The U.S. Department of Justice on Wednesday charged a Florida company owner with defrauding ransomware victims out of more than $19 million by secretly paying hackers while falsely claiming to use proprietary decryption tools. Zohar Pinhasi, a 50-year-old dual U.S. and Israeli citizen who operated MonsterCloud under aliases including Zack Silver and Zack Green, faces two counts of wire fraud and one count of wire fraud conspiracy, each carrying a potential 20-year prison sentence. The indictment alleges Pinhasi misled clients into believing his company possessed advanced technology to unlock encrypted data without negotiating with criminals, when in reality he simply paid the ransoms and charged massive markups.

The financial scale of the alleged fraud was substantial. Prosecutors say Pinhasi collected more than $19 million in fees from clients while actually paying out more than $8 million in ransom payments to cybercriminals. In one August 2023 case, the defendant allegedly paid approximately $8,200 to a threat actor but billed the client roughly $150,000—an 18-fold markup. Another incident around October 2021 involved a ransom payment of about $236,000 that resulted in a customer charge of approximately $380,000. MonsterCloud's website promoted "advanced decryption techniques and cutting-edge technology" and explicitly discouraged ransom payments, stating that paying cybercriminals "does not guarantee a positive outcome" and "only serves to encourage and reward their illegal behavior."

According to U.S. Attorney Joseph Nocella, Jr. for the Eastern District of New York, "By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself." FBI Assistant Director James C. Barnacle Jr. stated that Pinhasi "turned the victim's crisis into his own profit center," adding that the deception is unacceptable. While MonsterCloud's website included a service contract disclosure acknowledging it sometimes resorts to "other means" when working with ransomware perpetrators, prosecutors allege the company possessed no specialized decryption tools whatsoever and relied entirely on paying the attackers.

The charges underscore how victims of cyberattacks can face additional exploitation from those claiming to offer recovery services. The case illustrates a pattern where desperate organizations, already reeling from data encryption, become vulnerable to inflated fees from intermediaries who present themselves as technical experts. Pinhasi's alleged approach involved approaching the same cybercriminals his clients were trying to avoid, negotiating payments, then presenting the resulting decryptors as the product of proprietary technology—a scheme prosecutors say allowed him to extract profit margins of several hundred percent while leaving the underlying security threats unaddressed. The indictment highlights how the ransomware ecosystem can create opportunities not just for attackers but also for deceptive service providers who exploit the urgency and technical confusion surrounding these incidents. Companies facing this type of extortion increasingly find themselves navigating a marketplace where distinguishing legitimate assistance from opportunistic schemes requires caution, particularly when providers make sweeping claims about capabilities that bypass standard negotiation channels with threat actors.

If convicted on all counts, Pinhasi could face up to 60 years in federal prison. The case represents one of the Justice Department's efforts to target not only ransomware operators but also those who profit from the victimization process itself. For organizations confronting ransomware attacks, the prosecution serves as a reminder that recovery service providers should be vetted carefully, particularly when they claim technical capabilities that seem to eliminate the need for any engagement with attackers. Firms navigating this landscape may face pressure to accept bold promises during moments of crisis, but the underlying economics of data recovery remain unchanged regardless of marketing language. The investigation reveals how inflated service fees can dwarf the actual ransom amounts, turning an already costly security breach into a financial catastrophe driven not by criminals alone but by those positioned as saviors.