Skip to content
feed: live
0dayNews
ransomware
● Breaking

MonsterCloud CEO Charged for Secret Ransom Scheme

Zohar Pinhasi charged with wire fraud after prosecutors allege he secretly paid ransomware operators while billing victims over $19 million for proprietary recovery services.

MonsterCloud CEO Charged for Secret Ransom Scheme
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

The CEO of Florida ransomware recovery firm MonsterCloud was arraigned Wednesday on federal wire fraud charges. According to prosecutors, Zohar Pinhasi, 50, secretly paid ransomware operators for decryption keys while telling clients the company used proprietary technology to recover their data.

The indictment, filed September 23 in the Eastern District of New York, covers alleged activity from June 2018 through June 2023. Pinhasi pleaded not guilty and was released on $2 million bond. Charges are allegations; no conviction has been entered.

The numbers in the charging documents: MonsterCloud collected more than $19 million in total recovery fees over the period. Prosecutors allege the company passed more than $8 million of that directly to ransomware operators. Two transactions cited: one client billed $150,000 after the actual ransom paid was $8,200; another billed $380,000 after a $236,000 payment to attackers.

MonsterCloud contracts, per the indictment, told clients the company would contact criminals only if other recovery methods had failed. Prosecutors allege the practice was the opposite: contacting attackers was typically the first step.

Pinhasi faces three counts. Count one: conspiracy to commit wire fraud. Counts two and three: wire fraud. Maximum exposure is up to 20 years per count if convicted.

U.S. Attorney Joseph Nocella Jr. stated Pinhasi “re-victimized his clients while extracting a hefty profit.”

The case is distinct from a standard ransomware prosecution. Victims here faced two layers of financial harm: the original ransomware group demanded payment, then the firm hired to solve the problem allegedly marked up those payments and billed for services it wasn’t performing. The DOJ has not stated whether any individual victims have been identified as witnesses.

Confidence: confirmed via DOJ indictment (EDNY, September 23, 2026) and arraignment proceedings. The defense has entered a not-guilty plea; trial date not yet set.


Related coverage: ShinyHunters Member Arrested in Jordan, Aiding FBI, Ransomware Hits UIC Medical School, Data Stolen, Vicksburg, Miss. Ransomware Attack Shuts Down City Systems.

Found this useful? Share it.