The MonsterCloud case has reached US federal court, where the owner of a data recovery company faces charges of defrauding customers who had been hit by ransomware. Prosecutors allege that the company advertised its own decryption technology while paying the perpetrators for recovery keys.

The U.S. Department of Justice announced that Zohar Pinchasi, also known as Zach Silver or Zach Green, was arraigned in Brooklyn. A federal grand jury in the Eastern District of New York had indicted him on Sept. 23, 2026, according to a statement from prosecutors.
BleepingComputer reports that Pinchasi pleaded not guilty and was released on $2 million bail. The indictment includes one count of conspiracy to commit wire fraud and two counts of wire fraud; it is not a conviction.
What does the indictment allege in the MonsterCloud case?
MonsterCloud offered recovery services after ransomware attacks and, according to authorities, was pitching itself as an alternative to paying ransom. The company allegedly advertised “proprietary tools” and advanced decryption methods to recover files without aiding the extortionists.
The indictment, as summarized in the Justice Department's statement, alleges that Pinhasi did not have the specialized technology to decrypt the data. Instead, he allegedly contacted the perpetrators, purchased decryption keys from them, and then had them used by company employees.
Prosecutors also allege that the company charged customers much more than it paid the perpetrators. The discrepancy, according to the indictment, was part of the way the company charged for recovery services, while customers believed they were paying for an independent technical solution.
The indictment acknowledges that some contracts allowed for communication or payment to the perpetrators, but only if other decryption methods failed. Prosecutors argue that contacting the perpetrators was not a last resort, but often the first step to recovering files.
The MonsterCloud case doesn't mean that every recovery company that negotiates with perpetrators is committing fraud. The key difference prosecutors are looking at is whether customers were accurately informed about the recovery method and whether the company enforced what its contracts stipulated.

See also: Former engineer convicted of ransomware attack on his company
The amounts and previous reports
Authorities estimate that during the alleged practice, Pinhasi charged customers more than $19 million and paid over $8 million in ransom. In one example included in the official announcement, he allegedly paid about $8,200 for a decryption key and charged the customer about $150,000.
BleepingComputer's reporting says the indictment describes a practice that allegedly lasted from June 2018 to June 2023 and involved hundreds of businesses in the US and Canada. The amounts and incidents are allegations by the prosecution, not judicial findings.
The MonsterCloud case also reignited interest in an earlier 2019 ProPublicathat examined recovery companies that paid ransoms while advertising themselves as a no-fee solution. At the time, Pinhasi described MonsterCloud’s methods as a trade secret and denied misleading customers. The earlier investigation is not evidence for the current charges, but it adds historical context.
See also: Ransomware at the University of Illinois Chicago – The Medical School is in the spotlight
What customers need to check
For organizations seeking help after an attack, the SecNews technical team recommends requesting a written description of the recovery method, clear information about possible contact or payment to the perpetrators, and a detailed cost breakdown. The terms should make it clear who authorizes each payment and what happens if the recovery fails.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
An independent review of available backups and technical options can help before making any decisions. Organizations need to regularly test their backups and maintain at least one disconnected copy to limit their reliance on an external provider. The MonsterCloud case is a reminder that a promise of recovery alone is not enough: customers need a verifiable process, clear contractual terms, and regular updates.

The court process will determine whether the charges are substantiated. The Justice Ministry emphasizes that Pinhasi is presumed innocent until proven guilty, while the charges could carry up to 20 years in prison if convicted.
See also: Cyberattack on Arizona's judicial system: 1.3 million victims
