// 3 ZERO-DAY · 5 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
Zohar Pinhasi, CEO of MonsterCloud, has been indicted in Brooklyn for defrauding ransomware victims. He secretly paid ransoms and billed clients massive markups while claiming proprietary decryption technology.

Zohar Pinhasi, 50, a U.S. and Israeli citizen, was indicted on September 23, 2026, in the Eastern District of New York for a fraud scheme that turned the desperation of ransomware victims into a parallel market. The owner and CEO of MonsterCloud LLC, a Florida-based ransomware remediation firm, Pinhasi claimed to recover data through "advanced decryption techniques" and "proprietary tools." According to the federal indictment, the reality was different: he contacted the cybercriminals, paid the ransoms, then billed clients amounts far exceeding what he paid the attackers.

Key Takeaways
  • Pinhasi is charged with two counts of wire fraud and one count of wire fraud conspiracy; he faces up to 20 years in prison on each count.
  • Between June 2018 and June 2023, MonsterCloud allegedly billed clients more than $19 million and paid more than $8 million in ransoms to cybercriminals.
  • In one documented case from the indictment, Pinhasi paid roughly $8,200 in ransom in August 2023 and billed the client approximately $150,000—a markup of nearly 18 times.
  • A 2019 ProPublica sting operation had already documented the same scheme; John Pistole, former FBI deputy director and then MonsterCloud spokesman, admitted that "paying the ransom" was the business model.

The Mechanism: Information Arbitrage on Clients in Crisis

The system operated on a deliberate asymmetry. MonsterCloud's website posed an explicit question: "Do you pay ransoms?" The answer was framed in ambiguous terms, sufficient to suggest the company possessed technological alternatives. Some contracts acknowledged possible contact with criminals, but only as a last resort after the failure of "other means." The indictment alleges the opposite: ransom payment was the standard first step, not the last resort.

The decryptor obtained from the ransomware operators was then used to "demonstrate" recovery. MonsterCloud presented the decrypted files as proof of its own technical expertise, inducing new clients to sign contracts. The decryptor was standard, not proprietary; the expertise was negotiational, not engineering. The difference between the actual cost and the final invoice was not a legitimate commercial margin but, according to the prosecution, the core of the fraud.

"By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself."
— Joseph Nocella Jr., U.S. Attorney, Eastern District of New York

The Numbers of a Multi-Year Scheme

The indictment data outlines a structured, prolonged operation. Between June 2018 and June 2023, MonsterCloud allegedly collected more than $19 million from clients, of which more than $8 million was returned to attackers as ransoms. The remaining $11 million represents the gross difference, before operating expenses.

Two specific cases illustrate the scale of the markup. In October 2021, according to BleepingComputer, Pinhasi paid roughly $236,000 in ransom and billed the client approximately $380,000. In August 2023, according to The Hacker News, the ransom was about $8,200 and the invoice about $150,000. The cost-to-price ratio in the second case exceeds 18:1. These numbers are not anecdotal; the indictment uses them to exemplify a systemic pattern, not an exception.

A Pattern Already Documented: The 2019 Sting Operation

The case is no surprise to those who followed the sector. In 2019, ProPublica conducted an investigation that included a sting operation designed by researcher Fabian Wosar: he created a fictitious ransomware, simulated an activation, and observed the responses of recovery firms. MonsterCloud responded by offering to manage the payment. Pinhasi denied the allegations at the time.

The most revealing detail comes from John Pistole, the former FBI deputy director hired by MonsterCloud as a spokesman. Interviewed by ProPublica, Pistole admitted without hesitation: "The model I'm used to is, you pay the ransom." The statement, made in 2019, now serves as a link between the journalistic investigation and the federal indictment: the scheme was known, documented, and yet continued to operate for seven years.

The dossier does not clarify why the 2019 investigation did not lead to immediate charges. This is a significant gap: it separates public awareness from judicial action and raises questions about enforcement delays.

DOJ Enforcement and the Parallel Remediation Market

The Pinhasi indictment marks an intensification of the Justice Department's focus not only on attackers but on those who profit secondarily from them. Assistant Attorney General A. Tysen Duva framed the charge in explicit terms: "The defendant is charged with offering an alternative to ransom payments, but instead allegedly re-victimized victims and committed additional fraud." The message is directed at the industry: remediation is not a free-fire zone.

James C. Barnacle Jr., FBI assistant director, added a relevant technical-political element: "As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat." The distinction is subtle but crucial. Paying the ransom resolves the symptom (encrypted files) not the cause (network compromise). An operation that stops at the decryptor leaves the client exposed to a new infection, perhaps by the same attacker. According to the indictment, MonsterCloud not only failed to resolve the threat but exploited it commercially.

Pinhasi surrendered to authorities, pleaded not guilty at arraignment, and was released on a $2 million bond. The case is assigned to Judge Ramon E. Reyes Jr.

Why It Matters

The dossier does not specify whether MonsterCloud is still operational at the time of the indictment. It does not clarify the exact number of clients involved or the identity of the co-conspirators mentioned in the charges. It does not document how the more than $11 million difference between receipts and ransoms was used—whether for operating expenses, taxes, or other purposes.

What the case makes evident is a structural conflict in the cybersecurity market. Ransomware victims seek alternatives to direct payment, fearing they will fund organized crime or violate internal policies. Remediation vendors exploit this need by offering a technological solution that, in this case, did not exist. The information asymmetry is not a side effect but the foundation of the business model.

For companies, the case demands concrete verification: due diligence on incident response vendors cannot be limited to unverifiable intellectual property claims. For the industry, the indictment signals that the ransomware chain includes intermediate links subject to criminal liability, not just the primary attackers.

Information has been verified against cited sources and is current as of publication.

Sources

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. cyberscoop.com
  2. thehackernews.com
  3. justice.gov
  4. bleepingcomputer.com
  5. therecord.media
  6. cybernews.com