{
  "id": 12774031,
  "title": "Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead",
  "url": "https://urgent.news/2026/10/08/ransomware-fixer-claimed-he-could-decrypt-files-allegedly-defrauded",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T02:29:55.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/cyber-crime/2026/10/08/ransomware-fixer-claimed-he-could-decrypt-files-allegedly-defrauded-clients-instead/5301831"
  },
  "original_language": "en",
  "account": "The United States Department of Justice has charged a man named Zohar Pinhasi, better known by his aliases \"Zack Silver\" and \"Zack Green,\" with fraud for allegedly deceiving clients about his ability to decrypt files locked by ransomware. Pinhasi ran a Florida-based company called MonsterCloud, which claimed to have \"proprietary tools\" and \"advanced decryption techniques\" to recover encrypted data for distressed business owners who sought his aid.\n\nAccording to the DOJ press release, Pinhasi allegedly used a portion of his clients' fees to pay off ransomware attackers, while retaining the remainder, often with a substantial markup. In one case, Pinhasi charged his client $150,000 but paid the $8,200 ransom himself, retaining the remaining funds. This scheme proved successful, with Pinhasi allegedly charging clients over $19 million and paying over $8 million in ransom payments.\n\nThe indictment alleges that MonsterCloud's website featured claims of advanced decryption techniques, cutting-edge technology, and a team of IT experts. However, the indictment suggests that these claims were misleading, with the site containing \"testimonials\" and promotional content, including from at least one compensated spokesperson. In May 2019, the spokesperson questioned Pinhasi about his business practices and truthfulness, to which he allegedly responded that MonsterCloud did not possess any proprietary technology to decrypt ransomware data.\n\nPinhasi faces two counts of wire fraud and one count of wire fraud conspiracy, with a potential twenty-year prison sentence for each count should he be convicted. The FBI is currently investigating this case, and the indictment indicates that Pinhasi had multiple co-conspirators, both known and unknown to the grand jury, including MonsterCloud employees and contractors.",
  "summary": "Feds claim he charged clients more than ransoms, paid up, pocketed the difference",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Ransomware fixer claimed he could decrypt files, allegedly defrauded clients instead",
        "url": "https://urgent.news/2026/10/08/ransomware-fixer-claimed-he-could-decrypt-files-allegedly-defrauded-12775836",
        "published": "2026-10-08T02:29:55.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}