Cybercrime

Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme

Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation.

Ransomware

The owner of a US company was charged with defrauding clients through a ransomware remediation scheme.

Zohar Pinhasi, 50, the owner of MonsterCloud, a US and Israeli national also known as ‘Zack Silver’ and ‘Zack Green’, appeared in a New York court to face wire fraud charges.

According to the indictment, Pinhasi claimed that MonsterCloud could help organizations that fell victim to ransomware to recover their data without paying the attackers.

While cautioning ransomware victims not to pay the attackers, Pinhasi allegedly falsely claimed his company could decrypt ransomware.

Pinhasi allegedly claimed that MonsterCloud was using proprietary tools and advanced decryption techniques to recover encrypted data without paying the attackers.

Instead, he contacted the ransomware groups that hacked his clients, paid ransoms to obtain the decryption keys, and then charged the victim organizations a fee when using the decryption key to restore the data.

Advertisement. Scroll to continue reading.

In one instance, he made a ransom payment of approximately $8,200 to a ransomware affiliate, and then charged the client approximately $150,000.

Throughout the scheme, he allegedly paid over $8 million in ransoms and charged his clients over $19 million.

Pinhasi was charged with wire fraud and wire fraud conspiracy and could be sentenced to tens of years in prison.

“The defendant is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again and committed additional fraud, harming the victim again,” Assistant Attorney General A. Tysen Duva said.

Related: Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany

Related: FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

Related: Alleged ShinyHunters Leader Arrested in Jordan

Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

Related Content

Cybercrime

The individual was detained in May and has been extradited to Germany to face hacking charges.

Data Breaches

Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.

Malware & Threats

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

Cybercrime

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims.

Cybercrime

Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.

Cybercrime

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Data Breaches

FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version