# MonsterCloud CEO Zohar Pinhasi charged with wire fraud over secretly paying ransoms while claiming proprietary decryption

> A US indictment (EDNY, returned Sept 23, 2026) charges Zohar Pinhasi, aka "Zack Silver"/"Zack Green", CEO of Florida-based ransomware recovery firm MonsterCloud LLC, with conspiracy to commit wire fraud and two counts of wire fraud. Prosecutors allege he told victims the firm used proprietary decryption technology while actually contacting attackers and buying decryption keys, facilitating over $8 million in ransom payments and billing victims over $19 million between June 2018 and June 2023.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-08T02:41:43.300Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3024
- **ID:** TL-2026-3024
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** TRACKING
- **Actor:** Zohar Pinhasi
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On September 23, 2026 a federal grand jury in the Eastern District of New York indicted Zohar Pinhasi, 50, a US and Israeli national also known as "Zack Silver" and "Zack Green", owner and CEO of MonsterCloud LLC, a Florida-based ransomware remediation company. He was arraigned on October 7, 2026 and, per BleepingComputer, released on a $2 million bond. The charges are one count of conspiracy to commit wire fraud and two counts of wire fraud, each carrying a statutory maximum of 20 years. These are allegations; the defendant has not been convicted.

According to the Justice Department, MonsterCloud advertised that it could decrypt ransomware using "proprietary tools" and "advanced decryption techniques" and presented itself as an alternative to paying the attackers. Prosecutors allege that in practice Pinhasi and co-conspirators usually contacted and paid the cybercriminals who had victimized the client in exchange for a decryption key, did not disclose this, and then billed the client far more than the ransom. Between June 2018 and June 2023 the scheme allegedly facilitated more than $8 million in ransom payments while billing hundreds of companies in the United States and Canada more than $19 million. Two examples in the indictment: a ransom of about $8,200 billed to the victim at about $150,000, and a ransom of about $236,000 billed at about $380,000. US Attorney Joseph Nocella Jr. said that by falsely claiming to decrypt ransomware without paying the ransomers, the defendant re-victimized his clients. The FBI investigated; prosecutors are Brian Mund and Vasantha Rao (DOJ CCIPS) and AUSAs Alexander Mindlin and Lindsey Oken.

The conduct was publicly questioned years earlier. A 2019 ProPublica investigation ("The Trade Secret") reported that MonsterCloud and Proven Data Recovery claimed in-house technology but typically obtained decryption tools by paying attackers, and that MonsterCloud refused to explain its methods as "trade secrets". ProPublica documented MonsterCloud's "Don't Pay the Ransom" marketing, the use of the alias "Zack Green" with inflated titles, roughly 58 suspicious five-star Google reviews under celebrity-sounding names, and law-enforcement testimonials (Lauderdale County MS, Trumann AR police, Lamar County TX) for incidents including a Dharma ransomware attack for which researchers Fabian Wosar and Michael Gillespie said no public decryptor existed. A December 2016 sting by Wosar ("Operation Bleeding Cloud") found MonsterCloud claiming it could decrypt families that were undecryptable.

No ransomware groups, CVEs, or technical IOCs are named in the indictment coverage. The intelligence value is third-party and ransomware-ecosystem risk: recovery vendors that silently pay extortionists create undisclosed payment flows, sanctions/OFAC exposure, repeat-targeting risk and inflated costs. Defender takeaways: contractually require disclosure of any contact with or payment to threat actors, verify decryptor claims independently (for example No More Ransom), and keep law enforcement and counsel in the loop on any payment decision.

## MITRE ATT&CK

- T1657 Financial Theft
- T1684.001 Impersonation
- T1585 Establish Accounts
- T1585.001 Social Media Accounts

## Sources

- [Ransomware recovery CEO charged over secret ransom payments (BleepingComputer)](https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/)
- [Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged (DOJ Office of Public Affairs)](https://www.justice.gov/opa/pr/known-cybersecurity-expert-and-owner-florida-ransomware-remediation-company-charged)
- [Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients (USAO EDNY)](https://www.justice.gov/usao-edny/pr/owner-florida-ransomware-remediation-company-charged-defrauding-clients)
- [The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers (ProPublica)](https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers)
- [Sting Catches Another Ransomware Firm, Red Mosquito, Negotiating With "Hackers" (ProPublica)](https://www.propublica.org/article/sting-catches-another-ransomware-firm-red-mosquito-negotiating-with-hackers)
- [Grifty "information security" companies promised they could decrypt ransomware-locked computers (Boing Boing)](https://boingboing.net/2019/05/16/john-pistole-shilled.html)
- [THE TRADE SECRET (Emsisoft mirror)](https://www.emsisoft.com/en/blog/33227/the-trade-secret-firms-that-promised-high-tech-ransomware-solutions-almost-always-just-pay-the-hackers/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3024
