In about August 2023, prosecutors say, a Florida ransomware recovery company paid a cybercriminal roughly $8,200 to unlock a client’s files and then billed that client about $150,000. The owner, Zohar Pinhasi, 50, of Hollywood, Florida, was arraigned October 7 in federal court in Brooklyn on wire fraud charges. Over the whole scheme, the indictment alleges, he charged clients more than $19 million.
The company, MonsterCloud LLC, told customers it was a principled alternative to paying the hackers who locked their data. Prosecutors say it was the opposite: it paid the attackers, over $8 million in ransoms in all, and sold the result as its own technical skill. Pinhasi, also known as “Zack Silver” and “Zack Green,” is presumed innocent unless proven guilty, and the charges are allegations.
The people on the receiving end, according to the Justice Department, were distressed business owners who had already been hit by ransomware. For anyone weighing who to call after an attack, the case raises a plain question: what a recovery firm says about how it unlocks data can decide whether a bill reflects a service or a multiple of the ransom.
The grand jury indicted Pinhasi on September 23 and he was arraigned October 7, but the Justice Department’s releases give no trial date yet.
Get the deadline alerts before they pass →
What the website promised
The Justice Department’s Criminal Division release says MonsterCloud’s website cautioned clients against paying ransoms and claimed “proprietary tools” and “advanced decryption techniques.” The indictment alleges the company had no special decryption technology.
What it did, prosecutors say, was contact the criminals behind each attack, pay them, get a decryption key and have MonsterCloud staff run that key against the client’s files.
The charges are two counts of wire fraud and one count of wire fraud conspiracy. Each count carries a maximum of 20 years in prison.
An $8,200 payment and a $150,000 invoice
The mark-up is the heart of the case. The Eastern District of New York’s release says that across the scheme Pinhasi allegedly charged clients more than $19 million while paying more than $8 million in ransoms. The August 2023 example, $8,200 paid and about $150,000 billed, shows how far apart the two figures could sit on a single job.
The same release describes a 2019 exchange. In May of that year, a paid spokesperson who was writing testimonials for MonsterCloud’s website asked whether the company had proprietary decryption software. Pinhasi replied that MonsterCloud “doesn’t hold any Proprietary technology [to] decrypt the ransomware data.” The EDNY release cites that message alongside the website’s claims.
A question first raised in 2019
The business model drew scrutiny before the indictment. A 2019 ProPublica investigation reported that MonsterCloud and another firm, Proven Data Recovery, claimed proprietary recovery methods while paying ransoms. In a 2016 test, researcher Fabian Wosar infected his own computer with ransomware he said he could not break and posed as a victim. MonsterCloud and other firms said they could decrypt it and did not mention paying the ransom, according to ProPublica.
Pinhasi told ProPublica at the time that MonsterCloud’s methods were a trade secret and that its recovery rate reflected knowing “who these attackers are and their typical methods of operation.” The FBI told the outlet that ransom payment “encourages continued criminal activity.” Proven Data has never been charged, ProPublica said, and its chief executive denied a close relationship with attackers. Nothing in the 2026 releases involves that company.
The officials behind the case
A. Tysen Duva, the Assistant Attorney General for the Criminal Division, said the case “underscores the Department’s commitment to protecting ransomware victims, regardless of how these cyber ransoms occur.” Joseph Nocella, Jr., the U.S. Attorney for the Eastern District of New York, said, “Our Office will vigorously prosecute ransomware attackers.” James C. Barnacle Jr., the FBI’s assistant director in charge of its New York Field Office, said the bureau is committed to accountability for those who victimize people who sought their help.
Magistrate Judge Peggy Cross-Goldenberg presided over the arraignment, and the case number is 26-CR-271. The FBI investigated. Prosecutors include Senior Trial Attorneys Brian Mund and Vasantha Rao of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorneys Alexander Mindlin and Lindsey Oken, with Laura Mantell handling forfeiture.
Hiring help after a ransomware attack
The Justice Department’s own release is the free source for the allegations and cites joint FBI and Cybersecurity and Infrastructure Security Agency guidance that does not recommend paying ransoms. That guidance says paying does not guarantee data will be decrypted, that systems will stop being compromised, or that data won’t be leaked. A firm that promises a recovery without a payment should be able to say how, in writing, before any work begins.
Before signing, a business can ask four things: whether the firm ever pays attackers on a client’s behalf, whether any such payment is passed through at cost, how the fee is calculated, and whether the client approves each payment. The answers, kept in an email or contract, are the paper trail that matters in a dispute over a bill. In this case the figures prosecutors cite as the gap are $8,200 paid and about $150,000 billed.
The charges against Pinhasi are untested in court. For now the public record is the pair of Justice Department releases dated October 7 and the case number, 26-CR-271, in the Eastern District of New York.
More Financial Reading
- 24 Ways to Stretch a $2,087 Social Security Check
- 17 Places to Find Your Share of the $4.25 Billion States Give Back
- 16 Steps to Stop the Scams That Took $7.7 Billion From Seniors
This article was produced with AI assistance and reviewed by The Financial Wire’s editorial team.



