21 Arrows Ventures
All notes

October 8, 2026 — 21 Arrows

Ransomware recovery firm charged with secretly paying attackers

Key takeaways

  • The U.S. Department of Justice charged MonsterCloud's CEO with secretly paying ransoms while claiming to use proprietary recovery technology.
  • Businesses under ransomware pressure are vulnerable to deceptive recovery firms that exploit the urgency of the moment.
  • Paying a ransom without disclosure can violate compliance rules and fund future attacks.
  • Not all recovery firms are fraudulent, but vetting partners before an incident is critical.
  • A ransomware response plan with offline backups and vetted contacts reduces your reliance on unknown vendors during a crisis.

The development

On October 7, 2026, the U.S. Department of Justice announced charges (https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/) against Zohar Pinhasi, the 50-year-old owner of MonsterCloud, a ransomware recovery firm. Pinhasi, who also goes by the names Zack Silver and Zack Green, faces two counts of wire fraud and one count of wire fraud conspiracy. The allegations are stark: he billed victims more than $19 million while secretly paying ransomware attackers (https://thehackernews.com/2026/10/monstercloud-owner-accused-of-billing.html) for decryption keys, then told clients his company used proprietary recovery technology.

MonsterCloud marketed itself as a data recovery specialist. Victims locked out of their systems by ransomware would hire the firm, expecting technical expertise and ethical handling. Instead, prosecutors say, Pinhasi negotiated directly with the attackers, paid the ransom, and passed along the decryption key while marking up the cost and hiding what actually happened.

The indictment does not specify which ransomware gangs received payment, nor does it detail how many victims were misled. What matters is the pattern: businesses in crisis were sold a story about innovation when the service was something else entirely.

Why it matters to a business owner

Ransomware attacks hit when you are already down. Systems are frozen. Customers are waiting. Revenue is bleeding. That pressure creates a narrow window where decisions get made fast, often by people who have never dealt with this kind of incident before.

Into that window walk recovery firms, insurers, incident responders, and negotiators. Some are ethical. Some are experienced. And some, it turns out, are neither.

The MonsterCloud case exposes a hidden layer of risk: the people you hire to help may not be operating the way they say they are. If a firm tells you it can recover your data without paying a ransom, you want that to be true. You want proprietary tools, clever engineering, or access to known decryption flaws. What you do not want is someone quietly wiring Bitcoin to a criminal gang and then lying about it on the invoice.

This matters beyond the dollar amount. Paying a ransom funds future attacks. It teaches criminals that victims will pay. It makes your industry a bigger target. And if you thought you were avoiding that by hiring a recovery firm with a technical pitch, but the firm paid anyway, you funded the problem without knowing it.

There is also a compliance angle. Some sectors face regulatory or contractual limits on ransom payments. If your recovery partner pays without disclosure, you may be in violation without realizing it.

Finally, this case is a reminder that desperation is profitable. The businesses most likely to hire a recovery firm are the ones least able to vet it carefully. That asymmetry is easy to exploit.

What it does NOT mean

This is not evidence that all ransomware recovery firms are fraudulent. Many incident response companies operate with transparency, and some have strict policies against facilitating ransom payments. Organizations like Coveware and the Ransomware Task Force publish guidance on when and how payments happen, and reputable firms will tell you up front if paying the attacker is the recommended path.

It also does not mean you should never pay a ransom. Sometimes that is the least bad option, particularly when backups are gone and downtime costs are catastrophic. What matters is informed consent. If you decide to pay, you should know that is what you are doing, understand the risks, and have a clear picture of the cost.

The charges against Pinhasi are allegations, not a conviction. He is entitled to his defense, and the case will move through the courts. But the fact pattern described by prosecutors is enough to warrant a broader conversation about transparency in the recovery industry.

A practical next step

If you run a business with digital infrastructure, put a ransomware plan in place before you need it. That plan should include:

  • Offline backups that are tested regularly. If you can restore from backup, you remove the attacker's leverage.
  • A shortlist of vetted incident response firms. Do the research now, not during an outage. Look for firms that publish their methodology, carry relevant insurance, and have references you can check.
  • A decision tree for ransom scenarios. Who has authority to approve payment? What legal or regulatory obligations apply? What disclosures are required?
  • Transparency requirements in any recovery contract. If you hire someone to help, the agreement should specify whether they will or will not pay a ransom on your behalf, and what they will disclose to you.

If you are already working with a recovery firm or cyber insurance provider, ask explicit questions. Do they pay ransoms? Under what conditions? How is that cost reflected in your bill? If the answer is vague, keep asking.

The MonsterCloud indictment will not be the last case of its kind. The ransomware economy is too large and the incentives too misaligned. But you can shrink your exposure by building relationships and processes before the crisis hits. Trust matters most when you have the least time to establish it.

ransomware · cybersecurity · incident response · business continuity · compliance

Start a project

Have a target in mind?

Tell us what eats your week. The first conversation is free; the assessment that follows pays for itself or we say so up front.

The weekly AI briefing

One email a week.No filler.

What's actually working with AI and automation inside real businesses — the tools worth your time, the ones that aren't, and what we shipped this week.

No spam, and one click to leave whenever you like.