MonsterCloud CEO Charged with Fraud and Money Laundering in Ransomware Scheme
Zachary Adam Chesser allegedly secretly paid ransomware attackers while claiming proprietary recovery technology

Key Takeaways
- MonsterCloud CEO Zachary Adam Chesser charged with fraud and money laundering.
- Allegations involve secretly paying ransomware attackers while claiming proprietary recovery technology.
- The scheme occurred over several years and was uncovered through federal charges filed on October 7, 2026.
- The case undermines trust in ransomware recovery services and may have caused victims to pay double.
- Details regarding the number of victims and total financial amount involved have not been independently verified.
Quick answers
- What happened?
- The CEO of ransomware remediation firm MonsterCloud has been charged with fraud and money laundering. Authorities allege that Zachary Adam Chesser secretly paid ransomware attackers to obtain decryptors for victims, while claiming to use proprietary technology to recover their data. The scheme is said to have occurred over several years, undermining trust in ransomware recovery services and potentially causing victims to pay twice.
- What should defenders do?
- Affected parties are advised to seek alternative reputable incident response firms and to report any financial losses to the appropriate authorities. The case highlights the need for due diligence when engaging ransomware recovery services.
Zachary Adam Chesser, chief executive officer of the ransomware remediation company MonsterCloud, has been charged with fraud and money laundering by US authorities. According to the unsealed court documents, Chesser is alleged to have secretly paid ransomware attackers to obtain decryptors for victims, while publicly claiming to use proprietary technology to recover their encrypted data. The alleged scheme occurred over several years and came to light through federal charges filed on October 7, 2026. The case has raised concerns about the integrity of ransomware recovery services and the potential for victims to have paid both the remediation firm and the attackers. The charges were reported by BleepingComputer, which noted that details of the alleged scheme are based on unsealed court documents. Verification of specific financial amounts and the exact number of victims remains pending.
Security Details
The accused allegedly deceived ransomware victims by secretly paying attackers to obtain decryptors while misrepresenting the recovery method as proprietary technology. No active exploitation of systems was involved; the fraud centered on deception of victims and financial misconduct.
Mitigation
Affected parties are advised to seek alternative reputable incident response firms and to report any financial losses to the appropriate authorities. The case highlights the need for due diligence when engaging ransomware recovery services.
Sources
BleepingComputer
Ransomware recovery CEO charged over secret ransom payments
Oct 7, 2026 · 23:04
Original link
Related Security News

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Google reported on October 6, 2026, that threat actors compromised the registry operations of three country-code top-level domains (.gh, .sl, and .as) and obtained unauthorized HTTPS certificates for several Google domains. Google confirmed its own infrastructure was not breached, but any domain ending in these ccTLDs was placed at risk of impersonation. With fraudulent certificates, attackers could execute man-in-the-middle or phishing attacks against end-users visiting affected domains.




