Back to Feed
Incident ResponseOct 8, 2026

Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme

MonsterCloud owner charged with $11M fraud scheme buying ransomware decryption keys and reselling to victims.

Summary

Zohar Pinhasi, owner of MonsterCloud, was charged with wire fraud for deceiving ransomware victims. Instead of using proprietary decryption tools as claimed, Pinhasi allegedly paid ransoms to attackers for decryption keys and charged victims substantially higher fees for their recovery. Over the scheme's duration, Pinhasi paid over $8 million in ransoms while billing clients over $19 million—a markup exceeding $11 million.

Full text

The owner of a US company was charged with defrauding clients through a ransomware remediation scheme. Zohar Pinhasi, 50, the owner of MonsterCloud, a US and Israeli national also known as ‘Zack Silver’ and ‘Zack Green’, appeared in a New York court to face wire fraud charges. According to the indictment, Pinhasi claimed that MonsterCloud could help organizations that fell victim to ransomware to recover their data without paying the attackers. While cautioning ransomware victims not to pay the attackers, Pinhasi allegedly falsely claimed his company could decrypt ransomware. Pinhasi allegedly claimed that MonsterCloud was using proprietary tools and advanced decryption techniques to recover encrypted data without paying the attackers. Instead, he contacted the ransomware groups that hacked his clients, paid ransoms to obtain the decryption keys, and then charged the victim organizations a fee when using the decryption key to restore the data.Advertisement. Scroll to continue reading. In one instance, he made a ransom payment of approximately $8,200 to a ransomware affiliate, and then charged the client approximately $150,000. Throughout the scheme, he allegedly paid over $8 million in ransoms and charged his clients over $19 million. Pinhasi was charged with wire fraud and wire fraud conspiracy and could be sentenced to tens of years in prison. “The defendant is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again and committed additional fraud, harming the victim again,” Assistant Attorney General A. Tysen Duva said. Related: Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany Related: FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware Related: Alleged ShinyHunters Leader Arrested in Jordan Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire ASOS Confirms Cyberattack, Data BreachAndroid’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsFBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareApple to Tighten Full Disk Access Controls in macOS Amid AI RisksLong-Running NPM Malware Campaign Accumulates 40,000 Downloads8.8 Million Impacted by Data Breach at Denmark’s Central Person RegisterLinux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws Latest News Oracle Health Data Breach Tally Climbs to Nearly 20 MillionFortiBleed Attackers Locking Victims Out of Fortinet DevicesGeorgia Power, Alabama Power Data Breach Hits 400,000 AccountsQilin Ransomware Suspect Arrested in Japan, Extradited to GermanyHadrian Raises $40 Million to Expand Autonomous Offensive Security PlatformAdvantest Discloses Data Breach Months After Ransomware AttackChrome 155 Update Patches 247 VulnerabilitiesAnthropic Introduces 3-Tier Cyber Verification Program for AI Access Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Entities

MonsterCloud (vendor)Zohar Pinhasi (aliases: Zack Silver, Zack Green) (threat_actor)