Zohar Pinhasi, the 50-year-old owner of ransomware recovery company MonsterCloud, was arraigned in the Eastern District of New York on Wednesday, October 7, 2026, on two counts of wire fraud and one count of wire fraud conspiracy. Federal prosecutors allege that he told businesses hit by ransomware that his firm could decrypt their files without paying the attackers, then secretly paid those same attackers for decryption keys and billed clients a multiple of the ransom. Over the course of the alleged scheme, according to the US Department of Justice, clients were charged more than $19 million while more than $8 million went out in ransom payments. The charges are allegations, and Pinhasi is presumed innocent unless proven guilty.
In Short
A man who ran a company promising to rescue hacked businesses without paying the hackers has been charged with secretly paying them anyway and charging his clients far more than he paid. If the charges are true, the victims paid criminals without knowing it, which can create legal and financial problems for them on top of the original attack. Nothing has been proven yet, but the case puts a spotlight on what recovery firms actually do when they say they have special tools.
What the indictment alleges
The Office of Public Affairs at the Justice Department published the release on October 7, 2026, under press release number 26-1153. It identifies Pinhasi as a US and Israeli national who also used the names "Zack Silver" and "Zack Green." The headline of the release describes him as a "Known Cybersecurity Expert" and MonsterCloud as a "Florida Ransomware Remediation Company."
The core allegation concerns a sales promise. According to the Justice Department, MonsterCloud's website cautioned clients not to pay the ransom and claimed that its team specialized in helping businesses recover data without giving in to ransom demands. Pinhasi represented that he had access to "proprietary tools" and "advanced decryption techniques," according to the release.
Prosecutors say those tools did not exist. According to the Justice Department, Pinhasi "allegedly had no special technology to decrypt data but instead contacted and paid the cybercriminals who had victimized MonsterCloud's client in exchange for a decryption key that MonsterCloud employees then used in an attempt to decrypt the client's files."
The wording matters. The release says employees used the key "in an attempt" to decrypt files. It does not say every decryption succeeded, and it does not say how many clients recovered their data, how many did not, or whether any clients were told after the fact that a payment had been made.
The release states that Pinhasi "typically charged MonsterCloud's clients a fee that was substantially higher than the ransom that MonsterCloud secretly paid." One example is given. In or around August 2023, according to the Justice Department, he made a ransom payment of approximately $8,200 to a cybercriminal and charged the client approximately $150,000.
Three officials are quoted in the release. Assistant Attorney General A. Tysen Duva of the Criminal Division said: "The defendant is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again and committed additional fraud, harming the victim again." He added: "This prosecution underscores the Department's commitment to protecting ransomware victims, regardless of how these cyber ransoms occur."
US Attorney Joseph Nocella, Jr. for the Eastern District of New York said: "As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself." Assistant Director James C. Barnacle Jr. of the FBI said: "As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim's crisis into his own profit center."
Barnacle's statement adds an allegation that sits slightly apart from the payment scheme. "Never remediating the underlying threat" suggests that, beyond the undisclosed payments, the vulnerability that let the attackers in may have been left in place. The release does not elaborate on that point.
The arithmetic of the alleged markup
The two sets of numbers in the release tell different stories, and the gap between them is worth setting out.
In the single August 2023 example, a ransom of about $8,200 was billed at about $150,000. That is a multiple of roughly 18 times the payment, and a difference of about $141,800 on one engagement.
The aggregate figures are far less extreme. Clients were charged more than $19 million and more than $8 million went to ransom payments, according to the Justice Department. On those floor numbers, total billings were roughly 2.4 times total ransom outlays, and the difference was at least $11 million before any staff, operating or other costs. The release does not give MonsterCloud's other expenses, so that $11 million is a gross spread, not a profit figure.
Why would one case carry an 18-fold multiple while the overall ratio sits below three? The release does not say. Plausible explanations include large ransom demands in other cases that compressed the margin, fixed fees that did not scale with the ransom, or engagements in which MonsterCloud provided additional services. None of these is stated in the release, and the example appears to have been chosen to show the scheme at its sharpest.
What is clear from the numbers is the scale of money moving to criminal groups through a single intermediary. More than $8 million in ransom payments over the life of the alleged scheme is a substantial sum when set against the official complaint data. The FBI's Internet Crime Complaint Center recorded more than 3,600 ransomware complaints and losses above $32 million for 2025, figures PPC Land reported on July 5, 2026. The two figures are not directly comparable: the IC3 total covers one calendar year of self-reported complaints, while the MonsterCloud figure covers an unspecified multi-year period. But the comparison illustrates how much ransomware money can flow through private channels that never appear in complaint statistics, particularly when the victim does not know a ransom was paid at all.
Charges, penalties and the presumption of innocence
Pinhasi faces two counts of wire fraud and one count of wire fraud conspiracy. If convicted, according to the Justice Department, he faces a maximum penalty of 20 years on each count. A statutory maximum is a ceiling set by law, and any sentence after a conviction would be determined by a federal judge.
The conspiracy count implies at least one other participant in the alleged scheme. The release refers to "MonsterCloud employees" who used the decryption keys, but it does not name any co-conspirator, and it does not say whether anyone else has been charged.
The release closes with standard language: "An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law." The release does not report how Pinhasi pleaded at arraignment, whether he was detained or released on bail, or who represents him. No statement from Pinhasi or MonsterCloud appears in any of the three source documents.
The FBI is investigating the case. Senior Trial Attorneys Brian Mund and Vasantha Rao of the Computer Crime and Intellectual Property Section (CCIPS) and Assistant US Attorneys Alexander Mindlin and Lindsey Oken for the Eastern District of New York are prosecuting it, according to the release. The Justice Department states that since 2020, CCIPS has secured the conviction of over 180 cyber and IP criminals and court orders for the return of over $350 million in victim funds.
What the release does not say
Several gaps and inconsistencies in the documents are relevant to anyone reading the case closely.
Florida in the headline, New York in the body
The headline calls MonsterCloud a Florida company. The body of the release never mentions Florida, never gives a city or address for the business, and does not explain why the case sits in the Eastern District of New York, which covers Brooklyn, Queens, Staten Island and Long Island. Federal wire fraud venue can rest on where victims, transfers or communications were located, but the release does not say which applies here.
$19M or more than $19 million
The subheadline of the release reads "Paid Cybercriminals More Than $8M in Ransom Payments While Charging Clients $19M." The body states that he "allegedly charged clients more than $19 million and paid more than $8 million in ransom payments." The headline drops "more than" from the billing figure but keeps it for the ransom figure. The body is the more precise statement, and this article uses it.
No dates for the scheme or the indictment
The release says the misrepresentations were made "over the course of the scheme" but does not say when the scheme began or ended. Its only dated event before the arraignment is the August 2023 payment. It also does not give the date the indictment was returned, or the number of clients involved.
"Known" expert, unexplained
The headline describes Pinhasi as a "Known Cybersecurity Expert." The body offers no basis for that description, such as media appearances, certifications or prior public work.
The LinkedIn summary versus the release
The LinkedIn post discussed below summarizes the release accurately on the numbers. In one sentence it states that "According to the indictment, there were no proprietary tools," which is slightly firmer than the release, where the claim is framed as Pinhasi "allegedly" having no special technology. The very next sentence of the post returns to "Prosecutors allege," and the post ends with "He has been charged, not convicted." The sanctions point in the post comes from its author, not from the Justice Department, which does not mention the Office of Foreign Assets Control or sanctions anywhere in the release.
A business that had been questioned before
The indictment is not the first time MonsterCloud's methods drew scrutiny. In May 2019, ProPublica published an investigation by Renee Dudley and Jeff Kao into data recovery firms that promised technical solutions to ransomware. According to ProPublica, MonsterCloud, which it described as Florida-based, often paid ransoms instead of using its own recovery methods, sometimes without telling victims, and charged substantial fees on top. ProPublica reported that the firm's workers used aliases in communications with victims.
Pinhasi, then described as chief executive, told ProPublica at the time that MonsterCloud did not mislead clients, that it never promised data would be recovered by any particular method, and that its recovery methods were a trade secret that varied from case to case, according to that report. Those were his statements in 2019; the 2026 indictment is the first time prosecutors have made allegations against him, and the Justice Department release does not refer to the earlier reporting. The aliases ProPublica described in 2019 sit alongside the two names, "Zack Silver" and "Zack Green," that the Justice Department lists for Pinhasi.
The compliance reading on LinkedIn
The case reached a wider audience through a LinkedIn post by Brandi Reynolds, whose profile lists her as Chief Compliance and Risk Officer at World Liberty Financial since May 2025, an advisor at Bates Group, and an instructor and content advisor at ACAMS since October 2020. Her profile shows 12,036 followers and a headline that includes "(Opinions are my own- not financial advice)." The post was reposted by Dr. Augustine Fou, the ad fraud researcher behind FouAnalytics. In the captured version, it had 39 reactions, 4 comments and 6 reposts, and carried a "23h" timestamp; the exact publication date is not shown on the page.
Reynolds opened with "News You Can't Make Up." and wrote: "This one came out of a DOJ press release on Wednesday and I had to read it twice." She summarized the pitch: "A company called MonsterCloud built its entire business on telling ransomware victims not to pay the ransom." She added: "If you're a business owner in the middle of an attack, that is exactly what you want to hear."
Her compliance point was about knowledge, not price. "From a compliance standpoint, the piece that stood out to me is that those clients had no idea a payment was being made at all," she wrote. "If you don't know a payment happened, you can't screen who received it, and OFAC has been clear for years that facilitating a ransom payment to a sanctioned actor carries real sanctions risk."
That observation describes a second-order exposure that the Justice Department release does not address. A victim that knowingly pays a ransom can, at least in principle, check the recipient against sanctions lists. A victim that believes it has paid for decryption software has no reason to do so. If, as alleged, the payment was routed through the recovery firm, the client's records would show a payment to a vendor for a service, not a payment to an extortion group.
One of the four comments, from F Badre, who lists himself as founder of MarketClair, a decision infrastructure business for regulated financial institutions, extended the point to banks. "The bank side of this is worth a look," he wrote. "The victims' banks saw an ordinary supplier invoice for 'data recovery'. The ransom itself left from the recovery firm's own accounts, so the firm's bank saw a recognisable shape for years: money in from companies right after an incident, then an outgoing transfer, typically to buy crypto, worth a fraction of" - the captured comment is truncated at that point. The suggestion that ransoms were paid in cryptocurrency, and that the pattern ran "for years," comes from the commenter. Neither appears in the Justice Department release, which does not name the payment method or the duration of the scheme.
Another commenter, Val Harkless, compared the case with "crypto reloading scams," in which victims of one fraud are targeted again by people offering to recover their losses. Ian B., who lists trust and safety and fraud prevention work, wrote that it "Seems like the second half of the grey market."
What federal guidance says about paying
The release includes a paragraph that frames the case against official policy. In joint guidance, according to the Justice Department, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) "do not recommend that ransomware victims pay ransom." The release adds that paying ransoms "does not ensure that data is decrypted, that systems or data will no longer be compromised, or that data will not be leaked."
The allegation in this case turns that guidance into a selling point. MonsterCloud's public message, as described by prosecutors, matched the government position: do not pay. The indictment alleges the firm then paid on the client's behalf, without the client's knowledge, and kept the difference. Whether or not the charges are proven, the case shows how a victim who follows official advice can still end up as an unwitting payer if the intermediary does not disclose what it does.
Why this matters for marketers, agencies and publishers
Ransomware is not usually a marketing story, but the businesses that read PPC Land are among those exposed to it. Agencies hold client credentials, ad account access, customer lists and campaign data. Publishers run content management systems and ad servers that sit on the public internet. Research from hosting provider 20i, covered on September 25, 2026, found 87.62% of more than 44 million WordPress sites running versions below WordPress 7.1, and cited Verizon's 2026 Data Breach Investigations Report placing vulnerability exploitation as the leading initial access vector, at 31% of breaches.
The FBI's crime data puts the threat in context. Its 2025 report, covered by PPC Land in July, logged 1,008,597 complaints and $20.877 billion in total losses, with cryptocurrency the costliest category at $11.366 billion. The report identified 63 new ransomware variants, and the top 10, including Akira, Qilin and Lockbit, accounted for 56.8% of ransomware incidents.
There is also a structural parallel with problems the advertising industry knows well. The MonsterCloud allegations concern a vendor selling a technical capability that the buyer could not inspect, at a moment when the buyer had little choice and no time to check. Ad tech has its own version of that dynamic. Verification and fraud detection vendors sell proprietary methods that advertisers generally cannot audit, and practitioners have long argued over whether reported rates of invalid traffic reflect what is actually happening. Fou, who reposted the Reynolds post, has argued that fraud runs well above the 1% figure legacy vendors report, saying their tools catch only what they were built to catch, as PPC Land noted when FouAnalytics priced unlimited ad verification at $2 million a year in August 2026. The comparison is about the information gap between seller and buyer, not an allegation against any verification firm.
Self-declared claims that cannot be checked independently have been a recurring theme in industry debate. When the Ad Context Protocol arrived in October 2025, critics quoted in a PPC Land analysis of programmatic reform warned that it relied on self-declared information that fraudsters could exploit, as they had done with ads.txt. The same article cited 2023 research finding only 36% of post-transaction programmatic budgets reached valid, viewable, measurable impressions.
Federal prosecutors in New York have pursued fraud cases inside the marketing sector before. Kubient founder Paul Roberts pleaded guilty to securities fraud in September 2024 in a case brought by the US Attorney's Office for the Southern District of New York, over more than $1.3 million in fraudulent revenue that inflated the company's reported sales. The FBI has also worked directly on ad fraud: in June 2025 it issued a public service announcement on BADBOX 2.0, a botnet of more than 10 million infected Android devices whose ad fraud component peaked at 5 billion fake ad requests a week.
Schemes that target people and businesses at moments of pressure also depend on advertising reach. Meta removed more than 134 million scam ads in 2025, according to figures the company shared in December 2025, and click fraud and impersonation schemes routinely exploit the same urgency. The Justice Department release does not say how MonsterCloud found its clients beyond its website, so any link between the alleged scheme and paid acquisition remains unestablished.
Finally, the compliance angle Reynolds raised has a direct bearing on the companies that pay for recovery services, agencies included. A vendor invoice for "data recovery" tells the finance team nothing about where the money ultimately went. If the allegations are proven, the MonsterCloud clients were not just overcharged; some may have made indirect payments to criminal groups that they never screened and never recorded as ransom.
What happens next
The Justice Department release marks the arraignment, not the end of the case. The prosecution must prove each element of the charges beyond a reasonable doubt. Pinhasi has not been convicted of anything, and no response from him or from MonsterCloud is included in the documents reviewed for this article. Key facts that are likely to surface in court filings, but are absent from the release, include the time period of the alleged scheme, the number of affected clients, the ransomware groups involved, the payment channels used, and whether any clients knew of the payments.
Timeline
- 2016: Researcher Fabian Wosar runs an experiment in which recovery firms, including MonsterCloud, claimed they could decrypt ransomware families that could not be decrypted, according to ProPublica.
- May 15, 2019: ProPublica reports that MonsterCloud often paid ransoms rather than using its own methods, sometimes without telling victims; Pinhasi tells ProPublica the firm does not mislead clients.
- August 2023: Pinhasi allegedly pays a ransom of about $8,200 and charges the client about $150,000, according to the Justice Department.
- September 16, 2024: Former Kubient CEO Paul Roberts pleads guilty to securities fraud in an SDNY case.
- May 2025: Brandi Reynolds becomes Chief Compliance and Risk Officer at World Liberty Financial, according to her LinkedIn profile.
- June 5, 2025: The FBI issues a public service announcement on BADBOX 2.0 infected devices.
- December 3, 2025: Meta says it removed more than 134 million scam ads in 2025.
- July 5, 2026: PPC Land reports the FBI's 2025 IC3 figures, including more than 3,600 ransomware complaints.
- August 6, 2026: FouAnalytics prices unlimited verification at $2 million a year.
- September 25, 2026: 20i finds 88% of WordPress sites running outdated software.
- October 7, 2026: Zohar Pinhasi is arraigned in the Eastern District of New York on two counts of wire fraud and one count of wire fraud conspiracy; the Justice Department publishes press release 26-1153.
- October 2026: Brandi Reynolds posts about the case on LinkedIn; Dr. Augustine Fou reposts it.
Related PPC Land coverage
- AI-linked fraud costs Americans $893 million, FBI reports for 2025 - The FBI's 2025 IC3 report, including ransomware complaint and loss figures.
- Former Kubient CEO pleads guilty to accounting fraud scheme - A federal fraud prosecution in New York involving an ad tech company.
- FouAnalytics prices unlimited ad verification at $2 million a year - Augustine Fou's verification business and his views on reported fraud rates.
- Why greed, not technology, blocks programmatic advertising reform - Industry voices, including Fou, on why self-declared signals fail to stop fraud.
- Criminals steal billions from TV advertising through infected streaming devices - The FBI warning on BADBOX 2.0 and its ad fraud operation.
- 20i finds 88% of WordPress sites running outdated software as attacks rise - How widespread outdated software leaves publishers exposed to attacks.
- Meta removes 134 million scam ads in 2025 amid expanding fraud crisis - Meta's anti-scam figures and the scale of scam advertising.
Summary
Who: Zohar Pinhasi, 50, owner of ransomware recovery company MonsterCloud, also known as "Zack Silver" and "Zack Green"; the US Department of Justice, the US Attorney's Office for the Eastern District of New York and the FBI; compliance executive Brandi Reynolds, whose LinkedIn post on the case was reposted by ad fraud researcher Dr. Augustine Fou.
What: Pinhasi was arraigned on two counts of wire fraud and one count of wire fraud conspiracy. Prosecutors allege he told ransomware victims MonsterCloud could decrypt their data without paying attackers, then secretly paid the attackers for keys, charging clients more than $19 million while paying more than $8 million in ransoms. Each count carries a maximum of 20 years. The charges are allegations, and he is presumed innocent.
When: The arraignment and Justice Department release took place on October 7, 2026. The one dated example of the alleged scheme is from August 2023; the release gives no start or end date.
Where: The case is in the Eastern District of New York. The Justice Department describes MonsterCloud as a Florida company but does not give a location in the body of the release.
Why: The case matters because the alleged scheme turned official advice against paying ransoms into a sales pitch, left victims unaware that payments to criminals were made in their name, and, as Reynolds noted, may have exposed them to sanctions risk they could not screen. For agencies and publishers, which hold client data and run internet-facing systems, it also highlights how little buyers can verify about vendors that sell proprietary technical claims under pressure.
Discussion