MonsterCloud CEO charged over secret ransom payments
Recovery firm allegedly paid attackers, then billed victims far more

MonsterCloud CEO charged over secret ransom payments

Zohar Pinhasi, owner of Florida ransomware-recovery firm MonsterCloud, was arraigned in Brooklyn on 7 October 2026 on fraud charges. Prosecutors say the company had no proprietary decryptor. It paid the attackers, then billed the victim more.

What happened

A federal grand jury in the Eastern District of New York indicted Pinhasi on 23 September. He faces one count of conspiracy to commit wire fraud and two counts of wire fraud, covering June 2018 to June 2023. He pleaded not guilty and was released on a $2 million bond. He also uses the names Zack Silver and Zack Green.

The indictment says MonsterCloud advertised recovery without paying criminals. Some contracts did mention that the firm might contact attackers, but only if other methods failed. Prosecutors say paying the gang was usually the first step. Decrypted sample files, supplied by the operators, were then shown to victims as proof the tool worked.

One cited job: about $8,200 paid to the gang, about $150,000 charged to the client. Another: about $236,000 paid, about $380,000 charged. Across the alleged scheme, the firm facilitated more than $8 million in ransom payments and billed US and Canadian companies more than $19 million. If convicted, Pinhasi faces up to 20 years. These are allegations. He has pleaded not guilty.

Who is affected

The charging documents name customers in the United States and Canada, not a specific South African victim. The operational point is wider. Any company that hires a recovery firm in a panic can be pushed into a second payment, to the attacker, without a board-level decision to pay.

  • Victims who hired a firm that promised decryption without paying
  • Insurers and IR retainers that outsource decryption to an unnamed partner
  • Boards that never authorised a ransom payment, but funded one through a recovery invoice

What to do now

Ask the recovery firm, in writing, whether they will contact the attacker or buy a key. If the answer is vague, or the method is a trade secret, assume a payment is the plan. A decrypted sample is not proof of an independent tool. Keep the pay-or-not decision with the board, and keep negotiating identity, sanctions, and evidence handling out of the decryptor invoice.

Source: BleepingComputer, Ransomware recovery CEO charged over secret ransom payments. DOJ release: US Attorney's Office, Eastern District of New York.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-102255: SonicWall SMA1000 SSRF scores CVSS 10
Pre-authentication SSRF on SMA1000 Work Place, fixed in this week's hotfixes