MonsterCloud Owner Arraigned Over Fake Decryption Claims
Zohar Pinhasi, owner of cybersecurity firm MonsterCloud, faces wire fraud charges for allegedly paying ransomware extortionists while claiming to use proprietary decryption technology.

Zohar Pinhasi, the owner of ransomware remediation firm MonsterCloud who also used the names Zack Silver and Zack Green, has been arraigned in New York on wire fraud charges. Prosecutors accuse Pinhasi of falsely claiming that his company possessed specialized decryption techniques capable of recovering files without fulfilling hacker extortion demands. Instead of using proprietary technology, MonsterCloud allegedly bought decryption keys directly from cybercriminals and passed off those keys as in-house solutions.
The scheme allowed Pinhasi to extract exorbitant profits from desperate victims. In one cited 2023 case, he allegedly paid an attacker $8,200 for a key while billing his client $150,000 for the recovery service. District Attorney Joseph Nocella noted that Pinhasi re-victimized his clients to secure a hefty profit, exploiting organizations seeking alternatives to paying cybercriminals directly.
Victims often hire remediation firms to avoid legal pitfalls, as US government guidelines strongly discourage ransom payments. Furthermore, making direct transfers to foreign threat groups can violate trade sanctions and trigger criminal liability. Ilia Kolochenko from ImmuniWeb noted that fraudulent actors frequently exploit these fears, using tactics such as fake law enforcement contact, Dark Web monitoring scams, or billing extra fees under the guise of third-party data erasure validation. Kolochenko pointed out that similar legal actions occurred recently, including a July case against a Florida enterprise and a May proceeding against a Latvian national.
For enterprise risk officers and incident response leaders, this case highlights the immense danger of unverified incident vendors. Organizations facing a breach must demand clear verification of technical methodology and cryptographic proof rather than trusting third-party recovery claims. Failure to properly audit external negotiators risks severe financial markups, compliance breaches, and unintended exposure to federal sanction violations.
This is our own summary of reporting by Computerworld AI



