Skip to main content
AVOID.NET

Zohar Pinhasi / MonsterCloud

avoid.net/zohar-pinhasi-monstercloud→4/100·91% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

last updated 2026-10-08

Summary

Zohar Pinhasi, owner of Florida-based cybersecurity firm MonsterCloud LLC, was indicted by a federal grand jury in the Eastern District of New York on September 23, 2026 and arraigned on October 7, 2026 on two counts of wire fraud and one count of wire fraud conspiracy. Prosecutors allege he collected over $19 million from ransomware victims by falsely claiming his firm used proprietary decryption technology, while secretly paying ransomware attackers over $8 million in ransom and pocketing the difference. The alleged scheme ran from approximately June 2018 to June 2023. These are charges, not convictions; Pinhasi pleaded not guilty and was released on a $2 million bond.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Zohar Pinhasi / MonsterCloud?

Timeline(11 events)

1 January 2013

MonsterCloud LLC incorporated in Florida (Florida corporate records contradict Pinhasi's public claim that he led the firm since 2003).

ProPublica

1 May 2018

Lamar County, Texas Sheriff's Office allegedly receives MonsterCloud ransomware recovery services; county officials reportedly believed no ransom was paid.

ProPublica

1 May 2018

Lauderdale County, Mississippi Sheriff's Office allegedly receives MonsterCloud ransomware recovery services; officials reportedly believed no ransom was paid.

ProPublica

1 June 2018

Alleged start date of the wire fraud scheme as charged in the September 2026 indictment.

DOJ USAO-EDNY Press Release

1 November 2018

Trumann, Arkansas Police Department hit by Dharma ransomware; MonsterCloud allegedly restored files and assured the department no ransom was paid, according to ProPublica's subsequent investigation.

ProPublica

16 May 2019

ProPublica publishes 'The Trade Secret,' naming MonsterCloud and reporting that the firm paid ransoms while telling clients otherwise. No regulatory action follows at this time.

ProPublica

1 October 2021

Prosecutors allege Pinhasi paid approximately $236,000 to a ransomware operator while charging a client approximately $380,000 for the same incident.

The Hacker News

1 June 2023

Alleged end date of the wire fraud scheme as charged in the September 2026 indictment.

DOJ USAO-EDNY Press Release

1 August 2023

Prosecutors allege Pinhasi paid approximately $8,200 to a ransomware affiliate and charged the client approximately $150,000 — cited in the indictment as an illustrative transaction.

DOJ Office of Public Affairs

23 September 2026

Federal grand jury in the Eastern District of New York returns indictment against Zohar Pinhasi on two counts of wire fraud and one count of wire fraud conspiracy.

DOJ Office of Public Affairs

7 October 2026

Pinhasi arraigned in federal court in Brooklyn; pleads not guilty; released on $2 million bond. DOJ and FBI issue public statements.

DOJ USAO-EDNY Press Release
Provenance & Audit Trail
8 Wayback Archives

Decision Log

  • #1publishNot recorded (failed)10/8/2026, 5:08:25 PM
    hash 83f7M332YigxmMJfhcafYBdKJ1nskauGXjUNJbd4MZnF

8 of 11 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 10/8/2026, 5:08:16 PM

last updated: 10/8/2026, 7:52:16 PM

avoid.net — verified advice for a post-truth world