Threat Intelligence

Ransomware Recovery Firm Owner Charged Over Alleged Secret Ransom Payments and Inflated Bills

The Hacker News · 8 Oct 2026
Key Takeaway Before hiring any ransomware recovery provider, ask in writing how they will recover your data and whether they will pay attackers on your behalf, and keep tested offline backups so you are never forced to rely on a claim you cannot verify.

The US Department of Justice has charged Zohar Pinhasi, a 50-year-old US and Israeli national also known as Zack Silver and Zack Green, with two counts of wire fraud and one count of wire fraud conspiracy. He owned and operated MonsterCloud, a Florida company. If convicted, he faces up to 20 years in prison for each count.

Prosecutors allege Pinhasi told ransomware victims not to pay criminals and said he had "proprietary tools" and "advanced decryption techniques" to recover their data. According to the source, no such specialised tools existed. Instead, he allegedly approached the attackers, paid them for a decryptor, and then charged clients a fee "substantially higher" than the ransom. In one August 2023 case, he allegedly paid a threat actor about $8,200 and billed the client about $150,000.

MonsterCloud's website said paying a ransom does not guarantee a good outcome and only rewards criminals. Its Q&A also said the company "sometimes resort[s] to other means" and that all terms are disclosed in its service contract. US Attorney Joseph Nocella, Jr. said the defendant "re-victimized his clients while extracting a hefty profit for himself."

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.