Everything below is an allegation. Zohar Pinhasi, owner of the Florida firm MonsterCloud, was indicted by a federal grand jury in the Eastern District of New York on 23 September and arraigned in Brooklyn on 7 October, on two counts of wire fraud and one count of wire fraud conspiracy. He pleaded not guilty and was released on a two million dollar bond. Each count carries a maximum of twenty years.
None of it has been proved, and we are writing about it because of what the charges describe rather than because they are true.
What the indictment alleges
MonsterCloud sold ransomware recovery. The pitch, according to prosecutors, was that the firm had its own decryption technology — that a victim could get their files back without funding the people who had taken them.
Prosecutors allege there was no such technology. They say Pinhasi and others contacted the ransomware operators, paid them for decryption keys, and used those keys on customers' files.
The money, as the indictment has it: roughly eight million dollars paid to ransomware groups, against nineteen million billed to victims, across hundreds of clients in the United States and Canada. One example cited is a 2023 case where a client was charged around 150,000 dollars and the ransom paid was around 8,200.
The US Attorney's office framed it as re-victimising clients while taking a profit. That is a prosecutor's characterisation of a case it has to prove.
The defence that is already visible
The indictment itself acknowledges something that matters: some MonsterCloud contracts did disclose that the company might communicate with or pay cybercriminals.
The government's answer to that disclosure is a qualifier. Those same contracts allegedly said MonsterCloud would contact attackers only if it could not decrypt a customer's files by other means — which, if there were no other means, makes the disclosure describe a last resort that was in fact the only resort.
That is the hinge of the case, and it is a question about what the contracts said and what the firm could actually do. A reader should expect the defence to live there.
This was reported seven years ago
In 2019 ProPublica published an investigation into firms selling ransomware recovery that paid the ransom instead. MonsterCloud was one of two companies named. The researcher Fabian Wosar helped run a sting: ransom notes carrying email addresses the researchers controlled, posing as the gang, so they could see who got in touch.
Pinhasi's answer at the time was that the firm's recovery methods were a trade secret and that it did not mislead clients.
Put that beside the indictment's alleged period, which prosecutors give as June 2018 to June 2023. If the government is right about those dates, the conduct ran for four years after it was publicly reported, and the grand jury that returned this indictment did so on 23 September 2026 — seven years after the journalism.
Whatever the case decides, that gap is its own finding about how long a disputed practice can continue once the dispute is in print.
Why this matters past one firm
Set the specific allegations aside. The structure they describe is one the whole incident-response market has to answer for.
A victim calling a recovery firm is buying an outcome — files back — and is in no position to audit the method. The expertise gap is total: that is why they called. If the firm says it has proprietary tooling, the customer has no way to check, and the only observable is whether the files come back.
Which means a firm that quietly pays and bills a markup produces exactly the same observable as a firm that genuinely decrypts. The market cannot distinguish them on results.
And the second-order effect is the one that reaches people who never hired anybody. Ransomware is a business whose revenue is the proportion of victims who pay. A market segment that pays quietly, at scale, while telling the public that paying is unnecessary, inflates that proportion and conceals it at the same time. The gangs learn the real payment rate. Everyone else reads the advice.
This connects to something we wrote about an affiliate who diverted his gang's victims to his own leak site. The common thread is that almost everything known about ransomware economics is reported by parties with an interest in the number.
What to ask a recovery firm
Not as a response to this case, which is unproven, but because these are answerable questions and most contracts do not answer them:
- Will you pay a ransom on my behalf, under any circumstances, and will you tell me before you do it rather than after?
- What specifically is your recovery method for this family? A firm with real capability can name the flaw or the tool.
- Does your fee change depending on whether a payment is made? If not, ask why not.
- Will you give me the decryptor and its provenance, or only the restored files?
A firm that answers those plainly is a different proposition from one that does not, regardless of what any court decides here.
What is not established
- All of it, in the legal sense. These are charges. Pinhasi has pleaded not guilty and no case has been proved.
- What MonsterCloud's contracts actually said, in full, and how many customers saw which version.
- Whether the firm ever had any decryption capability, as opposed to none.
- Whether any client would have objected had they known. The indictment's theory is that the deception is the harm, which does not require that they would have.
- Whether other firms in the same market operate the same way. Nothing here establishes that, and the question is worth asking rather than assuming.