Editor’s Note: Zohar Pinhasi, owner of Florida ransomware-recovery firm MonsterCloud, was arraigned Oct. 7 in Brooklyn on federal charges that he told clients he had proprietary decryption tools while secretly paying their attackers. The U.S. Attorney’s Office told BleepingComputer he pleaded not guilty, and the charges are allegations. The case reaches past the fraud counts. According to the indictment, many clients were never told a ransom had been paid, and certain contracts allowed contact with attackers only as a last resort when prosecutors say it was generally the first step.

For cybersecurity and incident-response leaders, that is a vendor diligence problem. For compliance teams, OFAC asks victims to report ransomware payments, New York requires a 24-hour extortion payment notice, and CIRCIA, once its final rule takes effect, will require a paying vendor to advise its client of reporting duties. For information governance and eDiscovery professionals, the client’s own incident file may repeat the vendor’s account while the payment facts sit with the vendor.  Watch for CISA’s final CIRCIA rule and the next filings in United States v. Pinhasi.


Content Assessment: MonsterCloud indictment exposes the ransom payment a victim's own file may not record

Information - 94%
Insight - 92%
Relevance - 94%
Objectivity - 92%
Authority - 91%

93%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "MonsterCloud indictment exposes the ransom payment a victim's own file may not record."


News Analysis – Cybersecurity Beat

MonsterCloud indictment exposes the ransom payment a victim’s own file may not record

ComplexDiscovery OÜ Staff

The owner of a Florida ransomware-recovery firm was arraigned Oct. 7 in Brooklyn on charges he told clients he had proprietary decryption tools while secretly paying the criminals who locked their files.

Prosecutors say many of those clients were never told a ransom had been paid. If that holds, the incident files those organizations kept may tell a story about their own recovery that the indictment says is false.

Zohar Pinhasi, 50, of Hollywood, Florida, a U.S. and Israeli national also known as “Zack Silver” and “Zack Green,” owned and ran MonsterCloud LLC, according to the indictment a grand jury in the U.S. District Court for the Eastern District of New York returned Sept. 23. He is charged with one count of conspiracy to commit wire fraud and two counts of wire fraud, and the Justice Department said each count carries a maximum penalty of 20 years.

The court docket shows his first appearance was moved from Sept. 30 to Oct. 7 at his attorney’s request, after the lawyer wrote that Pinhasi was abroad on travel booked before he learned of the indictment, would return voluntarily and had no objection from prosecutors. The U.S. Attorney’s Office told BleepingComputer that Pinhasi surrendered Oct. 7, entered a plea of not guilty and was freed on a $2 million bond, and the docket lists an order setting his conditions of release. BleepingComputer said it had contacted his attorneys, Christopher Clark and Rodney Villazor, and reported no response; ComplexDiscovery did not seek comment from Pinhasi, his counsel or MonsterCloud. The charges are allegations, and Pinhasi is presumed innocent. What the indictment describes is a business built on a promise about how locked files came back.



What the grand jury says MonsterCloud sold

Between about June 2018 and June 2023, the indictment alleges, Pinhasi presented MonsterCloud as a remediation firm armed with “proprietary tools,” steered prospective clients away from paying ransoms and then paid the attackers himself for decryption keys. The company’s website said its team “specializes in helping businesses recover their data without succumbing to ransom demands,” the indictment states. Multiple clients hired the firm because they wanted no money going to a criminal and would not have approved such a payment, according to the grand jury.

The mechanics are specific. MonsterCloud first charged an analysis fee, typically $2,500 to $10,000, and then returned decrypted samples of the client’s files, usually two, as what Pinhasi called “recovery proofs.” In many instances, prosecutors allege, he had sent the samples to the attackers and obtained the decrypted versions from them. He described his methods to clients as “trade secrets” and directed employees and contractors to say “recovery tool” instead of “decryptor,” the indictment says.

The money is where the allegation sharpens. In one case the indictment dates to about August 2023, slightly after the approximate end date it gives for the scheme, Pinhasi allegedly paid about $8,200 and billed the client about $150,000. That is roughly 18 times the ransom, a multiple the indictment describes as “nearly twenty times the cost of the ransom demand.” In October 2021 he allegedly paid about $236,000 and billed about $380,000. Across the scheme, the grand jury counts dozens of ransom payments totaling over $8 million and says hundreds of companies in the United States and Canada paid MonsterCloud over $19 million. That second figure covers every recovery and remediation service those companies bought, so the gap between the two totals is not a measure of the markup.

In May 2019, a paid spokesperson questioned Pinhasi about whether the company owned any proprietary decryption software, the indictment says. He allegedly replied that “MonsterCloud doesn’t hold any Proprietary technology [to] decrypt the ransomware data.”

“As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” U.S. Attorney Joseph Nocella Jr. said. That account turns on what clients were told, and what some of them signed says something narrower.

The contract clause that described the exception

Some MonsterCloud contracts did tell clients that the company might, on occasion, communicate with or pay attackers, the indictment says. Certain contracts added that MonsterCloud would contact a cybercriminal “only once all possible means of directly decrypting Client’s files have been exhausted.” Prosecutors allege that dealing with the criminals was generally Pinhasi’s first step rather than his last.

A client relying on that language had paper. What it lacked was evidence of practice, because a promise that contact happens only under stated conditions tells an organization nothing about whether those conditions were ever met. The indictment alleges that in many cases Pinhasi paid without informing or consulting the client beforehand.

None of this language was new in 2026. ProPublica reported in May 2019 that a MonsterCloud contract with the police department in Trumann, Arkansas, obtained through a public records request, called the recovery method a trade secret and reserved contact with the attacker for when “all possible means of directly decrypting client’s files have been exhausted.” The same investigation found that MonsterCloud paid ransoms, sometimes without telling victims, and that the main MonsterCloud contact for the Lamar County, Texas, sheriff’s office went by “Zack Green,” a name Pinhasi acknowledged was an alias without saying whose. Pinhasi told ProPublica then that the company does not mislead clients. The indictment’s stated scheme period runs about four more years. For the organizations that hired such a vendor, the sharper risk may be their own legal position rather than the fraud done to them.

Why a hidden payment is a sanctions problem

A ransom payment is a transaction, and U.S. persons are generally prohibited from transacting with parties on the Treasury Department’s sanctions lists. In a Sept. 21, 2021, advisory, Treasury’s Office of Foreign Assets Control (OFAC) said it may impose civil penalties on a strict-liability basis, meaning a person can be held liable even without knowing or having reason to know that a transaction was prohibited. The advisory names digital forensics and incident-response firms, along with cyber insurers and financial institutions, among the companies that facilitate payments for victims and “may risk violating OFAC regulations.” It describes itself as explanatory only and states that it “does not have the force of law.”

The advisory credits two kinds of conduct in particular. One is preparation: OFAC treats security steps such as offline backups and incident response plans as a substantial mitigating factor. The other is disclosure. Where a ransomware payment may have a sanctions nexus, OFAC said it will treat a company’s prompt, self-initiated and complete report of the attack to law enforcement as a voluntary self-disclosure and a mitigating factor of the same weight, and it credits full cooperation that includes handing over the ransom demand and payment instructions. It also asks victims to report ransomware payments to Treasury. A victim can report an attack without knowing a payment occurred, but it cannot report, or hand over the details of, a payment it never learned about. The advisory does not address a payment a vendor made without the victim’s knowledge, and it does not say how OFAC would weigh the victim’s position in that situation.

The MonsterCloud indictment does not allege that any payment reached a sanctioned party. The risk has surfaced before, though. ProPublica’s 2019 investigation traced bitcoin payments from a different recovery firm, Proven Data Recovery, through a chain of addresses to a wallet maintained by the Iranian SamSam attackers, a destination Treasury later barred. In November 2018, OFAC designated two Iran-based financial facilitators and named two virtual currency addresses it linked to moving SamSam proceeds. Proven Data told ProPublica it paid at its clients’ direction and did not know the attackers were linked to Iran. Reporting duties written since then go further, and one of them anticipates exactly the kind of vendor-made payment the MonsterCloud case describes.

Reporting rules and the paying vendor

Since Dec. 1, 2023, a New York State Department of Financial Services (DFS) rule, 23 NYCRR 500.17(c), has required each covered entity, meaning a business operating, or required to operate, under a license, registration, charter or similar authorization under the state’s banking, insurance or financial services laws, to give notice within 24 hours of an extortion payment “made in connection with a cybersecurity event involving the covered entity.” On its face, that trigger turns on the event rather than on who paid. Within 30 days, the entity must explain why payment was necessary and the alternatives it considered, and it must describe “all diligence performed to find alternatives to payment” and “all diligence performed to ensure compliance with applicable rules and regulations including those of the Office of Foreign Assets Control.” The rule took effect after the indictment’s stated scheme period and reaches only DFS-regulated businesses, but it shows what one regulator now expects an affected business to be able to document.

Federal law speaks to the vendor directly. The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) requires a covered entity that makes a ransom payment to report it to the Cybersecurity and Infrastructure Security Agency (CISA) within 24 hours and to preserve data relevant to the payment. When a covered entity uses a third party to pay, the statute says the third party does not file a payment report for itself and the entity’s own duty remains. Any third party that knowingly pays on a covered entity’s behalf “shall advise the impacted covered entity” of its reporting responsibilities. Those reporting duties take effect on dates CISA’s final rule sets, and trade reports said in early October that the final rule had gone to the White House for review.

CIRCIA’s reporting duties were not in force during the alleged scheme and are not in force now. Its design still says something useful: Congress anticipated the vendor-made payment and required the paying vendor to advise the client of its reporting duties, a step that only works if the vendor discloses the payment. The MonsterCloud indictment describes a vendor that, prosecutors say, typically did not disclose its payments, which leaves the client’s own record as the weak point.

Records that outlast the criminal case

For information governance and eDiscovery teams, the allegations point to a potential records gap that may outlast the prosecution. A client’s incident file holds whatever its vendor reported. If the vendor called a purchased key a “recovery tool” and its method a trade secret, then the forensic report, the board briefing and any later statement in litigation can all repeat that account. Where the engagement ran through outside counsel, the inaccurate account may sit inside the privileged file, while the facts that matter, which party was paid, how much and when, sit in the vendor’s own records.

That gap matters in any later proceeding where a payment is at issue, from a data-breach class action to an insurance coverage dispute to a regulator’s inquiry. An organization that cannot produce its own payment record has to rely on the vendor for it, and here prosecutors say the vendor typically did not disclose it. Collection plans for ransomware matters should therefore reach the vendor’s communications and invoices, not only the client’s systems.

Other recent federal cases have also put incident-response insiders in the dock. Two former incident-response employees, identified by BleepingComputer as a Sygnia manager and a DigitalMint negotiator, were each sentenced to four years in prison after pleading guilty to conspiracy to obstruct commerce by extortion for BlackCat ransomware attacks, according to an April 30 Justice Department release. A second former DigitalMint negotiator, Angelo Martino, who prosecutors said fed clients’ confidential negotiating positions to ransomware criminals, was sentenced July 9 to 70 months. Those cases involve extortion rather than fraud, and DigitalMint is not accused of wrongdoing, CyberScoop reported. Taken together with Pinhasi’s case, they show prosecutors examining the intermediaries victims hire, and they make the case for diligence that does not depend on trusting the intermediary.

Building a diligence file that would survive scrutiny

The practical answer is documentation the client controls. Engagement letters can require written notice and written client approval before any contact with or payment to a threat actor, with no carve-out for alternatives the vendor deems exhausted. They can also turn CIRCIA’s advise-the-client duty into a contractual one now, rather than waiting on a final rule. Invoices can break out any ransom as its own line, showing the amount, date, receiving address and the vendor’s sanctions-screening result. Counsel can ask the vendor to state in writing how each decryptor was obtained, a version of the question the indictment says MonsterCloud’s spokesperson asked in 2019.

Organizations should keep those attestations in their own systems under their own retention schedules, because a screening record that lives only on a vendor’s server is one the client may not be able to produce when a regulator, an insurer or opposing counsel asks for it.

“This deception is unacceptable, and the FBI is committed to ensuring accountability for those who choose to victimize the very people who trusted them for help,” FBI Assistant Director in Charge James C. Barnacle Jr. said.

Neither Justice Department release on the MonsterCloud charges announced a trial date. When the next ransomware incident arrives, will the organization’s own file tell the true story of its recovery, including who paid, how much and to whom, or only the story the vendor chose to tell?



News sources



Assisted by GAI and LLM Technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).