Editor’s Note: Zohar Pinhasi, owner of Florida ransomware-recovery firm MonsterCloud, was arraigned Oct. 7 in Brooklyn on federal charges that he told clients he had proprietary decryption tools while secretly paying their attackers. The U.S. Attorney’s Office told BleepingComputer he pleaded not guilty, and the charges are allegations. The case reaches past the fraud counts. According to the indictment, many clients were never told a ransom had been paid, and certain contracts allowed contact with attackers only as a last resort when prosecutors say it was generally the first step.
For cybersecurity and incident-response leaders, that is a vendor diligence problem. For compliance teams, OFAC asks victims to report ransomware payments, New York requires a 24-hour extortion payment notice, and CIRCIA, once its final rule takes effect, will require a paying vendor to advise its client of reporting duties. For information governance and eDiscovery professionals, the client’s own incident file may repeat the vendor’s account while the payment facts sit with the vendor. Watch for CISA’s final CIRCIA rule and the next filings in United States v. Pinhasi.
Content Assessment: MonsterCloud indictment exposes the ransom payment a victim's own file may not record
Information - 94%
Insight - 92%
Relevance - 94%
Objectivity - 92%
Authority - 91%
93%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "MonsterCloud indictment exposes the ransom payment a victim's own file may not record."
News Analysis – Cybersecurity Beat
MonsterCloud indictment exposes the ransom payment a victim’s own file may not record
ComplexDiscovery OÜ Staff
The owner of a Florida ransomware-recovery firm was arraigned Oct. 7 in Brooklyn on charges he told clients he had proprietary decryption tools while secretly paying the criminals who locked their files.
Prosecutors say many of those clients were never told a ransom had been paid. If that holds, the incident files those organizations kept may tell a story about their own recovery that the indictment says is false.
Zohar Pinhasi, 50, of Hollywood, Florida, a U.S. and Israeli national also known as “Zack Silver” and “Zack Green,” owned and ran MonsterCloud LLC, according to the indictment a grand jury in the U.S. District Court for the Eastern District of New York returned Sept. 23. He is charged with one count of conspiracy to commit wire fraud and two counts of wire fraud, and the Justice Department said each count carries a maximum penalty of 20 years.
The court docket shows his first appearance was moved from Sept. 30 to Oct. 7 at his attorney’s request, after the lawyer wrote that Pinhasi was abroad on travel booked before he learned of the indictment, would return voluntarily and had no objection from prosecutors. The U.S. Attorney’s Office told BleepingComputer that Pinhasi surrendered Oct. 7, entered a plea of not guilty and was freed on a $2 million bond, and the docket lists an order setting his conditions of release. BleepingComputer said it had contacted his attorneys, Christopher Clark and Rodney Villazor, and reported no response; ComplexDiscovery did not seek comment from Pinhasi, his counsel or MonsterCloud. The charges are allegations, and Pinhasi is presumed innocent. What the indictment describes is a business built on a promise about how locked files came back.
What the grand jury says MonsterCloud sold
Between about June 2018 and June 2023, the indictment alleges, Pinhasi presented MonsterCloud as a remediation firm armed with “proprietary tools,” steered prospective clients away from paying ransoms and then paid the attackers himself for decryption keys. The company’s website said its team “specializes in helping businesses recover their data without succumbing to ransom demands,” the indictment states. Multiple clients hired the firm because they wanted no money going to a criminal and would not have approved such a payment, according to the grand jury.
The mechanics are specific. MonsterCloud first charged an analysis fee, typically $2,500 to $10,000, and then returned decrypted samples of the client’s files, usually two, as what Pinhasi called “recovery proofs.” In many instances, prosecutors allege, he had sent the samples to the attackers and obtained the decrypted versions from them. He described his methods to clients as “trade secrets” and directed employees and contractors to say “recovery tool” instead of “decryptor,” the indictment says.
The money is where the allegation sharpens. In one case the indictment dates to about August 2023, slightly after the approximate end date it gives for the scheme, Pinhasi allegedly paid about $8,200 and billed the client about $150,000. That is roughly 18 times the ransom, a multiple the indictment describes as “nearly twenty times the cost of the ransom demand.” In October 2021 he allegedly paid about $236,000 and billed about $380,000. Across the scheme, the grand jury counts dozens of ransom payments totaling over $8 million and says hundreds of companies in the United States and Canada paid MonsterCloud over $19 million. That second figure covers every recovery and remediation service those companies bought, so the gap between the two totals is not a measure of the markup.
In May 2019, a paid spokesperson questioned Pinhasi about whether the company owned any proprietary decryption software, the indictment says. He allegedly replied that “MonsterCloud doesn’t hold any Proprietary technology [to] decrypt the ransomware data.”
“As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” U.S. Attorney Joseph Nocella Jr. said. That account turns on what clients were told, and what some of them signed says something narrower.
The contract clause that described the exception
Some MonsterCloud contracts did tell clients that the company might, on occasion, communicate with or pay attackers, the indictment says. Certain contracts added that MonsterCloud would contact a cybercriminal “only once all possible means of directly decrypting Client’s files have been exhausted.” Prosecutors allege that dealing with the criminals was generally Pinhasi’s first step rather than his last.
A client relying on that language had paper. What it lacked was evidence of practice, because a promise that contact happens only under stated conditions tells an organization nothing about whether those conditions were ever met. The indictment alleges that in many cases Pinhasi paid without informing or consulting the client beforehand.
None of this language was new in 2026. ProPublica reported in May 2019 that a MonsterCloud contract with the police department in Trumann, Arkansas, obtained through a public records request, called the recovery method a trade secret and reserved contact with the attacker for when “all possible means of directly decrypting client’s files have been exhausted.” The same investigation found that MonsterCloud paid ransoms, sometimes without telling victims, and that the main MonsterCloud contact for the Lamar County, Texas, sheriff’s office went by “Zack Green,” a name Pinhasi acknowledged was an alias without saying whose. Pinhasi told ProPublica then that the company does not mislead clients. The indictment’s stated scheme period runs about four more years. For the organizations that hired such a vendor, the sharper risk may be their own legal position rather than the fraud done to them.
Why a hidden payment is a sanctions problem
A ransom payment is a transaction, and U.S. persons are generally prohibited from transacting with parties on the Treasury Department’s sanctions lists. In a Sept. 21, 2021, advisory, Treasury’s Office of Foreign Assets Control (OFAC) said it may impose civil penalties on a strict-liability basis, meaning a person can be held liable even without knowing or having reason to know that a transaction was prohibited. The advisory names digital forensics and incident-response firms, along with cyber insurers and financial institutions, among the companies that facilitate payments for victims and “may risk violating OFAC regulations.” It describes itself as explanatory only and states that it “does not have the force of law.”
The advisory credits two kinds of conduct in particular. One is preparation: OFAC treats security steps such as offline backups and incident response plans as a substantial mitigating factor. The other is disclosure. Where a ransomware payment may have a sanctions nexus, OFAC said it will treat a company’s prompt, self-initiated and complete report of the attack to law enforcement as a voluntary self-disclosure and a mitigating factor of the same weight, and it credits full cooperation that includes handing over the ransom demand and payment instructions. It also asks victims to report ransomware payments to Treasury. A victim can report an attack without knowing a payment occurred, but it cannot report, or hand over the details of, a payment it never learned about. The advisory does not address a payment a vendor made without the victim’s knowledge, and it does not say how OFAC would weigh the victim’s position in that situation.
The MonsterCloud indictment does not allege that any payment reached a sanctioned party. The risk has surfaced before, though. ProPublica’s 2019 investigation traced bitcoin payments from a different recovery firm, Proven Data Recovery, through a chain of addresses to a wallet maintained by the Iranian SamSam attackers, a destination Treasury later barred. In November 2018, OFAC designated two Iran-based financial facilitators and named two virtual currency addresses it linked to moving SamSam proceeds. Proven Data told ProPublica it paid at its clients’ direction and did not know the attackers were linked to Iran. Reporting duties written since then go further, and one of them anticipates exactly the kind of vendor-made payment the MonsterCloud case describes.
Reporting rules and the paying vendor
Since Dec. 1, 2023, a New York State Department of Financial Services (DFS) rule, 23 NYCRR 500.17(c), has required each covered entity, meaning a business operating, or required to operate, under a license, registration, charter or similar authorization under the state’s banking, insurance or financial services laws, to give notice within 24 hours of an extortion payment “made in connection with a cybersecurity event involving the covered entity.” On its face, that trigger turns on the event rather than on who paid. Within 30 days, the entity must explain why payment was necessary and the alternatives it considered, and it must describe “all diligence performed to find alternatives to payment” and “all diligence performed to ensure compliance with applicable rules and regulations including those of the Office of Foreign Assets Control.” The rule took effect after the indictment’s stated scheme period and reaches only DFS-regulated businesses, but it shows what one regulator now expects an affected business to be able to document.
Federal law speaks to the vendor directly. The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) requires a covered entity that makes a ransom payment to report it to the Cybersecurity and Infrastructure Security Agency (CISA) within 24 hours and to preserve data relevant to the payment. When a covered entity uses a third party to pay, the statute says the third party does not file a payment report for itself and the entity’s own duty remains. Any third party that knowingly pays on a covered entity’s behalf “shall advise the impacted covered entity” of its reporting responsibilities. Those reporting duties take effect on dates CISA’s final rule sets, and trade reports said in early October that the final rule had gone to the White House for review.
CIRCIA’s reporting duties were not in force during the alleged scheme and are not in force now. Its design still says something useful: Congress anticipated the vendor-made payment and required the paying vendor to advise the client of its reporting duties, a step that only works if the vendor discloses the payment. The MonsterCloud indictment describes a vendor that, prosecutors say, typically did not disclose its payments, which leaves the client’s own record as the weak point.
Records that outlast the criminal case
For information governance and eDiscovery teams, the allegations point to a potential records gap that may outlast the prosecution. A client’s incident file holds whatever its vendor reported. If the vendor called a purchased key a “recovery tool” and its method a trade secret, then the forensic report, the board briefing and any later statement in litigation can all repeat that account. Where the engagement ran through outside counsel, the inaccurate account may sit inside the privileged file, while the facts that matter, which party was paid, how much and when, sit in the vendor’s own records.
That gap matters in any later proceeding where a payment is at issue, from a data-breach class action to an insurance coverage dispute to a regulator’s inquiry. An organization that cannot produce its own payment record has to rely on the vendor for it, and here prosecutors say the vendor typically did not disclose it. Collection plans for ransomware matters should therefore reach the vendor’s communications and invoices, not only the client’s systems.
Other recent federal cases have also put incident-response insiders in the dock. Two former incident-response employees, identified by BleepingComputer as a Sygnia manager and a DigitalMint negotiator, were each sentenced to four years in prison after pleading guilty to conspiracy to obstruct commerce by extortion for BlackCat ransomware attacks, according to an April 30 Justice Department release. A second former DigitalMint negotiator, Angelo Martino, who prosecutors said fed clients’ confidential negotiating positions to ransomware criminals, was sentenced July 9 to 70 months. Those cases involve extortion rather than fraud, and DigitalMint is not accused of wrongdoing, CyberScoop reported. Taken together with Pinhasi’s case, they show prosecutors examining the intermediaries victims hire, and they make the case for diligence that does not depend on trusting the intermediary.
Building a diligence file that would survive scrutiny
The practical answer is documentation the client controls. Engagement letters can require written notice and written client approval before any contact with or payment to a threat actor, with no carve-out for alternatives the vendor deems exhausted. They can also turn CIRCIA’s advise-the-client duty into a contractual one now, rather than waiting on a final rule. Invoices can break out any ransom as its own line, showing the amount, date, receiving address and the vendor’s sanctions-screening result. Counsel can ask the vendor to state in writing how each decryptor was obtained, a version of the question the indictment says MonsterCloud’s spokesperson asked in 2019.
Organizations should keep those attestations in their own systems under their own retention schedules, because a screening record that lives only on a vendor’s server is one the client may not be able to produce when a regulator, an insurer or opposing counsel asks for it.
“This deception is unacceptable, and the FBI is committed to ensuring accountability for those who choose to victimize the very people who trusted them for help,” FBI Assistant Director in Charge James C. Barnacle Jr. said.
Neither Justice Department release on the MonsterCloud charges announced a trial date. When the next ransomware incident arrives, will the organization’s own file tell the true story of its recovery, including who paid, how much and to whom, or only the story the vendor chose to tell?

News sources
- Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients (U.S. Attorney’s Office, Eastern District of New York)
- Known Cybersecurity Expert and Owner of Florida Ransomware Remediation Company Charged with Defrauding Clients (Department of Justice, Office of Public Affairs)
- Indictment, United States v. Zohar Pinhasi, No. 26-CR-271 (E.D.N.Y.) (U.S. Attorney’s Office, Eastern District of New York)
- United States v. Pinhasi, 1:26-cr-00271 (CourtListener docket, U.S. District Court for the Eastern District of New York)
- Letter Requesting an Adjournment of Initial Appearance and Bond Hearing, ECF No. 9 (Clark Smith Villazor LLP via CourtListener)
- Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (U.S. Department of the Treasury, Office of Foreign Assets Control)
- Y. Comp. Codes R. & Regs. Tit. 23 § 500.17: Notices to Superintendent (Legal Information Institute)
- Y. Comp. Codes R. & Regs. Tit. 23 § 500.22: Transitional Periods (Legal Information Institute)
- Y. Comp. Codes R. & Regs. Tit. 23 § 500.1: Definitions (Legal Information Institute)
- 6 U.S. Code § 681b: Required reporting of certain cyber incidents (Legal Information Institute)
- The Trade Secret: Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers (ProPublica)
- Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison (Department of Justice, Office of Public Affairs)
- Florida Ransomware Negotiator Who Extorted and Attacked Multiple U.S. Victims Sentenced to Prison (Department of Justice, Office of Public Affairs)
- Ransomware recovery CEO charged over secret ransom payments (BleepingComputer)
- US ransomware negotiators get 4 years in prison over BlackCat attacks (BleepingComputer)
- Former DigitalMint ransomware negotiator pleads guilty to extortion scheme (CyberScoop)
- CISA Sends CIRCIA Final Rule for White House Review (HIPAA Journal)
Assisted by GAI and LLM Technologies
Additional reading
- Wikimedia publishes its own account of suspected OpenAI agent activity on its wikis
- Cyber Law Toolkit tests AI deception, cyber torture and peacetime cyber duties
- ENISA Threat Landscape 2026 finds DDoS leads incident counts while ransomware stays most impactful in the short term
- Cyber Resilience Act reporting starts Sept. 11 on an unfinished platform
- Europe’s draft cloud rule would put vendor ownership in the audit file
- The eight-hour clock starts today: EU e-evidence orders now land on covered U.S. providers’ EU addressees
- California’s AI Transparency Act arrives alongside Europe’s Article 50
- Federal magistrate judge treats LinkedIn’s Relativity aiR workflow as TAR
- One benchmark, three directions: 2026 legal rates rise, flatten and fall at once
- Confidence cools, commitment holds: full results from the 1H 2026 eDiscovery Business Confidence Survey
- Complete look: ComplexDiscovery OÜ’s 2025 to 2030 eDiscovery market size mashup
- The workstream of eDiscovery: Considering processes and tasks
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.



























