Incident
Published 2026-10-07
Verified 2026-10-08

US charges MonsterCloud owner Zohar Pinhasi with wire fraud: prosecutors say the ransomware recovery firm secretly paid attackers for decryptors while telling victims it used its own decryption tools

The US Justice Department said on 7 October 2026 that Zohar Pinhasi, 50, owner of Florida ransomware remediation company MonsterCloud LLC, was arraigned in the Eastern District of New York on two counts of wire fraud and one count of wire fraud conspiracy (docket 26-CR-271; indictment filed 23 September). Prosecutors allege that from June 2018 to June 2023 MonsterCloud told ransomware victims not to pay and claimed to have proprietary tools and advanced decryption techniques, but in practice contacted the attackers, paid them for decryption keys and charged clients far more than the ransom. In one example cited by the Justice Department, about US$8,200 went to a ransomware operator and the client was billed about US$150,000. Over the scheme he allegedly charged clients more than US$19 million and paid more than US$8 million in ransoms, with BleepingComputer reporting hundreds of affected companies in the US and Canada. Pinhasi pleaded not guilty and was released on a US$2 million bond, according to the US Attorney's Office. Each count carries a maximum of 20 years. For Australian organisations the case is a reminder that a paid recovery or negotiation firm may still be paying the attacker on your behalf, which can bring the ransomware payment reporting obligation under the Cyber Security Act 2024 into play. Primary: US Department of Justice; wire: BleepingComputer.

Product
MonsterCloud LLC ransomware recovery and remediation services
Versions
n/a
Exploited in Australia?
unknown
Patch to
Nothing to patch. If you engage a ransomware recovery or negotiation firm, require it in writing to disclose whether any payment will be made to the attacker, who makes it and how much, and keep that record. A payment made for you by a third party can still trigger the 72-hour ransomware payment report to the ASD under Part 3 of the Cyber Security Act 2024 for entities that meet the threshold, so build that check into your incident response plan.

Primary: US Department of Justice — Known cybersecurity expert and owner of Florida ransomware remediation company charged with defrauding clients (7 Oct 2026) · Vendor: Cyberstack — Ransomware payment reporting (Cyber Security Act 2024, Part 3) · BleepingComputer — Ransomware recovery CEO charged over secret ransom payments (7 Oct 2026)

breaches