The news
Federal prosecutors on October 8, 2026, charged Zohar Pinhasi, the owner of Florida-based ransomware recovery firm MonsterCloud, with wire fraud and wire fraud conspiracy. They allege the MonsterCloud ransomware recovery business secretly paid hackers while billing victims $19 million, as reported by The Record.
According to the charges described by The Record, Pinhasi told clients MonsterCloud had proprietary tools and advanced decryption techniques that could restore encrypted files without paying a ransom. Prosecutors say the company instead paid the ransomware gangs what they demanded and then charged clients far more for the decryption keys.
Prosecutors put the gap in numbers. Clients paid MonsterCloud a total of $19 million, while roughly $8 million went to cybercriminals as ransom payments, according to The Record. In one 2023 case cited in the charges, the firm allegedly paid an $8,200 ransom and charged the victim $150,000.
Victims included local governments and police departments, The Record reported. Pinhasi, a 50-year-old U.S. and Israeli national, faces up to 20 years in prison if convicted. The charges are allegations, and he has not been convicted of any crime.
U.S. Attorney Joseph Nocella Jr. said Pinhasi "re-victimized his clients while extracting a hefty profit for himself," according to The Record.
The allegations are not entirely new territory. In May 2019, a ProPublica investigation reported that MonsterCloud advertised that clients should not pay the ransom while in practice paying hackers, and that several police departments had praised the firm believing it had recovered data without payment.
The numbers
- Total billed to clients (alleged)
- $19 million
- Ransoms paid to hackers (alleged)
- About $8 million
- Example 2023 case
- $8,200 ransom, $150,000 invoice
- Maximum prison term
- 20 years
Why CEOs should care
For CFOs and general counsel, the case is a reminder that a ransomware recovery invoice can hide a ransom payment. Paying a ransom carries its own legal, insurance and sanctions questions, and a vendor that pays on your behalf without telling you leaves you exposed to all of them while you believe you avoided them. Contracts with recovery firms should require written disclosure of whether any payment is made to an attacker, to whom and for how much.
CISOs should ask any incident response or recovery vendor to explain its method in plain terms before an incident, not during one. If a vendor claims it can decrypt files without the attackers' key, ask which ransomware strains that applies to, and whether independent researchers have published a decryptor for them. A claim of secret proprietary decryption for a strain with no known weakness is a red flag.
Boards and public-sector leaders, including the city and police officials named as victim types here, should make sure ransomware playbooks name pre-vetted vendors, require itemized billing and route any ransom decision through legal counsel and the insurer. Price alone is a signal too: in the case prosecutors cited, the bill was more than 18 times the ransom, by our calculation.
The bigger picture
Ransomware has built a service industry around it: negotiators, recovery specialists and incident responders. Most operate legitimately, and some openly negotiate and pay ransoms at a client's request. The problem prosecutors describe is not paying but lying about it, which strips victims of the ability to make an informed decision and to report payments accurately to insurers and authorities.
ProPublica's 2019 reporting suggested the practice of quietly paying hackers was not limited to one firm, so buyers should treat transparency as a selection criterion for the whole category.
What’s next
The case will now move through federal court, where Pinhasi can contest the charges. Organizations that hired MonsterCloud may want to review their invoices and records of any ransom payment made on their behalf, and check with counsel about reporting obligations.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







