Zohar Pinhasi, 50, also known as “Zack Silver” and “Zack Green,” a U.S. and Israeli national, was arraigned today in the Eastern District of New York on wire fraud charges relating to Pinhasi’s false representations that he could decrypt ransomware without paying cybercriminals. Pinhasi claimed to prospective clients that his company, MonsterCloud, offered a principled alternative to paying off ransomware attackers.
“The defendant is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again and committed additional fraud, harming the victim again,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “This prosecution underscores the Department’s commitment to protecting ransomware victims, regardless of how these cyber ransoms occur.”
“As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” said U.S. Attorney Joseph Nocella, Jr. for the Eastern District of New York. “Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity.”
“As alleged, Zohar Pinhasi claimed to fix ransomware while never remediating the underlying threat. Instead, he turned the victim’s crisis into his own profit center,” said Assistant Director James C. Barnacle Jr. of the FBI. “This deception is unacceptable, and the FBI is committed to ensuring accountability for those who choose to victimize the very people who trusted them for help.”
According to the indictment, Pinhasi made misrepresentations to distressed business owners who came to his company, MonsterCloud, for help after being victimized by cybercriminals. MonsterCloud’s website cautioned clients not to pay the ransom and claimed that his team specialized in helping businesses recover their data without succumbing to ransom demands. Pinhasi represented that he had access to “proprietary tools” and “advanced decryption techniques.” He allegedly had no special technology to decrypt data but instead contacted and paid the cybercriminals who had victimized MonsterCloud’s client in exchange for a decryption key that MonsterCloud employees then used in an attempt to decrypt the client’s files. Pinhasi typically charged MonsterCloud’s clients a fee that was substantially higher than the ransom that MonsterCloud secretly paid. For instance, in or around August 2023, he made a ransom payment of approximately $8,200 to a cybercriminal and charged the client approximately $150,000. Over the course of the scheme, he allegedly charged clients more than $19 million and paid more than $8 million in ransom payments.
Pinhasi is charged with two counts of wire fraud and one count of wire fraud conspiracy. If convicted, he faces a maximum penalty of 20 years on each count.
In joint guidance , the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have advised that they do not recommend that ransomware victims pay ransom. Paying ransoms does not ensure that data is decrypted, that systems or data will no longer be compromised, or that data will not be leaked.
The FBI is investigating the case.
Senior Trial Attorneys Brian Mund and Vasantha Rao of the Justice Department’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorneys Alexander Mindlin and Lindsey Oken for the Eastern District of New York are prosecuting the case.
CCIPS investigates and prosecutes cybercrime and intellectual property (IP) crime in coordination with domestic and international law enforcement agencies, often with assistance from the private sector. Since 2020, CCIPS has secured the conviction of over 180 cyber and IP criminals, and court orders for the return of over $350 million in victim funds.
An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.