The U.S. Department of Justice (DoJ) has recently pursued charges against Zohar Pinhasi, a 50-year-old individual with dual citizenship in the United States and Israel. Pinhasi, also known by the aliases Zack Silver and Zack Green, stands accused of defrauding victims of ransomware by falsely asserting that he could recover their stolen data through proprietary tools, all while covertly paying the cybercriminals behind the attacks.
Pinhasi faces serious legal consequences, with charges including two counts of wire fraud and one count of conspiracy to commit wire fraud. Conviction on these charges could lead to a sentence of up to 20 years in prison for each count. U.S. Attorney Joseph Nocella Jr., representing the Eastern District of New York, emphasized the gravity of the situation, stating that Pinhasi’s actions not only victimized the clients he professed to help but allowed him to extract substantial profits from their misfortunes.
Operating a Florida-based company named MonsterCloud, Pinhasi allegedly misled numerous ransomware victims by discouraging them from paying ransoms. He claimed to possess “proprietary tools” and “advanced decryption techniques” that could restore their encrypted data without yielding to the demands of the attackers. However, investigations revealed that these claims were baseless. Instead of deploying any advanced technology, Pinhasi is accused of secretly negotiating with cybercriminals, paying them directly to obtain decryptors.
The company’s website touted its capabilities, claiming to utilize “advanced decryption techniques and cutting-edge technology” for data recovery. A section on the site posed the question, “Should I Pay The Ransom?” and advised clients against doing so, suggesting that such payments could embolden the criminals and offer no guarantee of recovery. In another section, the company addressed whether it pays ransoms on behalf of its clients. While asserting its stance against paying ransoms, MonsterCloud admitted to having experience in dealing with ransomware perpetrators and sometimes utilizing “other means” to resolve such incidents.
Contrary to its professed diligence and technical proficiency, MonsterCloud did not have any specialized tools for decrypting data. Instead, Pinhasi’s strategy involved paying the ransomers directly while significantly inflating his service fees to his clients. Reports indicate that Pinhasi often charged fees that were “substantially higher” than the actual ransoms paid to cybercriminals. For example, in August 2023, he reportedly paid about $8,200 to a hacker while billing his client approximately $150,000 for data recovery services. Moreover, in October 2021, he was accused of making a payment of around $236,000 to a criminal group and subsequently charging the impacted customer roughly $380,000.
In total, Pinhasi is alleged to have billed clients more than $19 million while secretly paying over $8 million in ransom payments. This disturbing pattern of behavior highlights serious concerns regarding ethical practices in the cybersecurity field, particularly in situations involving ransomware, where victims are often already experiencing a crisis. James C. Barnacle Jr., an Assistant Director at the FBI, criticized Pinhasi’s actions, stating, “As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim’s crisis into his own profit center. This deception is unacceptable.”
The fallout from this case raises essential questions about accountability in the cybersecurity industry and the vital need for transparency when dealing with ransom scenarios. With Pinhasi’s legal proceedings underway, it remains to be seen how this case might influence other cybersecurity firms and their operational practices. Victims of ransomware are often left vulnerable and in precarious situations; incidents like these serve to emphasize the necessity for legitimate, ethical solutions in combating cybercrime.
