discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The owner of MonsterCloud, Zohar Pinhasi, is accused of defrauding ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary tools. He allegedly charged clients millions more than the ransoms paid.

By Ravie Lakshmanan·Oct 8·thehackernews.com·3 min read

Intelligence analysis by Gemini 2.5 Flash Lite

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
Image: thehackernews.com

Zohar Pinhasi, owner of MonsterCloud, faces federal charges for allegedly deceiving ransomware victims. Instead of using proprietary tools as claimed, he secretly paid ransoms to attackers to decrypt data, then billed clients significantly higher amounts, pocketing the difference.

Why it matters

This case highlights a severe breach of trust in the cybersecurity services sector, where a company allegedly exploited its clients' crises for profit, undermining legitimate data recovery efforts and potentially encouraging further criminal activity.

Imagine a firefighter who claims to have a magic hose that puts out fires without water. But secretly, they just pay the arsonist to stop, then charge you a huge fee for their 'magic' service. That's what this company owner is accused of doing with computer viruses.

Analysis

Zohar Pinhasi

Zohar Pinhasi, also known by aliases Zack Silver and Zack Green, is the central figure in this case, accused by the U.S. Department of Justice of orchestrating a fraudulent scheme. Pinhasi, a dual U.S. and Israeli national, allegedly operated MonsterCloud, a company that purported to offer advanced solutions for ransomware recovery. The charges, including wire fraud and conspiracy, stem from his alleged practice of misrepresenting his company's capabilities to desperate clients.

Instead of employing the 'proprietary tools' and 'advanced decryption techniques' advertised on MonsterCloud's website, Pinhasi is accused of directly negotiating with and paying cybercriminals to obtain the necessary decryptors. This clandestine operation allowed him to present a facade of successful data recovery while secretly engaging with the very entities his clients were trying to combat. The DOJ's indictment paints a picture of a calculated deception designed to maximize personal profit at the expense of victims already in distress.

MonsterCloud

MonserCloud, the Florida-based company owned by Pinhasi, is at the heart of the alleged fraud. The company's public-facing materials, including its website, promoted a strong stance against paying ransoms, advising clients that doing so "only serves to encourage and reward their illegal behavior." It also claimed to possess "extensive experience working with ransomware perpetrators" and sometimes resorting to "other means to resolve the ransomware incident for our clients," with terms disclosed in service contracts.

However, the reality, as alleged by prosecutors, was starkly different. The company's claims of specialized decryption tools were reportedly false. Instead, Pinhasi allegedly acted as an intermediary, paying ransoms himself and then marking up the cost substantially before billing the clients. This created a profitable business model where the client's crisis directly fueled Pinhasi's income, with the company's purported ethical stance serving as a cover for its illicit activities.

$19 Million in Alleged Fraud

The scale of the alleged financial misconduct is substantial, with Pinhasi accused of charging clients over $19 million in total fees. Against this, he is said to have paid out more than $8 million in ransom payments to cybercriminals. The disparity between the amounts billed and the amounts paid to attackers represents the alleged profit margin Pinhasi secured through his deceptive practices.

Specific examples cited by the Department of Justice illustrate the magnitude of the alleged overcharging. In one instance in August 2023, a ransom payment of approximately $8,200 was allegedly billed to a client for around $150,000. Another case from October 2021 involved a ransom payment of roughly $236,000, with the client being charged approximately $380,000. These figures underscore the significant markups and the extent to which Pinhasi allegedly exploited his clients' vulnerability for personal gain.

Key points

  • MonsterCloud owner Zohar Pinhasi faces charges for defrauding ransomware victims.
  • Pinhasi allegedly paid ransoms secretly while claiming to use proprietary decryption tools.
  • He is accused of charging clients significantly more than the ransoms paid.
  • Total alleged client billing exceeds $19 million, with over $8 million paid in ransoms.
  • The U.S. Department of Justice is prosecuting the case.
The Upside

The prosecution of Zohar Pinhasi could serve as a strong deterrent to other cybersecurity service providers who might consider exploiting clients' data breach crises. It may also encourage greater transparency and due diligence from clients seeking ransomware recovery services.

The Downside

The alleged actions of Pinhasi could erode trust in legitimate cybersecurity firms, making victims more hesitant to seek professional help. It might also embolden cybercriminals if they perceive that such intermediaries are common and profitable.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybercrimeransomwarefraudlaw-enforcementstartups

Author

Ravie Lakshmanan

Intelligence analysis by

Gemini 2.5 Flash Lite

Published

Oct 8, 2026

Source

thehackernews.com

Share

Topics

securitycybercrimeransomwarefraudlaw-enforcementstartups

Related

More from this desk

Oct 8·bleepingcomputer.com

Maryland Man Found Guilty of Stealing $53 Million from Decentralized Crypto Exchange Uranium Finance

Maryland man convicted of hacking Uranium Finance, a decentralized crypto exchange, and stealing $53 million in cryptocurrency.

Oct 8·wired.com

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

A Telegram group helps Palestinian drivers navigate checkpoints in the West Bank, where popular navigation apps fail them.

Oct 8·thehackernews.com

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.

Oct 8·bleepingcomputer.com

Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

Security researchers collected $232,500 in cash awards at Pwn2Own Ireland 2026, with Samsung Galaxy S26 getting hacked three times.