HomeSecurityMonsterCloud Case: Charges for Hidden Ransom Payments

MonsterCloud Case: Allegations of Hidden Ransom Payments

The MonsterCloud case has reached US federal court, where the owner of a data recovery company faces charges of defrauding customers who had been hit by ransomware. Prosecutors allege that the company advertised its own decryption technology while paying the perpetrators for recovery keys.

The MonsterCloud case and data recovery

The U.S. Department of Justice announced that Zohar Pinchasi, also known as Zach Silver or Zach Green, was arraigned in Brooklyn. A federal grand jury in the Eastern District of New York had indicted him on Sept. 23, 2026, according to a statement from prosecutors.

BleepingComputer reports that Pinchasi pleaded not guilty and was released on $2 million bail. The indictment includes one count of conspiracy to commit wire fraud and two counts of wire fraud; it is not a conviction.

What does the indictment allege in the MonsterCloud case?

MonsterCloud offered recovery services after ransomware attacks and, according to authorities, was pitching itself as an alternative to paying ransom. The company allegedly advertised “proprietary tools” and advanced decryption methods to recover files without aiding the extortionists.

The indictment, as summarized in the Justice Department's statement, alleges that Pinhasi did not have the specialized technology to decrypt the data. Instead, he allegedly contacted the perpetrators, purchased decryption keys from them, and then had them used by company employees.

Prosecutors also allege that the company charged customers much more than it paid the perpetrators. The discrepancy, according to the indictment, was part of the way the company charged for recovery services, while customers believed they were paying for an independent technical solution.

The indictment acknowledges that some contracts allowed for communication or payment to the perpetrators, but only if other decryption methods failed. Prosecutors argue that contacting the perpetrators was not a last resort, but often the first step to recovering files.

The MonsterCloud case doesn't mean that every recovery company that negotiates with perpetrators is committing fraud. The key difference prosecutors are looking at is whether customers were accurately informed about the recovery method and whether the company enforced what its contracts stipulated.

Decryption keys and storage media

See also: Former engineer convicted of ransomware attack on his company

The amounts and previous reports

Authorities estimate that during the alleged practice, Pinhasi charged customers more than $19 million and paid over $8 million in ransom. In one example included in the official announcement, he allegedly paid about $8,200 for a decryption key and charged the customer about $150,000.

BleepingComputer's reporting says the indictment describes a practice that allegedly lasted from June 2018 to June 2023 and involved hundreds of businesses in the US and Canada. The amounts and incidents are allegations by the prosecution, not judicial findings.

The MonsterCloud case also reignited interest in an earlier 2019 ProPublicathat examined recovery companies that paid ransoms while advertising themselves as a no-fee solution. At the time, Pinhasi described MonsterCloud’s methods as a trade secret and denied misleading customers. The earlier investigation is not evidence for the current charges, but it adds historical context.

See also: Ransomware at the University of Illinois Chicago – The Medical School is in the spotlight

What customers need to check

For organizations seeking help after an attack, the SecNews technical team recommends requesting a written description of the recovery method, clear information about possible contact or payment to the perpetrators, and a detailed cost breakdown. The terms should make it clear who authorizes each payment and what happens if the recovery fails.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

An independent review of available backups and technical options can help before making any decisions. Organizations need to regularly test their backups and maintain at least one disconnected copy to limit their reliance on an external provider. The MonsterCloud case is a reminder that a promise of recovery alone is not enough: customers need a verifiable process, clear contractual terms, and regular updates.

Secure data recovery process

The court process will determine whether the charges are substantiated. The Justice Ministry emphasizes that Pinhasi is presumed innocent until proven guilty, while the charges could carry up to 20 years in prison if convicted.

See also: Cyberattack on Arizona's judicial system: 1.3 million victims

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS