American cybersecurity professionals plead guilty to ALPHV/BlackCat ransomware attacks

31.12.2025 2 minutes Author: Newsman

Two U.S.-based cybersecurity professionals have formally admitted their involvement in ransomware attacks linked to ALPHV/BlackCat. According to federal investigators, the defendants abused their incident response expertise to breach corporate networks and extort multimillion-dollar ransom payments from victims across the United States.

A federal judge in the Southern District of Florida accepted the guilty pleas of Ryan Goldberg and Kevin Martin, who operated as ALPHV/BlackCat affiliates throughout 2023. Both individuals previously held trusted positions in cybersecurity and incident response firms, giving them detailed knowledge of enterprise defense mechanisms.

Investigators revealed that the pair deployed BlackCat 2.0 ransomware against multiple organizations, including a medical device manufacturer that paid a $1.2 million ransom. Several additional extortion attempts targeted companies in healthcare, engineering, and manufacturing sectors, with ransom demands ranging from hundreds of thousands to several million dollars.

The illicit proceeds were split among the conspirators and ALPHV administrators, with approximately 20% allocated to the core operators. Laundering techniques involving cryptocurrency transactions were used to obscure financial trails.

ALPHV/BlackCat operated as a ransomware-as-a-service platform, supplying malware and infrastructure to affiliates worldwide. In December 2023, the Federal Bureau of Investigation seized parts of the group’s darknet infrastructure and later released a free decryption tool, helping hundreds of victims recover encrypted data.

Court documents estimate that the group targeted more than 1,000 organizations globally during its active period, generating tens of millions of dollars in criminal revenue.

The case highlights a troubling trend where trusted cybersecurity professionals turn into threat actors, leveraging insider knowledge to bypass defenses. It underscores the growing complexity of the ransomware landscape and the risks posed by abuse of professional expertise.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.