مالك الوحوش (زوهار بينشاسي) متهم بضحايا فواتير من أجل مدّعين عامين مشفرة
A company hired to beat ransomware is supposed to fight the encryption, not pay the crew that planted it. Federal prosecutors say MonsterCloud advertised the first service and delivered the second. On October 7, 2026, owner Zohar Pinhasi, 50, a dual U.S. and Israeli national from Hollywood, Florida, pleaded not guilty in Brooklyn and left on a $2 million bond. A grand jury in the Eastern District of New York returned the indictment on September 23 in United States v. Zohar Pinhasi, No. 26-CR-271. The charges are two wire fraud counts and one conspiracy count, each punishable by up to 20 years. An indictment is an allegation. He is presumed innocent.
The الإدارة says he told owners already locked out of their files that MonsterCloud could recover the data with proprietary tools and advanced decryption techniques, and that paying attackers was the wrong move. Prosecutors say that tool was not what restored the files. They say he used client money to pay the same cybercriminals, took a decryption key, and billed a fee well above the ransom. He allegedly charged more than $19 million and paid more than $8 million to attackers. Assistant Attorney General A. Tysen Duva said the defendant “is charged with offering an alternative to ransom payments, but instead is alleged to have victimized the victim again.”
What prosecutors say MonsterCloud sold instead of a decryptor
The pitch fits the hour after a ransom note, when a finance chief wants a moral exit and a technical one at the same time. MonsterCloud’s public language, documented in 2019 by ProPublica, told prospects “Don’t Pay the Ransom” and warned that payment did not guarantee the files would return. Pinhasi would not explain the method. “We work in the shadows,” he said. “How we do it, it’s our problem. You will get your data back. Sit back, relax and enjoy the ride.”
The indictment treats that mystery as the fraud. Coverage of the charging papers says that in May 2019, asked whether the firm held software that could decrypt ransomware, he answered that MonsterCloud did not hold any proprietary technology to decrypt the data. Prosecutors say he used the names Zack Silver and Zack Green with some of the crews. U.S. Attorney Joseph Nocella Jr. said that by falsely claiming to decrypt ransomware without paying, “the defendant re-victimized his clients while extracting a hefty profit for himself.”
The résumé did its own selling. Pinhasi told ProPublica he was a former Israeli military IT security intelligence officer, and later accounts describe Israel Defense Forces service in that field before a South Florida IT business. A past uniform is an easy thing to hand a panicked clerk. It deserves less reverence than the brochure gives it when Israel’s military-intelligence brand is doing the selling and the product, prosecutors say, was a payment desk.
How a decrypted sample became the close
The sale did not open at the full price. Reporting on the indictment describes an analysis fee, often $2,500 to $10,000. The firm took the ransom note and a sample of encrypted files, then sent back what it called recovery proofs, usually two unlocked documents. In many instances, prosecutors allege, the samples had gone to the attackers, who returned the clean copies. The client saw a before-and-after and did not see the chat where the proof was ordered.
That demonstration made the larger contract feel earned. The charging papers say the proofs pushed clients into full ransomware recovery, sometimes priced at twice the ransom or more. Some contracts said the firm would contact a cybercriminal only after every direct way of decrypting the files had failed. Prosecutors say contact was the usual first step, the way the company got both the sample and the key. Hundreds of companies in the United States and Canada are alleged to have paid.

The markup inside one August bill
The Justice Department’s public example is blunt. In or around August 2023, Pinhasi paid a ransom of about $8,200 and charged the client about $150,000, a gap that court coverage calls nearly twenty times the demand. Another job, from about October 2021, is described as a payment of about $236,000 against a bill of about $380,000. Court summaries place the core of the scheme from about June 2018 through June 2023. The numbers are allegations. They are what the government says wires, chats, and invoices will show, and they describe a workflow. The charging language reaches co-conspirators known and unknown to the grand jury, including MonsterCloud employees and contractors.
A former FBI deputy director called payment the model
ProPublica’s 2019 investigation found firms that promised high-tech recovery and, the reporters concluded, almost always just paid the hackers. Pinhasi denied misleading clients and said victims should never deal with attackers themselves. “They wouldn’t waste their time with us if we were a deceptive company,” he said. The same investigation reported that MonsterCloud paid former FBI deputy director John Pistole to speak for the firm. Pistole did not describe a secret breaker. “The model I’m used to is, you pay the ransom,” he told ProPublica.

A later account of ransom negotiation names MonsterCloud in a chapter on fraudulent recovery shops, walking through a Florida firm that told an engineering company it had cracked files after a quieter talk with the crew about a smaller sum.

Police clients who thought no ransom moved
Public agencies were the clients who most needed a no-payment promise. After a May 2018 attack, Chief Deputy Ward Calhoun of the Lauderdale County Sheriff’s Office in Mississippi told ProPublica the office would not hand money to hackers and that he still sent other victims toward MonsterCloud. In Trumann, Arkansas, Police Chief Chad Henson said case files and payroll were frozen. He picked the firm because it seemed friendly to law enforcement and because it would not pay. “To turn around and spend taxpayer money on a ransom, that is absolutely the wrong decision,” he said. The files returned within 72 hours. He was told no ransom moved. A $75,000 fee was waived for a testimonial.
The Trumann contract, released by public records request, called the method a trade secret and allowed contact with the attacker only after التشفير المباشر كان مرهقاً. ظن (هينسون) أن الخيار النووي خارج الطاولة ويقول المدعين أن الخيار هو الطريقة.

لماذا دفعة مخفية تكسر ملف الضحية
إذا كانت المدينة أو العيادة تعتقد أن البائع قام بفك شفرة الملفات سجل الحادث سيقول ذلك. الفدية، إذا تحركت، يمكن أن تعيش في الدردشة تحت زاك سيلفر أو زاك غرين بدلا من في كتب الضحية الخاصة. ComplexDiscovery’s read of the court file هي النقطة العملية. الضحية التي يجب أن تخبر مكتب الجزاءات، أو المؤمّن، أو المُنظّم ما إذا كان المال قد وصل إلى مهاجم لا يمكن أن يجيب من ملف فقط يكرر شعار البائع.
مكتب التحقيقات الفدرالي ووكالة أمن الفضاء والبنى التحتية قالوا منذ وقت طويل أنهم لا يوصون بالدفع. الدفع لا يضمن التشفير ولا يعني أن الدخيل قد ذهب ولا يحتفظ بنسخ مسروقة. إنها تمول الحملة القادمة التحذير يجلس CISA’s Stop Ransomware الصفحات والمقبوض عليها FBI Internet Crime Complaint Centerالبائع الذي يدفع في السر يأخذ فرصة العميل لتتبع تلك النصيحة.
نفس الضغط يظهر في مكان آخر cyber reportingطاقم الإبتزاز ما زال يطلب المال لدفن الملفات المسروقة ShinyHunters shopped Pornhub Premium historiesو Brazilian defendant was charged with seeking bitcoin بعد إختراق كبير طاقم (فانتوم هاكر) مرتبط billions in reported tech-support lossesيُقنع الناس بنقل المال بأنفسهم هنا، يَقُولُ المدعين العامين، الشخص الذي حرّكَه إعتقدَ a حامي كَانَ مستأجرَ.

ما الذي لا يزال غير مذنب يترك هيئة المحلفين
الإحتيال الزوجي عبارة عن كذبة محملة على جهاز تنصت، وليس نموذجاً تجارياً يُصادف أن هيئة المحلفين لا تحبه. المفاوض الذي يقول كتابياً أن طاقماً سيدفع له هو في موقف مختلف من متجر يقول موقعه على الإنترنت لا يدفع البرهان يشبه الهندسة. لا يزال على الحكومة أن تظهر سوء التمثيل والاعتماد والمال. المحادثات التي تم الإبلاغ عنها حول الإدانة ليست نداء مسؤول مكتب التحقيقات الفيدرالي (جيمس س. بارناكل الابن) لم يلمس وجهة نظر المكتب. (بينهاسي) ادعى أن يصلح الفدية بينما لا يصلح التهديد الأساسي. "أستيد، حوّل أزمة الضحية إلى مركز ربحه الخاص."

وريثما يتكلم المحلفين أو الاتفاق الموقع، تكون الخطوة المفيدة أقل من الحكم. أكتب إلى العقد ما إذا كان أي من الرسوم يمكن أن يصل إلى مهاجم. سمي الشخص الذي سيتحدث مع الطاقم ولا تقبل اسم مستعار. مقارنه بأوقات ملف الدليل مع الأصلي المشفر بدلا من معاملة وثيقة نظيفة كخدعة The المذنب و ♪ الملفات هنا تحتفظ بالسجل الأوسع للطاقم والوسطاء الذين يحاولون جمع مرتين، مرة واحدة للقفل ومرة واحدة للذعر. كما اتهمت قضية (مونستر كلود) هي مشروع القانون الثاني.










