Skip to content

US Charges MonsterCloud Owner With Hiding Ransom Payments

Zohar Pinhasi billed clients more than $19M while paying over $8M to the attackers he said he could work around, prosecutors allege. He has pleaded not guilty and is free on a $2M bond.

US Charges MonsterCloud Owner With Hiding Ransom Payments
Image courtesy: Unsplash

Zohar Pinhasi built MonsterCloud on a promise that it could unlock ransomware-encrypted files without paying the criminals who locked them. That promise was written for victims who did not want to fund an attacker. Prosecutors in Brooklyn say he was paying them all along, and a federal grand jury indicted him on 23 September on two counts of wire fraud and one of wire fraud conspiracy.

The 50-year-old from Hollywood, Florida, surrendered and pleaded not guilty on 7 October, the day the Justice Department announced the case. He was released on a $2M bond and faces up to 20 years on each count if convicted.

According to the indictment, MonsterCloud told victims it used proprietary tools and advanced decryption techniques, and its website advised them not to pay ransoms. Pinhasi and at least one employee instead contacted the attackers, bought the keys that unlock the files, and billed clients without saying a payment had been made.

In one case from around August 2023, prosecutors say the firm paid a ransom of roughly $8,200 and charged the client about $150,000. Across the alleged scheme they put the billing at more than $19M against more than $8M paid out.

A paid spokesperson asked Pinhasi in May 2019 whether MonsterCloud held proprietary decryption software. Prosecutors quote his answer: "Monstercloud doesn't hold any Proprietary technology [to] decrypt the ransomware data."

How The Upsell Allegedly Worked

Prosecutors say clients came in through an exploratory fee of between $2,500 and $10,000, after which the firm asked for the ransom note and some encrypted sample files. Requesting those is standard practice for any recovery outfit.

The samples then went to the criminals, prosecutors say, and the decrypted versions that came back were shown to the victim as proof of capability. A full recovery, the indictment says, was quoted at twice the ransom or more.

Some disclosure did sit in the contracts, which prosecutors say allowed for contact with or payment to criminals. The paperwork stated that such contact or payment would happen only if other methods failed, while prosecutors say reaching out to the attackers was usually the first step taken.

Reporting outside the court file puts the alleged scheme between June 2018 and June 2023, covering hundreds of clients in the United States and Canada. The Justice Department's own announcement gives neither a date range nor a victim count.

Journalists Described It In 2019

ProPublica published an investigation in May 2019 reporting that MonsterCloud paid ransoms without always informing victims, including local law enforcement agencies, while presenting recovery as its own work. None of the conduct now alleged is newly described.

Emsisoft researcher Fabian Wosar built a ransomware variant and infected one of his own machines in December 2016, then, posing as a victim who did not want to pay, approached several recovery firms. Wosar said anonymous offers of payment arrived at the fake attacker's accounts, and that he traced them back to the firms he had contacted.

Pinhasi disputed those findings at the time, calling the firm's methods a trade secret and saying the company had never promised recovery by any particular method. A further ProPublica sting later in 2019 caught a Scottish firm negotiating a ransom down to $900 and quoting the victim $3,950.

Seven years separate that reporting from this indictment, and no regulatory action, civil enforcement or legislative change traceable to the 2019 investigation could be found. Pinhasi disputed the findings at the time and the firm kept trading.

Paying A Ransom Is Not The Offence

Nothing in American federal law makes paying a ransom a crime, and the charges here concern alleged deception of clients rather than the payments themselves. The two counts of wire fraud and one of conspiracy turn on what customers were told.

A Treasury advisory updated in September 2021 warns that paying a blocked person can breach sanctions law on a strict liability basis, meaning a penalty is possible even where the payer had no reason to know. It names incident response firms, the companies hired to clean up after a breach, among the facilitators it is aimed at.

North Carolina went further for public bodies, barring its agencies from paying or even communicating with attackers, and Florida prohibited payments by state agencies, counties and municipalities from July 2022. The Treasury advisory, by its own admission, carries no force of law. Both states wrote their obligations into statute rather than leaving them to guidance.

Chainalysis put the share of victims paying at 28% in 2025, down from 62.8% in 2024, while the median payment rose sharply to $59,556. Fewer victims pay than at any point on record, and those who do, pay more.

What The Marketing Claimed

MonsterCloud advertised a free cyberterrorism crisis response programme for qualified police and sheriff departments, promising to clear an infection within a few hours in most cases, with guaranteed results or no charge. Nine video testimonials sat on its site, seven of them from public bodies. Its site named the Lauderdale County Sheriff's Office in Mississippi, Trumann Police Department in Arkansas, Lamar County Sheriff's Office in Texas and Mexico Beach Police Department in Florida.

Prosecutors describe the victims as business owners and clients, name no government customer, and put no figure on what any public body paid. None of those agencies appears in the indictment.

A Plea Talk And No Comment

A judge has granted a one-month delay while lawyers discuss a plea, according to CyberScoop, and Pinhasi's attorneys had not commented when reports were published. MonsterCloud did not respond to requests from several outlets, and no statement from the company or its owner has appeared since the charges were announced.

Tysen Duva, who leads the Justice Department's criminal division, said the defendant is alleged to have "victimized the victim again and committed additional fraud". A jury has yet to hear any of it.

Add Morning Tick on Google