Cybersecurity CEO Indicted in Multi-Million-Dollar Ransomware Scam

A Florida cybersecurity executive has been indicted in New York for allegedly running a ransomware scam, secretly paying hackers while charging clients massive fees.

Ynet•Author: Daniel Edelson
Source •
Cybersecurity CEO Indicted in Multi-Million-Dollar Ransomware Scam
Photo: Ynet / צילום: יח"צ

A Florida-based cybersecurity executive has been indicted in Brooklyn federal court for allegedly running a multi-million-dollar scam where he promised to unlock computer systems without paying hackers, only to secretly pay the extortionists a fraction of the cost while charging clients inflated fees.

Zohar Pinhasi, 50, a dual Israeli and American citizen who operated the company MonsterCloud, appeared in a Brooklyn courtroom in handcuffs. Federal prosecutors charge that Pinhasi defrauded hundreds of companies across the United States and Canada, taking in more than $19 million while secretly funneling over $8 million to the original attackers.

The Illusion of Proprietary Technology

According to the federal indictment, MonsterCloud marketed itself as a premier defense against ransomware attacks, assuring clients that paying cybercriminals only encourages further crimes. The firm promised unique recovery methods and advanced decryption tools protected as trade secrets. However, prosecutors allege that no such proprietary technology existed.

Instead, Pinhasi and his employees routinely contacted the hackers, paid their ransom demands, and obtained the decryption keys, passing them off as their own technological breakthroughs. In one instance detailed by the prosecution, a client paid $150,000 to recover locked files after Pinhasi covertly paid the attackers just $8,200 for the key. In another case, Pinhasi collected roughly $380,000 while paying the hackers $236,000.

"MonsterCloud has no proprietary ransomware decryption technology," Pinhasi admitted in a 2019 internal exchange cited in the court documents when asked by a promoter if the firm possessed unique software.

Public Persona and Prior Scrutiny

Over the years, Pinhasi cultivated a public profile as an international cybersecurity expert, frequently appearing on American and Israeli media outlets. During the 2020 ransomware attack on the Israeli insurance firm Shirbit, he offered commentary in Israeli media criticizing the company's handling of negotiations.

Investigative reporting by ProPublica as early as 2019 had raised red flags regarding MonsterCloud's business model, detailing sting operations where security researchers caught the firm routing ransom demands through intermediaries while publicly denying they ever paid extortionists.

Pinhasi, who also used the aliases Zack Silver and Zack Green, now faces three felony counts of wire fraud and conspiracy, carrying a maximum sentence of 20 years per count. He pleaded not guilty and was released on a $2 million bond.

Related News