Image: CSO Online

UpTrajectory Review

A Long Island ransomware 'recovery' firm called MonsterCloud is at the center of a fraud case that should unsettle every small business owner who has ever outsourced a cybersecurity crisis. The company's owner, Zohar Pinhasi (who also went by Zack Silver and Zack Green), has been arraigned in New York on wire fraud charges. According to the indictment, MonsterCloud marketed itself as a technical alternative to paying ransoms — claiming specialized decryption techniques that could restore locked files without capitulating to cybercriminals. In reality, prosecutors allege, Pinhasi simply paid the hackers, obtained the decryption key, and then passed it off as the product of his own expertise. The markup was staggering: in one 2023 case, he allegedly paid an $8,200 ransom and billed the client $150,000.

For a small business owner, this case cuts to the bone because ransomware is not an abstract threat — it is the kind of event that can end a business permanently. When your files are encrypted and your operations are frozen, you are desperate, you are not thinking clearly, and you are highly susceptible to anyone who promises a clean, legal, technically elegant way out. MonsterCloud exploited that vulnerability. The company positioned itself as the responsible choice: pay us, and you avoid the moral hazard and legal risk of funding criminals. That framing is exactly what made the alleged fraud so effective. A small business owner who believed they were taking the high road may have been paying a 1,700 percent markup for the very transaction they were trying to avoid.

What is genuinely newsworthy here is not just the fraud itself but the structural problem it exposes in the ransomware recovery industry. The FBI and CISA officially discourage ransom payments, and paying sanctioned entities can carry real legal exposure. That creates a perverse incentive: recovery firms can charge a premium for what is essentially plausible deniability. The client never has to know a payment was made, the recovery firm pockets the difference, and everyone walks away satisfied — except the broader ecosystem, which continues to fund criminal operations. The CSO piece hints at this dynamic but does not fully explore it. Kolochenko's observation that some negotiators inflate fees with dubious add-ons like 'third-party validation of secure data erasure' suggests this may not be an isolated pattern. We are skeptical that Pinhasi is the only operator running this playbook.

The second-order effects ripple outward in several directions. First, trust in legitimate incident response firms — and there are many — takes a hit every time a story like this breaks. Business owners who might have benefited from professional help during a ransomware event may now attempt to handle it in-house, with worse outcomes. Second, the case highlights a regulatory gray zone. Ransomware negotiation is an unlicensed, largely unregulated industry. Anyone can hang a shingle and claim decryption expertise. There is no certification body, no mandatory disclosure requirement, no obligation to tell a client that a ransom was paid on their behalf. That opacity is not a bug — it is the business model. Third, for businesses in regulated industries or those handling sensitive data, the discovery that a vendor secretly paid a ransom could create compliance and liability problems that outlast the original attack.

What should a small business operator do with this information? First, if you are ever hit with ransomware and engage an outside firm, demand transparency in writing: ask specifically whether any ransom payment will be made on your behalf, and require itemized invoicing that separates service fees from any payments to third parties. Second, vet any recovery firm before you need one. Look for established incident response providers with verifiable technical credentials, not just a polished website and a promise to avoid paying. Third, treat this as a prompt to invest in prevention — immutable backups, segmented networks, and a written incident response plan — because the best negotiation is the one you never have to conduct. Watch how this trial unfolds, because a conviction could prompt lawmakers to finally impose disclosure and licensing requirements on an industry that has operated in the shadows for too long.

“The defendant re-victimized his clients while extracting a hefty profit for himself.” — CSO Online

Takeaway: Before hiring any ransomware recovery firm, demand written confirmation of whether ransom payments will be made on your behalf and require itemized billing separating fees from payments.

Excerpt from the original — CSO Online

The owner of a ransomware remediation company is facing trial for defrauding customers.

Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” has been arraigned in New York on wire fraud charges for allegedly defrauding clients of his ransomware remediation company, MonsterCloud.

Pinhasi falsely claimed he could recover documents encrypted by ransomware without paying a ransom, according to district attorney Joseph Nocella. “The defendant re-victimized his clients while extracting a hefty profit for himself,” Nocella said.

MonsterCloud claimed to offer an alternative to paying the ransom. Its website said that, thanks to its decryption techniques, “our team specializes in helping businesses recover their data without succumbing to ransom demands.” 

However, the indictment alleges that rather than using any technology, Pinhasi simply paid the cybercriminals in exchange …