Skip to content
TECH CEO Daily

MonsterCloud CEO charged with secretly paying ransoms while billing victims $19 million

Federal prosecutors allege Zohar Pinhasi told clients MonsterCloud could decrypt data without paying hackers, then quietly paid the ransoms and marked up the bill.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Zohar Pinhasi, owner of Florida-based MonsterCloud, was charged with wire fraud and wire fraud conspiracy on October 8, 2026.
  • 2Prosecutors allege clients paid $19 million while about $8 million went to ransomware gangs as ransoms.
  • 3Victims included local governments and police departments; the charges carry up to 20 years in prison.

The news

Federal prosecutors on October 8, 2026, charged Zohar Pinhasi, the owner of Florida-based ransomware recovery firm MonsterCloud, with wire fraud and wire fraud conspiracy. They allege the MonsterCloud ransomware recovery business secretly paid hackers while billing victims $19 million, as reported by The Record.

According to the charges described by The Record, Pinhasi told clients MonsterCloud had proprietary tools and advanced decryption techniques that could restore encrypted files without paying a ransom. Prosecutors say the company instead paid the ransomware gangs what they demanded and then charged clients far more for the decryption keys.

Prosecutors put the gap in numbers. Clients paid MonsterCloud a total of $19 million, while roughly $8 million went to cybercriminals as ransom payments, according to The Record. In one 2023 case cited in the charges, the firm allegedly paid an $8,200 ransom and charged the victim $150,000.

Victims included local governments and police departments, The Record reported. Pinhasi, a 50-year-old U.S. and Israeli national, faces up to 20 years in prison if convicted. The charges are allegations, and he has not been convicted of any crime.

U.S. Attorney Joseph Nocella Jr. said Pinhasi "re-victimized his clients while extracting a hefty profit for himself," according to The Record.

The allegations are not entirely new territory. In May 2019, a ProPublica investigation reported that MonsterCloud advertised that clients should not pay the ransom while in practice paying hackers, and that several police departments had praised the firm believing it had recovered data without payment.

The numbers

Total billed to clients (alleged)
$19 million
Ransoms paid to hackers (alleged)
About $8 million
Example 2023 case
$8,200 ransom, $150,000 invoice
Maximum prison term
20 years

Why CEOs should care

For CFOs and general counsel, the case is a reminder that a ransomware recovery invoice can hide a ransom payment. Paying a ransom carries its own legal, insurance and sanctions questions, and a vendor that pays on your behalf without telling you leaves you exposed to all of them while you believe you avoided them. Contracts with recovery firms should require written disclosure of whether any payment is made to an attacker, to whom and for how much.

CISOs should ask any incident response or recovery vendor to explain its method in plain terms before an incident, not during one. If a vendor claims it can decrypt files without the attackers' key, ask which ransomware strains that applies to, and whether independent researchers have published a decryptor for them. A claim of secret proprietary decryption for a strain with no known weakness is a red flag.

Boards and public-sector leaders, including the city and police officials named as victim types here, should make sure ransomware playbooks name pre-vetted vendors, require itemized billing and route any ransom decision through legal counsel and the insurer. Price alone is a signal too: in the case prosecutors cited, the bill was more than 18 times the ransom, by our calculation.

The bigger picture

Ransomware has built a service industry around it: negotiators, recovery specialists and incident responders. Most operate legitimately, and some openly negotiate and pay ransoms at a client's request. The problem prosecutors describe is not paying but lying about it, which strips victims of the ability to make an informed decision and to report payments accurately to insurers and authorities.

ProPublica's 2019 reporting suggested the practice of quietly paying hackers was not limited to one firm, so buyers should treat transparency as a selection criterion for the whole category.

What’s next

The case will now move through federal court, where Pinhasi can contest the charges. Organizations that hired MonsterCloud may want to review their invoices and records of any ransom payment made on their behalf, and check with counsel about reporting obligations.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

MonsterCloudZohar PinhasiRansomwareDepartment of Justice

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.