Tidavo
Thursday 8 October 2026

Head of data recovery firm faces federal charges over secret ransom payouts

Prosecutors say a security firm owner took millions from hacked clients while quietly buying unlock keys directly from extortionists.

8 Oct 2026

When computer networks get locked by extortion software, known as ransomware, panicked business owners often search for specialists who can save their files. Many firms promise to unlock the scrambled records using special software without ever dealing with the hackers who caused the trouble.

Federal prosecutors say one prominent provider was running a very different kind of business. Zohar Pinhasi, the fifty-year-old owner of Florida-based MonsterCloud, now faces criminal fraud charges in New York for allegedly misleading his customers for half a decade.

The government says Pinhasi told clients his company possessed unique tools that could restore hostage files safely. His public materials urged victims not to pay the cybercriminals, marketing his team as an ethical and technically superior alternative to giving in to extortion demands.

Instead of inventing clever ways to crack the encryption, Pinhasi allegedly reached out directly to the digital extortionists behind each attack. He bought the official unlock keys from the criminals, used those keys to restore the systems, and kept the dealings hidden from the businesses that hired him.

According to the indictment, MonsterCloud acted as an expensive middleman that pocketed huge markups. Across hundreds of cases between 2018 and 2023, Pinhasi allegedly paid more than eight million dollars to criminal syndicates while billing his customers more than nineteen million dollars.

The price differences in individual jobs were often staggering. In August 2023, Pinhasi paid an attacker about 8,200 dollars to release a customer's files, but then sent the victim an invoice for nearly 150,000 dollars. In another job, he bought a key for roughly 236,000 dollars and charged 380,000 dollars.

To convince wary clients that his software worked, MonsterCloud allegedly showed them sample files that had been successfully unlocked. Prosecutors say those files were actually tested and freed by the extortionists themselves, rather than by any internal recovery tool.

Investigators note that while some company contracts mentioned contacting hackers as a last resort, doing so was usually the firm's first and only plan. Internal messages also allegedly reveal Pinhasi admitting to a paid spokesperson in 2019 that his company possessed no unique decryption software at all.

Pinhasi, who also used the names Zack Silver and Zack Green, surrendered to authorities, pleaded not guilty, and posted a two million dollar bond. He faces multiple wire fraud counts that carry penalties of up to twenty years behind bars for each charge.

SecurityWeek , Help Net Security , BleepingComputer