Zohar Pinhasi, owner of Florida ransomware-recovery firm MonsterCloud, was arraigned in Brooklyn on 7 October 2026 on fraud charges. Prosecutors say the company had no proprietary decryptor. It paid the attackers, then billed the victim more.
What happened
A federal grand jury in the Eastern District of New York indicted Pinhasi on 23 September. He faces one count of conspiracy to commit wire fraud and two counts of wire fraud, covering June 2018 to June 2023. He pleaded not guilty and was released on a $2 million bond. He also uses the names Zack Silver and Zack Green.
The indictment says MonsterCloud advertised recovery without paying criminals. Some contracts did mention that the firm might contact attackers, but only if other methods failed. Prosecutors say paying the gang was usually the first step. Decrypted sample files, supplied by the operators, were then shown to victims as proof the tool worked.
One cited job: about $8,200 paid to the gang, about $150,000 charged to the client. Another: about $236,000 paid, about $380,000 charged. Across the alleged scheme, the firm facilitated more than $8 million in ransom payments and billed US and Canadian companies more than $19 million. If convicted, Pinhasi faces up to 20 years. These are allegations. He has pleaded not guilty.
Who is affected
The charging documents name customers in the United States and Canada, not a specific South African victim. The operational point is wider. Any company that hires a recovery firm in a panic can be pushed into a second payment, to the attacker, without a board-level decision to pay.
- Victims who hired a firm that promised decryption without paying
- Insurers and IR retainers that outsource decryption to an unnamed partner
- Boards that never authorised a ransom payment, but funded one through a recovery invoice
What to do now
Ask the recovery firm, in writing, whether they will contact the attacker or buy a key. If the answer is vague, or the method is a trade secret, assume a payment is the plan. A decrypted sample is not proof of an independent tool. Keep the pay-or-not decision with the board, and keep negotiating identity, sanctions, and evidence handling out of the decryptor invoice.
Source: BleepingComputer, Ransomware recovery CEO charged over secret ransom payments. DOJ release: US Attorney's Office, Eastern District of New York.
Also on the blog
- CVE-2026-21589: unauthenticated file read on 8 Atlassian products
- FortiBleed: FBI says 86,644 FortiGate devices still locked out
- tensorlake 0.5.144: npm worm steals cloud and AI-tool credentials
- Chrome 155 patches 247 flaws, four of them critical
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.