Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data


MonsterCloud owner accused of billing over $19M while secretly paying ransoms to decrypt data. A 50-year-old U.S. and Israeli national, Zohar Pinhasi, faces up to 20 years in prison if convicted of two counts of wire fraud and one count of wire fraud conspiracy.

  • Zohar Pinhasi, owner of MonsterCloud, has been charged with wire fraud and wire fraud conspiracy for a complex scheme involving ransomware victims.
  • Pinhasi paid ransomware attackers to obtain decryptors while claiming to use proprietary tools to recover data.
  • He made false representations to clients, urging them not to pay a ransom and claiming he could recover data without paying.
  • Pinhasi charged clients substantially more than the ransom paid to attackers, resulting in over $19 million in false charges.
  • Potential prison sentence of up to 20 years if convicted.



  • The U.S. Department of Justice (DoJ) has announced a series of charges against Zohar Pinhasi, a 50-year-old U.S. and Israeli national, in relation to a complex scheme involving the defrauding of ransomware victims by secretly paying attackers to obtain decryptors while claiming to use proprietary tools to recover their data. This case has significant implications for the cybersecurity landscape, highlighting the importance of vigilance and transparency in the face of sophisticated threats.

    Pinhasi, the owner and operator of MonsterCloud, a Florida-based company, has been accused of engaging in a dual-pronged scheme. On the one hand, he purportedly offered his clients "proprietary tools" and "advanced decryption techniques" to recover encrypted data without paying a ransom. On the other hand, behind the scenes, he allegedly paid substantial sums of money to cybercriminals to obtain decryptors, thus allowing him to recover the data.

    The full extent of Pinhasi's scheme was revealed through an investigation conducted by the U.S. Attorney's Office for the Eastern District of New York. The DoJ alleges that Pinhasi made false representations to his clients, urging them not to pay a ransom and claiming that his proprietary tools and advanced decryption techniques could recover their encrypted data without yielding to ransom demands.

    However, contrary to his claims, Pinhasi did not possess any specialized tools to decrypt the data. Instead, he approached the cybercriminals and paid them in exchange for obtaining a decryptor to recover the information. This payment arrangement was made without disclosing the true nature of his actions to his clients.

    The financial implications of Pinhasi's actions are staggering. He allegedly charged his clients a fee that was substantially higher than the ransom that was secretly paid to the criminals. In one case, Pinhasi made a ransom payment of approximately $8,200 to a threat actor and billed the client approximately $150,000. In another incident in or around October 2021, Pinhasi made a ransom payment of approximately $236,000 and charged the customer about $380,000. In all, Pinhasi is accused of charging clients more than $19 million and paying more than $8 million in ransom payments.

    The U.S. Attorney, Joseph Nocella, Jr., stated that "By falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself." The FBI also weighed in, noting that Pinhasi's deception was "unacceptable" and that he had turned the victim's crisis into his own profit center.

    Pinhasi, who is currently facing charges of two counts of wire fraud and one count of wire fraud conspiracy, could potentially face up to 20 years in prison for each count if convicted.

    This case highlights the need for vigilance and transparency in the face of sophisticated threats. It also underscores the importance of reporting suspicious activities and the need for law enforcement agencies to be proactive in investigating and prosecuting such cases.

    In conclusion, the case of Zohar Pinhasi serves as a stark reminder of the dangers of deception and the importance of transparency in the cybersecurity landscape. It also underscores the need for vigilance and cooperation between law enforcement agencies and the public in the face of complex threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/MonsterCloud-Owner-Accused-of-Billing-Over-19M-While-Secretly-Paying-Ransoms-to-Decrypt-Data-ehn.shtml

  • https://thehackernews.com/2026/10/monstercloud-owner-accused-of-billing.html


  • Published: Thu Oct 8 04:52:24 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us