Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
BROOKLYN, N.Y. — The owner of a Florida ransomware remediation company has been arraigned on federal wire fraud charges after prosecutors accused him of falsely claiming his company could decrypt ransomware through proprietary technology while secretly paying the cybercriminals responsible for the attacks and charging victims substantially more than the underlying ransom demands.
Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” of Hollywood, Florida, was arraigned in federal court in Brooklyn before U.S. Magistrate Judge Peggy Cross-Goldenberg. Pinhasi, a citizen of both the United States and Israel, was indicted by a federal grand jury in the Eastern District of New York on September 23, 2026.
Pinhasi owned and operated MonsterCloud LLC, a Florida-based business marketed as a ransomware remediation company. According to the indictment, he also served as the company’s chief executive officer, managed employees, established prices charged to customers and communicated directly with cybercriminals on MonsterCloud’s behalf.
Federal prosecutors allege that from approximately June 2018 through June 2023, Pinhasi presented MonsterCloud as an alternative for businesses that did not want to pay ransomware operators. The company advertised what it described as proprietary tools, advanced decryption techniques and specialized technology capable of restoring encrypted data without surrendering to ransom demands.
The government alleges that those representations were false.
According to the indictment, Pinhasi and his associates did not possess specialized proprietary technology capable of independently decrypting the affected data. Instead, prosecutors say Pinhasi contacted the same cybercriminals who had attacked MonsterCloud’s customers, paid them for decryption keys and then used those keys in attempts to restore the victims’ files.
The alleged scheme placed ransomware victims in an unusual position. Businesses that had already suffered a cyberattack turned to MonsterCloud believing they were hiring a company capable of recovering their systems without financially rewarding the attackers. Prosecutors allege that MonsterCloud secretly paid those attackers anyway and then concealed those payments from its customers.
MonsterCloud allegedly structured its remediation process in two stages. Prospective clients first entered an analysis phase in which the company offered what Pinhasi described as “recovery proofs.” According to the indictment, that initial stage generally cost between approximately $2,500 and $10,000. After receiving ransomware notes and encrypted sample files from clients, MonsterCloud allegedly obtained decrypted samples from the cybercriminals themselves and presented those files to customers as evidence of the company’s recovery capabilities.
Those demonstrations allegedly encouraged victims to purchase a second, substantially more expensive full-recovery service.
Federal prosecutors say MonsterCloud’s fees routinely exceeded the actual ransom paid to attackers and in some cases were several times higher.
One example cited by the government involved an August 2023 ransomware incident in which Pinhasi allegedly paid approximately $8,200 to a cybercriminal for a decryption key and then charged the affected client approximately $150,000.
The indictment contains another example from approximately October 2021. Prosecutors allege Pinhasi paid a ransom of roughly $236,000 and charged the customer approximately $380,000, creating a markup approaching $150,000. The government says clients were typically not told that MonsterCloud had paid the ransomware operators or informed of the difference between the ransom and MonsterCloud’s own fee.
Some MonsterCloud contracts acknowledged that communication with or payment to cybercriminals could occur under limited circumstances, but prosecutors allege the company represented that such contact would occur only after other means of direct decryption had been exhausted. The indictment states that dealing with the attackers was instead generally one of Pinhasi’s first steps and the standard method used to obtain decryption keys.
Federal prosecutors also allege Pinhasi took deliberate steps to conceal how the company was obtaining those keys. According to the indictment, he directed MonsterCloud employees and contractors to use the term “recovery tool” rather than “decryptor” when discussing the technology with customers.
The government also points to MonsterCloud’s promotional material and customer testimonials. At least one testimonial allegedly came from a compensated spokesperson.
In May 2019, according to prosecutors, that spokesperson directly questioned Pinhasi about whether MonsterCloud actually possessed proprietary software capable of decrypting ransomware-encrypted data. Pinhasi allegedly responded that MonsterCloud did not possess proprietary technology for decrypting ransomware data.
The indictment alleges the scheme continued for approximately five years and involved dozens of ransom payments made to cybercriminals.
Prosecutors say Pinhasi paid more than $8 million in ransom payments while MonsterCloud and Pinhasi collected more than $19 million from hundreds of companies in the United States and Canada for ransomware recovery and remediation services.
Many of those businesses were facing severe operational disruption or substantial financial losses caused by ransomware attacks when they contacted MonsterCloud. Prosecutors allege that at least some customers specifically hired the company because they did not want their money paid to cybercriminals.
The indictment identifies two alleged victims located in the Eastern District of New York. One was a company in the home décor industry and another operated in the display manufacturing industry. Both companies are identified by number rather than corporate name in the charging document.
The federal indictment charges Pinhasi with one count of conspiracy to commit wire fraud and two substantive counts of wire fraud. One of the alleged wire transactions involved an approximately $175,000 transfer from an Eastern District of New York victim to Pinhasi’s Florida bank account in April 2021. Another count concerns an August 2021 telephone communication between another New York victim and Pinhasi in Florida.
Federal prosecutors are also seeking forfeiture of property and proceeds allegedly derived from the charged offenses. If directly traceable assets cannot be located, have been transferred, placed outside the court’s jurisdiction, diminished in value or mixed with other property, the indictment states that the government may seek substitute assets up to the value of the forfeitable property.
U.S. Attorney Joseph Nocella Jr. for the Eastern District of New York said the alleged conduct effectively victimized businesses a second time by exploiting their attempts to recover from ransomware attacks. He said federal prosecutors would pursue both ransomware operators and individuals accused of profiting deceptively from victims seeking help.
Assistant Attorney General A. Tysen Duva, head of the Justice Department’s Criminal Division, said the prosecution reflects the department’s effort to protect ransomware victims from additional fraud after an initial cyberattack.
FBI New York Assistant Director in Charge James C. Barnacle Jr. said the government alleges Pinhasi turned ransomware victims’ emergencies into a source of profit while misrepresenting the way his company restored encrypted systems.
The allegations are significant within the ransomware-response industry because victims frequently face urgent operational decisions after an attack. Companies can lose access to essential files, networks and business systems while ransom demands continue to create financial and legal pressure. A remediation provider hired during that period can occupy a position of considerable trust because the victim may depend on the provider to assess recovery options, communicate accurately and disclose whether money will ultimately reach the attackers.
The prosecution also highlights the difference between legitimate ransomware negotiation and an alleged fraudulent representation about how recovery is being performed. The government is not alleging that every interaction with a ransomware operator constitutes fraud. The central accusation is that Pinhasi allegedly told customers MonsterCloud possessed capabilities it did not have, concealed payments to the attackers and charged clients substantial premiums based on those alleged misrepresentations.
The Justice Department’s Office of International Affairs assisted in the case.
Assistant U.S. Attorneys Alexander Mindlin and Lindsey Oken of the Eastern District of New York’s National Security and Cybercrime Section are prosecuting the matter alongside Senior Trial Attorneys Brian Mund and Vasantha Rao of the Justice Department’s Computer Crime and Intellectual Property Section. Assistant U.S. Attorney Laura Mantell is handling forfeiture matters.
If convicted, Pinhasi faces a maximum sentence of 20 years in federal prison.
The indictment contains allegations only. Pinhasi is presumed innocent unless and until the government proves the charges beyond a reasonable doubt in federal court.
U.S. District Court for the Eastern District of New York — United States v. Zohar Pinhasi, Indictment, Case No. 26-CR-271, filed September 23, 2026. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



