Justice CEO of Ransomware Recovery Firm Charged with Fraud
Article Content
- •Zohar Pinhasi charged with wire fraud for misleading clients about ransomware recovery.
- •MonsterCloud allegedly paid over $8 million in ransom while charging clients over $19 million.
- •Pinhasi faces up to 20 years in prison if convicted.
Zohar Pinhasi, owner of MonsterCloud, was charged with wire fraud for allegedly defrauding clients by falsely claiming to decrypt ransomware without paying attackers. The indictment states that from June 2018 to June 2023, Pinhasi paid over $8 million in ransom while charging clients more than $19 million for recovery services. Prosecutors allege that MonsterCloud's contracts misled clients about the company's practices, claiming proprietary technology that did not exist. Instead, Pinhasi reportedly contacted cybercriminals to obtain decryption keys, which he then used to restore clients' files. If convicted, he faces up to 20 years in prison. The case highlights the risks of trusting third-party recovery services in ransomware incidents.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track MonsterCloud LLC in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What specific charges does Pinhasi face?
What was MonsterCloud's claimed method for data recovery?
What are the potential consequences for Pinhasi?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…