← Zohar Pinhasi / MonsterCloud1 decision on this page
Audit log
Every state-changing event for Zohar Pinhasi / MonsterCloud: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-08 17:08:25ZScore: ? → ? (no score change)anchorfailed
- chain
- ●—
- hash
83f7M332Yigx…Jbd4MZnFsha256 → base58
verifying row…canonical bytes (19698 B) ▸
{"actor":"system:backfill","investigation_id":"fca6f31e-7735-4d1d-945a-9e251956ab15","kind":"publish","page_slug":"zohar-pinhasi-monstercloud","published_at":"2026-10-08T17:08:25.188Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Zohar Pinhasi / MonsterCloud","sections":[{"content":"On September 23, 2026, a federal grand jury in the Eastern District of New York returned an indictment against Zohar Pinhasi, also known as 'Zack Silver' and 'Zack Green,' charging him with two counts of wire fraud and one count of wire fraud conspiracy. Pinhasi was arraigned on October 7, 2026 in federal court in Brooklyn, where he pleaded not guilty and was released on a $2 million bond. If convicted on all counts, he faces a maximum sentence of 20 years in prison per count. The charges are allegations; no verdict or judicial finding of guilt has been entered as of the date of this writing. The DOJ press release quoted U.S. Attorney Joseph Nocella Jr. as stating that Pinhasi 're-victimized his clients while extracting hefty profit,' and FBI Assistant Director James C. Barnacle Jr. as stating he 'turned the victim's crisis into his own profit center.' The indictment references multiple co-conspirators described as 'individuals whose identities are both known and unknown to the Grand Jury, including MonsterCloud employees and contractors,' but no co-defendants have been publicly named.","heading":"Criminal Charges (October 2026)","severity":"critical","sources":[{"credibility":1,"name":"DOJ Office of Public Affairs — Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged","type":"regulatory","url":"https://www.justice.gov/opa/pr/known-cybersecurity-expert-and-owner-florida-ransomware-remediation-company-charged"},{"credibility":1,"name":"DOJ USAO-EDNY Press Release","type":"regulatory","url":"https://www.justice.gov/usao-edny/pr/owner-florida-ransomware-remediation-company-charged-defrauding-clients"},{"credibility":2,"name":"Help Net Security — Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims","type":"news_article","url":"https://www.helpnetsecurity.com/2026/10/08/monstercloud-owner-ransomware-fraud-charges/"}]},{"content":"Prosecutors allege that from approximately June 2018 to June 2023, Pinhasi and co-conspirators operated MonsterCloud by soliciting businesses, hospitals, and municipalities that had been struck by ransomware attacks. MonsterCloud's website and marketing materials advertised 'proprietary tools' and 'advanced decryption techniques' as an alternative to paying ransoms directly, with the site stating the company did 'not guarantee' that ransom payments worked. According to the indictment, Pinhasi had no such proprietary technology. Instead, he and co-conspirators allegedly contacted the ransomware operators directly, negotiated and paid ransoms in cryptocurrency to obtain decryption keys, then used those keys to restore victims' files — all while billing clients at substantially inflated rates and misrepresenting the recovery method. The Register reported that when confronted by a paid spokesperson, Pinhasi admitted 'MonsterCloud doesn't hold any proprietary technology [to] decrypt the ransomware data.' These representations are drawn from the government's charging documents and contemporaneous reporting; they have not been adjudicated.","heading":"Alleged Scheme: Fake Proprietary Decryption","severity":"critical","sources":[{"credibility":1,"name":"DOJ Office of Public Affairs — Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged","type":"regulatory","url":"https://www.justice.gov/opa/pr/known-cybersecurity-expert-and-owner-florida-ransomware-remediation-company-charged"},{"credibility":2,"name":"The Hacker News — MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms","type":"news_article","url":"https://thehackernews.com/2026/10/monstercloud-owner-accused-of-billing.html"},{"credibility":2,"name":"The Register — Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead","type":"news_article","url":"https://www.theregister.com/cyber-crime/2026/10/08/ransomware-fixer-claimed-he-could-decrypt-files-allegedly-defrauded-clients-instead/5301831"}]},{"content":"According to the indictment as reported by the DOJ and multiple news outlets, Pinhasi allegedly billed clients over $19 million in total while paying ransomware operators over $8 million, yielding an alleged markup of approximately $11 million. Two specific transactions are cited in reporting. First, prosecutors allege that in August 2023, Pinhasi paid a ransomware affiliate approximately $8,200 to obtain a decryption key but charged the client approximately $150,000 — a markup of roughly 1,730 percent. Second, in October 2021, he allegedly paid approximately $236,000 in ransom while charging a customer approximately $380,000. These figures are drawn from the government's charging documents and have not been proven at trial.","heading":"Financial Allegations: Scale and Markup","severity":"critical","sources":[{"credibility":2,"name":"SecurityWeek — Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme","type":"news_article","url":"https://www.securityweek.com/fake-decryption-tools-masked-11m-markup-in-ransomware-recovery-scheme/"},{"credibility":2,"name":"The Hacker News — MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms","type":"news_article","url":"https://thehackernews.com/2026/10/monstercloud-owner-accused-of-billing.html"},{"credibility":2,"name":"Help Net Security — Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims","type":"news_article","url":"https://www.helpnetsecurity.com/2026/10/08/monstercloud-owner-ransomware-fraud-charges/"}]},{"content":"A central element of the alleged scheme, as described in the DOJ's charging narrative, is the use of cryptocurrency to pay ransomware operators. Ransomware groups routinely demand payment in Bitcoin or other cryptocurrencies to preserve attacker anonymity, and prosecutors allege Pinhasi facilitated these payments on behalf of victims while concealing that any ransom was being paid at all. The indictment covers a period (June 2018 to June 2023) during which crypto-denominated ransomware payments became a defining feature of the cybercriminal ecosystem. Specific cryptocurrency wallets or blockchain forensics are not detailed in publicly available charging documents or reporting as of the date of this writing. The indictment characterizes the transfers as the basis for the wire fraud charges, and the FBI — which is the investigating agency — has extensive on-chain analysis capability. No on-chain evidence has been independently published.","heading":"Cryptocurrency as the Payment Layer","severity":"high","sources":[{"credibility":1,"name":"DOJ Office of Public Affairs — Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged","type":"regulatory","url":"https://www.justice.gov/opa/pr/known-cybersecurity-expert-and-owner-florida-ransomware-remediation-company-charged"},{"credibility":2,"name":"BleepingComputer — Ransomware recovery CEO charged over secret ransom payments","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/"}]},{"content":"The alleged conduct did not emerge without prior warning. In May 2019, ProPublica published a major investigative piece titled 'The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers,' which named MonsterCloud and examined its practices in detail. The investigation found that MonsterCloud routinely paid ransoms while telling clients no ransom was paid. Specific law enforcement agencies mentioned by ProPublica as MonsterCloud clients — believing they had received ransom-free recovery — include the Trumann, Arkansas Police Department (November 2018, Dharma ransomware), the Lamar County, Texas Sheriff's Office (May 2018), and the Lauderdale County, Mississippi Sheriff's Office (May 2018). The investigation also documented the use of employee aliases such as 'Zack Green,' the posting of fabricated five-star Google reviews, and Pinhasi's self-description as a former Israeli military IT security intelligence officer — a claim contradicted by corporate records showing MonsterCloud was incorporated in Florida in 2013, not 2003 as he claimed. Pinhasi acknowledged the use of aliases to ProPublica, stating: 'We go based on aliases, because we're dealing with cyberterrorists.' No FTC or DOJ action followed the 2019 reporting at the time; charges were brought approximately seven years after the scheme allegedly began.","heading":"Prior Investigative Reporting (2019)","severity":"high","sources":[{"credibility":1,"name":"ProPublica — The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers","type":"news_article","url":"https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/"}]},{"content":"Zohar Pinhasi, 50, is a dual U.S.-Israeli national who resided in Hollywood, Florida at the time of his indictment. He describes himself publicly as a former IT security intelligence officer for the Israeli military and claims to have led MonsterCloud since 2003. Florida corporation records reviewed by ProPublica show the business was incorporated in 2013. Prior to MonsterCloud, Pinhasi co-founded PC USA Computer Solutions Providers in 2003; at least one client of that earlier firm alleged, in ProPublica's 2019 reporting, that Pinhasi demanded additional payment and disappeared after a data loss incident — a claim Pinhasi disputed. At the time of the ProPublica investigation, MonsterCloud operated from a storefront in Hollywood, Florida with approximately 20 employees and handled an estimated 30 client calls per day. The company listed former TSA Deputy Director John Pistole as the sole member of a 'Cyber Security Advisory Council,' though Pistole acknowledged in interviews that MonsterCloud's model involved paying ransoms. Pistole was also involved in a separate Pinhasi venture, Skyline Comfort LLC, an airport massage chair business. These earlier associations are factual background; they do not bear on the criminal charges, which are themselves allegations.","heading":"Background: Zohar Pinhasi and MonsterCloud","severity":"medium","sources":[{"credibility":1,"name":"ProPublica — The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers","type":"news_article","url":"https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/"},{"credibility":2,"name":"DataBreaches.Net — Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients","type":"news_article","url":"https://databreaches.net/2026/10/07/known-cybersecurity-expert-and-owner-of-florida-ransomware-remediation-company-charged/"}]},{"content":"As of October 8, 2026, Pinhasi has pleaded not guilty to all counts. He was released on a $2 million bond following his arraignment on October 7, 2026 in the Eastern District of New York. The indictment references unnamed co-conspirators among MonsterCloud employees and contractors, suggesting the investigation may be ongoing and further charges are possible. No trial date has been publicly announced. This page will require updating as proceedings develop. The charges represent serious federal allegations, but they remain unproven and Pinhasi is presumed innocent unless and until found guilty.","heading":"Case Status and Pending Proceedings","severity":"high","sources":[{"credibility":1,"name":"DOJ USAO-EDNY Press Release","type":"regulatory","url":"https://www.justice.gov/usao-edny/pr/owner-florida-ransomware-remediation-company-charged-defrauding-clients"},{"credibility":2,"name":"BleepingComputer — Ransomware recovery CEO charged over secret ransom payments","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/"},{"credibility":2,"name":"The Jerusalem Post — Zohar Pinhasi charged with wire fraud after using cybersecurity company to pay off hackers","type":"news_article","url":"https://www.jpost.com/israel-news/article-910994"}]}],"sources_used":[{"credibility":1,"name":"DOJ Office of Public Affairs — Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged","type":"regulatory","url":"https://www.justice.gov/opa/pr/known-cybersecurity-expert-and-owner-florida-ransomware-remediation-company-charged"},{"credibility":1,"name":"DOJ USAO-EDNY — Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients","type":"regulatory","url":"https://www.justice.gov/usao-edny/pr/owner-florida-ransomware-remediation-company-charged-defrauding-clients"},{"credibility":1,"name":"ProPublica — The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers","type":"news_article","url":"https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/"},{"credibility":2,"name":"The Hacker News — MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data","type":"news_article","url":"https://thehackernews.com/2026/10/monstercloud-owner-accused-of-billing.html"},{"credibility":2,"name":"Help Net Security — Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims","type":"news_article","url":"https://www.helpnetsecurity.com/2026/10/08/monstercloud-owner-ransomware-fraud-charges/"},{"credibility":2,"name":"SecurityWeek — Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme","type":"news_article","url":"https://www.securityweek.com/fake-decryption-tools-masked-11m-markup-in-ransomware-recovery-scheme/"},{"credibility":2,"name":"The Register — Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead","type":"news_article","url":"https://www.theregister.com/cyber-crime/2026/10/08/ransomware-fixer-claimed-he-could-decrypt-files-allegedly-defrauded-clients-instead/5301831"},{"credibility":2,"name":"BleepingComputer — Ransomware recovery CEO charged over secret ransom payments","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/"},{"credibility":2,"name":"DataBreaches.Net — Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients","type":"news_article","url":"https://databreaches.net/2026/10/07/known-cybersecurity-expert-and-owner-of-florida-ransomware-remediation-company-charged/"},{"credibility":2,"name":"The Jerusalem Post — Zohar Pinhasi charged with wire fraud after using cybersecurity company to pay off hackers","type":"news_article","url":"https://www.jpost.com/israel-news/article-910994"},{"credibility":2,"name":"Insurance Journal — Florida Cybersecurity Firm Head Charged With Scamming Victimized Businesses","type":"news_article","url":"https://www.insurancejournal.com/news/southeast/2026/10/08/888445.htm"}],"summary":"Zohar Pinhasi, owner of Florida-based cybersecurity firm MonsterCloud LLC, was indicted by a federal grand jury in the Eastern District of New York on September 23, 2026 and arraigned on October 7, 2026 on two counts of wire fraud and one count of wire fraud conspiracy. Prosecutors allege he collected over $19 million from ransomware victims by falsely claiming his firm used proprietary decryption technology, while secretly paying ransomware attackers over $8 million in ransom and pocketing the difference. The alleged scheme ran from approximately June 2018 to June 2023. These are charges, not convictions; Pinhasi pleaded not guilty and was released on a $2 million bond.","timeline":[{"date":"2013-01-01","event":"MonsterCloud LLC incorporated in Florida (Florida corporate records contradict Pinhasi's public claim that he led the firm since 2003).","source":"ProPublica","source_url":"https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/"},{"date":"2018-05-01","event":"Lamar County, Texas Sheriff's Office allegedly receives MonsterCloud ransomware recovery services; county officials reportedly believed no ransom was paid.","source":"ProPublica","source_url":"https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/"},{"date":"2018-05-01","event":"Lauderdale County, Mississippi Sheriff's Office allegedly receives MonsterCloud ransomware recovery services; officials reportedly believed no ransom was paid.","source":"ProPublica","source_url":"https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/"},{"date":"2018-06-01","event":"Alleged start date of the wire fraud scheme as charged in the September 2026 indictment.","source":"DOJ USAO-EDNY Press Release","source_url":"https://www.justice.gov/usao-edny/pr/owner-florida-ransomware-remediation-company-charged-defrauding-clients"},{"date":"2018-11-01","event":"Trumann, Arkansas Police Department hit by Dharma ransomware; MonsterCloud allegedly restored files and assured the department no ransom was paid, according to ProPublica's subsequent investigation.","source":"ProPublica","source_url":"https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/"},{"date":"2019-05-16","event":"ProPublica publishes 'The Trade Secret,' naming MonsterCloud and reporting that the firm paid ransoms while telling clients otherwise. No regulatory action follows at this time.","source":"ProPublica","source_url":"https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/"},{"date":"2021-10-01","event":"Prosecutors allege Pinhasi paid approximately $236,000 to a ransomware operator while charging a client approximately $380,000 for the same incident.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/10/monstercloud-owner-accused-of-billing.html"},{"date":"2023-06-01","event":"Alleged end date of the wire fraud scheme as charged in the September 2026 indictment.","source":"DOJ USAO-EDNY Press Release","source_url":"https://www.justice.gov/usao-edny/pr/owner-florida-ransomware-remediation-company-charged-defrauding-clients"},{"date":"2023-08-01","event":"Prosecutors allege Pinhasi paid approximately $8,200 to a ransomware affiliate and charged the client approximately $150,000 — cited in the indictment as an illustrative transaction.","source":"DOJ Office of Public Affairs","source_url":"https://www.justice.gov/opa/pr/known-cybersecurity-expert-and-owner-florida-ransomware-remediation-company-charged"},{"date":"2026-09-23","event":"Federal grand jury in the Eastern District of New York returns indictment against Zohar Pinhasi on two counts of wire fraud and one count of wire fraud conspiracy.","source":"DOJ Office of Public Affairs","source_url":"https://www.justice.gov/opa/pr/known-cybersecurity-expert-and-owner-florida-ransomware-remediation-company-charged"},{"date":"2026-10-07","event":"Pinhasi arraigned in federal court in Brooklyn; pleads not guilty; released on $2 million bond. DOJ and FBI issue public statements.","source":"DOJ USAO-EDNY Press Release","source_url":"https://www.justice.gov/usao-edny/pr/owner-florida-ransomware-remediation-company-charged-defrauding-clients"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 7fdee216-3375-44ab-87d2-c3486efe65ce
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.