Threat reportThreat IntelligenceTL-2026-3024

MonsterCloud CEO Zohar Pinhasi charged with wire fraud over secretly paying ransoms while claiming proprietary decryption

mediumTRACKING

MonsterCloud CEO Zohar Pinhasi charged with wire fraud over (TL-2026-3024), also tracked as MonsterCloud ransomware recovery fraud, is a medium-severity tracked intrusion set, first published 2026-10-07 and last reviewed 2026-10-08. It is attributed to Zohar Pinhasi with medium confidence, affects MonsterCloud LLC Ransomware remediation / data recovery services, maps to 4 MITRE ATT&CK techniques (T1585, T1585.001, T1657), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
4MITRE ATT&CK
Actors
2Zohar Pinhasi
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-3024

Threat ID
TL-2026-3024
Also known as
MonsterCloud ransomware recovery fraud, United States v. Zohar Pinhasi
Severity
MEDIUM
Status
TRACKING
Category
THREAT_INTEL
First published
Last reviewed
Attribution
Zohar Pinhasi, MonsterCloud LLC
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
government administration, police - law enforcement, small-business, enterprise
Target regions
North America
Detection rules
9
Indicators of compromise
14
Updates
2026-10-08 · revalidated 1× · latest source

Malware and tooling in MonsterCloud CEO Zohar Pinhasi charged with wire fraud over

Malware and tooling: Dharma Ransomware, Gotcha, Nozelesn, dharma

How MonsterCloud CEO Zohar Pinhasi charged with wire fraud over works

A US indictment (EDNY, returned Sept 23, 2026) charges Zohar Pinhasi, aka "Zack Silver"/"Zack Green", CEO of Florida-based ransomware recovery firm MonsterCloud LLC, with conspiracy to commit wire fraud and two counts of wire fraud. Prosecutors allege he told victims the firm used proprietary decryption technology while actually contacting attackers and buying decryption keys, facilitating over $8 million in ransom payments and billing victims over $19 million between June 2018 and June 2023.

On September 23, 2026 a federal grand jury in the Eastern District of New York indicted Zohar Pinhasi, 50, a US and Israeli national also known as "Zack Silver" and "Zack Green", owner and CEO of MonsterCloud LLC, a Florida-based ransomware remediation company. He was arraigned on October 7, 2026 and, per BleepingComputer, released on a $2 million bond. The charges are one count of conspiracy to commit wire fraud and two counts of wire fraud, each carrying a statutory maximum of 20 years. These are allegations; the defendant has not been convicted.

According to the Justice Department, MonsterCloud advertised that it could decrypt ransomware using "proprietary tools" and "advanced decryption techniques" and presented itself as an alternative to paying the attackers. Prosecutors allege that in practice Pinhasi and co-conspirators usually contacted and paid the cybercriminals who had victimized the client in exchange for a decryption key, did not disclose this, and then billed the client far more than the ransom. Between June 2018 and June 2023 the scheme allegedly facilitated more than $8 million in ransom payments while billing hundreds of companies in the United States and Canada more than $19 million. Two examples in the indictment: a ransom of about $8,200 billed to the victim at about $150,000, and a ransom of about $236,000 billed at about $380,000. US Attorney Joseph Nocella Jr. said that by falsely claiming to decrypt ransomware without paying the ransomers, the defendant re-victimized his clients. The FBI investigated; prosecutors are Brian Mund and Vasantha Rao (DOJ CCIPS) and AUSAs Alexander Mindlin and Lindsey Oken.

The conduct was publicly questioned years earlier. A 2019 ProPublica investigation ("The Trade Secret") reported that MonsterCloud and Proven Data Recovery claimed in-house technology but typically obtained decryption tools by paying attackers, and that MonsterCloud refused to explain its methods as "trade secrets". ProPublica documented MonsterCloud's "Don't Pay the Ransom" marketing, the use of the alias "Zack Green" with inflated titles, roughly 58 suspicious five-star Google reviews under celebrity-sounding names, and law-enforcement testimonials (Lauderdale County MS, Trumann AR police, Lamar County TX) for incidents including a Dharma ransomware attack for which researchers Fabian Wosar and Michael Gillespie said no public decryptor existed. A December 2016 sting by Wosar ("Operation Bleeding Cloud") found MonsterCloud claiming it could decrypt families that were undecryptable.

No ransomware groups, CVEs, or technical IOCs are named in the indictment coverage. The intelligence value is third-party and ransomware-ecosystem risk: recovery vendors that silently pay extortionists create undisclosed payment flows, sanctions/OFAC exposure, repeat-targeting risk and inflated costs. Defender takeaways: contractually require disclosure of any contact with or payment to threat actors, verify decryptor claims independently (for example No More Ransom), and keep law enforcement and counsel in the loop on any payment decision.

MITRE ATT&CK techniques used in TL-2026-3024

Resource Development

T1585 Establish Accounts; T1585.001 Social Media Accounts

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in MonsterCloud CEO Zohar Pinhasi charged with wire fraud over

  • MonsterCloud LLC — Ransomware remediation / data recovery services (customers in the US and Canada)
    Vulnerable versions: Engagements June 2018 - June 2023 (alleged)

Remediation for MonsterCloud CEO Zohar Pinhasi charged with wire fraud over

Immediate actions

  • Ask any ransomware recovery or negotiation vendor in writing whether they have contacted, negotiated with or paid threat actors on your behalf
  • Review past incident-response invoices for ransom payments passed through at a markup or without disclosure

Workarounds

  • Independently verify decryptor claims against public resources such as No More Ransom before engaging a vendor
  • Victims who engaged MonsterCloud between June 2018 and June 2023 should preserve invoices and communications and report to the FBI

Longer-term hardening

  • Contract IR and recovery vendors with explicit disclosure, no-payment-without-consent, and audit-right clauses
  • Pre-vet ransomware recovery vendors and route payment decisions through legal counsel, insurers and law enforcement (FBI/IC3)
  • Maintain tested offline backups so vendor claims of proprietary decryption are not the only recovery path

Timeline of MonsterCloud CEO Zohar Pinhasi charged with wire fraud over

  • Researcher Fabian Wosar's "Operation Bleeding Cloud" sting (December 2016) finds MonsterCloud claiming it can decrypt ransomware families that have no public decryptor (per ProPublica).
  • Lauderdale County (MS) and Lamar County (TX) sheriff's offices become MonsterCloud clients and later give testimonials claiming recovery without ransom payment (ProPublica).
  • Start of the period (June 2018 - June 2023) in which prosecutors allege MonsterCloud secretly paid attackers for decryption keys while advertising proprietary decryption.
  • Wosar's April 2019 GOTCHA sting of recovery firms; MonsterCloud does not respond to the inquiry while Proven Data and Red Mosquito are shown negotiating with the fake attacker.
  • ProPublica publishes "The Trade Secret", reporting that MonsterCloud and Proven Data typically pay ransoms despite claiming proprietary technology, and documenting aliases and suspicious Google reviews.
  • End of the alleged scheme period (June 2023); over $8 million in ransoms facilitated and over $19 million billed to hundreds of US and Canadian clients.
  • The DOJ release says the alleged scheme continued through at least August 2023, later than the June 2023 end date reported by BleepingComputer.
  • Federal grand jury in the Eastern District of New York indicts Zohar Pinhasi on one count of wire fraud conspiracy and two counts of wire fraud.
  • Pinhasi is arraigned; DOJ announces the charges and BleepingComputer reports release on a $2 million bond. Each count carries up to 20 years.
  • The Register reports the case, noting the indictment references unidentified co-conspirators including MonsterCloud employees and contractors, and that Pinhasi pleaded not guilty at arraignment.

Update history for TL-2026-3024

Sources cited for MonsterCloud CEO Zohar Pinhasi charged with wire fraud over

Detection coverage for TL-2026-3024

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3024 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats