets". ProPublica documented MonsterCloud's "Don't Pay the Ransom" marketing, the use of the alias "Zack Green" with inflated titles, roughly 58 suspicious five-star Google reviews under celebrity-sounding names, and law-enforcement testimonials (Lauderdale County MS, Trumann AR police, Lamar County TX) for incidents including a Dharma ransomware attack for which researchers Fabian Wosar and Michael Gillespie said no public decryptor existed. A December 2016 sting by Wosar ("Operation Bleeding Cloud") found MonsterCloud claiming it could decrypt families that were undecryptable.
No ransomware groups, CVEs, or technical IOCs are named in the indictment coverage. The intelligence value is third-party and ransomware-ecosystem risk: recovery vendors that silently pay extortionists create undisclosed payment flows, sanctions/OFAC exposure, repeat-targeting risk and inflated costs. Defender takeaways: contractually require disclosure of any contact with or payment to threat actors, verify decryptor claims independently (for example No More Ransom), and keep law enforcement and counsel in the loop on any payment decision.
MITRE ATT&CK techniques used in TL-2026-3024
Resource Development
T1585 Establish Accounts; T1585.001 Social Media Accounts
Impact
Defense Evasion
Affected products and versions in MonsterCloud CEO Zohar Pinhasi charged with wire fraud over
- MonsterCloud LLC — Ransomware remediation / data recovery services (customers in the US and Canada)
Vulnerable versions: Engagements June 2018 - June 2023 (alleged)
Remediation for MonsterCloud CEO Zohar Pinhasi charged with wire fraud over
Immediate actions
- Ask any ransomware recovery or negotiation vendor in writing whether they have contacted, negotiated with or paid threat actors on your behalf
- Review past incident-response invoices for ransom payments passed through at a markup or without disclosure
Workarounds
- Independently verify decryptor claims against public resources such as No More Ransom before engaging a vendor
- Victims who engaged MonsterCloud between June 2018 and June 2023 should preserve invoices and communications and report to the FBI
Longer-term hardening
- Contract IR and recovery vendors with explicit disclosure, no-payment-without-consent, and audit-right clauses
- Pre-vet ransomware recovery vendors and route payment decisions through legal counsel, insurers and law enforcement (FBI/IC3)
- Maintain tested offline backups so vendor claims of proprietary decryption are not the only recovery path
Timeline of MonsterCloud CEO Zohar Pinhasi charged with wire fraud over
- Researcher Fabian Wosar's "Operation Bleeding Cloud" sting (December 2016) finds MonsterCloud claiming it can decrypt ransomware families that have no public decryptor (per ProPublica).
- Lauderdale County (MS) and Lamar County (TX) sheriff's offices become MonsterCloud clients and later give testimonials claiming recovery without ransom payment (ProPublica).
- Start of the period (June 2018 - June 2023) in which prosecutors allege MonsterCloud secretly paid attackers for decryption keys while advertising proprietary decryption.
- Wosar's April 2019 GOTCHA sting of recovery firms; MonsterCloud does not respond to the inquiry while Proven Data and Red Mosquito are shown negotiating with the fake attacker.
- ProPublica publishes "The Trade Secret", reporting that MonsterCloud and Proven Data typically pay ransoms despite claiming proprietary technology, and documenting aliases and suspicious Google reviews.
- End of the alleged scheme period (June 2023); over $8 million in ransoms facilitated and over $19 million billed to hundreds of US and Canadian clients.
- The DOJ release says the alleged scheme continued through at least August 2023, later than the June 2023 end date reported by BleepingComputer.
- Federal grand jury in the Eastern District of New York indicts Zohar Pinhasi on one count of wire fraud conspiracy and two counts of wire fraud.
- Pinhasi is arraigned; DOJ announces the charges and BleepingComputer reports release on a $2 million bond. Each count carries up to 20 years.
- The Register reports the case, noting the indictment references unidentified co-conspirators including MonsterCloud employees and contractors, and that Pinhasi pleaded not guilty at arraignment.
Update history for TL-2026-3024
- 2026-10-08 — MonsterCloud ransomware recovery fraud: CEO Zohar Pinhasi charged with secretly paying ransoms while claiming proprietary decryption: What changed No severity/exploitability change. Alleged scheme window extended from June 2023 to at least August 2023 per the DOJ release; Pinhasi pleaded not guilty at arraignment. New indicators (4) SamSam (Proven Data ecosystem context)
Sources cited for MonsterCloud CEO Zohar Pinhasi charged with wire fraud over
- Ransomware recovery CEO charged over secret ransom payments (BleepingComputer)
- Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged (DOJ Office of Public Affairs)
- Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients (USAO EDNY)
- The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers (ProPublica)
- Sting Catches Another Ransomware Firm, Red Mosquito, Negotiating With "Hackers" (ProPublica)
- Grifty "information security" companies promised they could decrypt ransomware-locked computers (Boing Boing)
- THE TRADE SECRET (Emsisoft mirror)
Detection coverage for TL-2026-3024
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3024 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.