Cybersecurity CEO accused of pocketing millions by secretly paying hackers
The secret behind MonsterCloud’s success? Paying hackers.

Mystery man in silhouette red with binary code background. Kmatta/Getty.
- Prosecutors charged MonsterCloud owner Zohar Pinhasi with defrauding ransomware victims.
- The indictment says MonsterCloud secretly paid attackers while claiming it used proprietary recovery software.
- Pinhasi allegedly charged clients over $19 million and paid more than $8 million in ransoms.
- If convicted, Pinhasi faces a maximum sentence of up to 20 years in prison.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The owner of MonsterCloud, a ransomware mediation company, has been charged with defrauding his clients by secretly paying attackers for decryptors while claiming he used proprietary software to recover encrypted data.
According to the indictment, Zohar Pinhasi, founder and CEO of MonsterCloud, also known as “Zack Silver” and “Zack Green,” discouraged clients from making ransom payments and promised them that his company could safely recover encrypted files without paying hackers.
To do this, he would use “specialized, proprietary technology” to recover data that had been encrypted by ransomware. This promotion brought him many new customers who didn't want to pay hackers to decrypt their data.
However, MonsterCloud never owned proprietary software to decrypt encrypted data. Instead, Pinhasi contacted and paid hackers who had encrypted MonsterCloud’s clients’ data in exchange for a decryption key that employees used to decrypt clients’ files.
According to the US Department of Justice, Pinhasi typically charged MonsterCloud’s clients a fee that was substantially higher than the ransom that MonsterCloud secretly paid.
For example, in August 2023, Pinhasi made a ransom payment of approximately $8,200 to a hacker and charged the client approximately $150,000.
Between June 1st, 2018, and June 30th, 2023, Pinhasi had charged clients more than $19 million and paid more than $8 million in ransom payments.
Pinhasi is being accused of running a fraudulent ransomware-remediation business and devising a fraud scheme to scam ransomware victims.
“By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself. Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity,” US Attorney for the Eastern District of New York Joseph Nocella says in a press release.
If found guilty, Pinhasi faces a maximum sentence of up to 20 years in prison.