October 8, 2026

Ransomware Recovery Firm Accused of Defrauding Clients: Why Cyber Incident Response Requires Due Diligence

Ransomware Recovery Firm Accused of Defrauding Clients: Why Cyber Incident Response Requires Due Diligence

The owner of a Florida ransomware remediation company has been charged with wire fraud after allegedly misleading businesses about how his company recovered data following cyberattacks.

The U.S. Department of Justice announced on October 7, 2026 that Zohar Pinhasi, also known as Zack Silver and Zack Green, had been arraigned in the Eastern District of New York on charges relating to his operation of MonsterCloud LLC.

According to prosecutors, Pinhasi represented to clients that MonsterCloud could recover encrypted data without paying cybercriminals.

The company allegedly promoted the use of proprietary tools and advanced decryption techniques as an alternative to paying ransomware demands.

However, the Department of Justice alleges that Pinhasi had no special technology capable of decrypting the affected systems.

Instead, prosecutors say he contacted the cybercriminals responsible for the ransomware attacks, paid them for decryption keys and charged clients substantially more than the ransom payments themselves.

Over the course of the alleged scheme, MonsterCloud is said to have charged clients more than $19 million while paying more than $8 million in ransom payments.

The charges remain allegations and Pinhasi is presumed innocent unless and until proven guilty.

For businesses, the case highlights an important issue that can arise during a cyber incident.

When systems are inaccessible, operations are disrupted and sensitive information may be at risk, organizations can be under intense pressure to appoint external specialists quickly.

That urgency should not remove the need for appropriate due diligence.

Why Cyber Incidents Create a Vulnerable Decision-Making Environment

Ransomware attacks can create immediate operational pressure.

Employees may be unable to access files.

Customer services may be interrupted.

Production systems can become unavailable.

Sensitive information may also have been copied or exposed.

The priority is understandably to restore operations as quickly as possible.

That environment can make businesses particularly dependent on external specialists.

A cybersecurity provider may be trusted to assess the attack, identify the ransomware involved, advise on recovery options and potentially negotiate with the threat actor.

Clients may have limited ability to independently assess the technical claims being made.

This imbalance of information can create risk.

The MonsterCloud case is notable because prosecutors allege the company publicly positioned itself as an alternative to ransom payments while privately paying the attackers responsible for the incidents.

According to the indictment, clients therefore may not have understood what was actually happening during their recovery process.

The Difference Between Recovery and Verification

An organization experiencing ransomware understandably wants one thing first: to regain access to its systems.

But restoration alone does not necessarily answer all the questions created by an incident.

Businesses may also need to understand:

  • How the attackers gained access.
  • Whether the vulnerability remains open.
  • Whether data was copied before encryption.
  • Whether credentials were compromised.
  • What actions were taken by the recovery provider.
  • Whether payments were made to third parties.
  • Whether evidence has been preserved.
  • Whether the threat actor still has access to the environment.

A system appearing to function again does not necessarily mean the underlying incident has been fully resolved.

This is particularly important in modern ransomware cases, where attackers may steal data before encrypting systems.

The recovery of encrypted files may therefore address only one part of the problem.

Due Diligence on Cybersecurity Providers

Businesses often carry out checks before appointing accountants, lawyers, financial advisers and other important professional providers.

Cybersecurity specialists should also be subject to proportionate verification, particularly where they will have access to sensitive systems or will be making decisions involving significant financial or operational risk.

Checks may include:

  • Verifying the legal entity providing the service.
  • Establishing the background of key individuals.
  • Reviewing relevant professional experience.
  • Understanding exactly what services will be provided.
  • Clarifying how third parties may be involved.
  • Reviewing contractual terms and payment arrangements.
  • Establishing how evidence and confidential information will be handled.
  • Confirming how significant decisions will be documented.

The level of due diligence should reflect the sensitivity of the appointment.

A provider responding to a major ransomware incident may have access to some of an organization's most sensitive data and infrastructure.

That relationship can justify a higher level of scrutiny than an ordinary technology supplier.

Conflict International USA provides Due Diligence support to organizations requiring a clearer understanding of companies, individuals and commercial relationships before important decisions are made.

Transparency Matters During Ransomware Recovery

According to the Department of Justice, MonsterCloud allegedly represented that it could recover data without paying ransomware operators.

Prosecutors say the reality was different.

In one example cited by the government, Pinhasi allegedly paid approximately $8,200 to a cybercriminal in August 2023 while charging the affected client approximately $150,000.

The wider alleged scheme involved more than $8 million in ransom payments and over $19 million in client charges.

For businesses appointing an incident-response provider, this illustrates the importance of transparency around both methods and costs.

Clients should understand, as far as reasonably possible:

  • What recovery approach is being proposed.
  • Whether outside parties will be contacted.
  • Whether any ransom payment is being contemplated.
  • What fees the provider will charge.
  • What evidence will be retained.
  • What risks remain after restoration.

Cyber incidents are often complicated and the appropriate response will depend on the circumstances.

But significant decisions should not become opaque simply because the business is under pressure.

Ransomware Payments Carry Wider Risks

The FBI and the Cybersecurity and Infrastructure Security Agency do not recommend paying ransom demands.

Payment does not guarantee that encrypted data will be successfully recovered.

It also does not guarantee that attackers will delete information they may have stolen or that compromised systems are secure.

There can also be legal and compliance considerations associated with payments to cybercriminal groups.

For organizations affected by ransomware, decisions therefore need to take account of more than the immediate cost of restoring files.

Legal advice, forensic assessment and appropriate incident-response expertise may all be required.

Conflict International USA's Cyber Security support can help organizations assess cyber risk and respond appropriately to incidents involving compromised systems, digital evidence and potential data exposure.

Preserving Evidence During a Cyber Incident

One of the risks during urgent recovery work is that evidence may be altered or lost.

Logs may be overwritten.

Devices may be rebuilt.

Systems may be restored without retaining information that could later help establish how the attack occurred.

Where fraud, extortion or other criminal activity is suspected, preserving relevant digital evidence can become particularly important.

That evidence may assist internal investigations, legal proceedings, insurance claims or law-enforcement enquiries.

Organizations should therefore consider evidence preservation as part of the incident-response process rather than treating recovery and investigation as completely separate issues.

The objective is not to delay restoration unnecessarily.

It is to ensure that the response does not destroy information that may later become important.

Supplier Risk Becomes More Important During a Crisis

The MonsterCloud allegations also illustrate a broader commercial lesson.

Organizations often carry out significant due diligence when selecting long-term strategic suppliers.

But during an emergency, normal procurement processes can become compressed.

A business affected by ransomware may appoint a provider it has never previously worked with because systems need immediate attention.

That urgency can make supplier verification more important, not less.

Before granting a third party access to systems, sensitive information or significant funds, businesses should establish who they are dealing with and understand the scope of the proposed engagement.

This principle applies not only to cybersecurity.

It is relevant whenever a company appoints an unfamiliar adviser or specialist during a crisis.

The Wider Lesson for US Businesses

The allegations against MonsterCloud remain to be tested in court.

However, the case provides a useful illustration of the risks businesses can face when appointing specialist providers during a high-pressure cyber incident.

A company dealing with ransomware may already have been targeted by criminals once.

It should not become unnecessarily exposed to additional financial or operational risk during the recovery process.

Organizations cannot remove all uncertainty from a cyber incident.

They can, however, take steps to understand who they are appointing, what the provider intends to do and how significant decisions will be made.

Strong cyber incident response therefore requires more than technical expertise.

It also requires transparency, appropriate verification and clear accountability.

For businesses, law firms and professional advisers requiring support with cyber incidents, digital evidence, due diligence or complex commercial enquiries, Conflict International USA can provide discreet assistance in the United States and internationally.

Get a quote today!

Can we help you? Contact us in confidence. We are always happy to help and give you an indication of how we may be able to assist.

Please provide a brief background to your case and the reasons for initiating an investigation.

What is your required outcome? (e.g. Asset Identification, Litigation Support, Due Diligence, or Risk Mitigation).

Please define your relationship to the person or entity of interest (e.g. Legal Counsel, Business Partner, Family Member, or Victim of Fraud).

Please list any specific details you currently possess, such as names, addresses, or any other known details which may assist.

Need our help?
Get a free consultation today.

Get started
© 2026 Conflict International · Privacy Policy · Cookie Policy · Website by ghostwhite