INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Two Cybersecurity Professionals Sentenced for BlackCat Ransomware Attacks

| 2026-05-01 09:56 HIGH LOW RANSOMWARE & EXTORTION DATA BREACH LAW ENFORCEMENT
Executive Summary
AI-generated
In 2023, Ryan Goldberg and Kevin Martin deployed the BlackCat ransomware against multiple victims located throughout the United States between April and December. The two cybersecurity professionals conspired with Angelo Martino to conduct the attacks, agreeing to pay a 20% share of any ransoms received in exchange for access to the ransomware and its extortion platform. They successfully extorted a victim for approximately $1.2 million in Bitcoin, laundering the funds to cover up their tracks. The BlackCat ransomware-as-a-service scheme targeted over 1,000 victims worldwide, with Goldberg working as an incident response manager for Sygnia and Martino employed by DigitalMint. Two cybersecurity professionals were later sentenced to four years each in prison for their role in facilitating these attacks, which exploited specialized cybersecurity knowledge not to protect victims but to extort them using ransomware to lock down critical systems and steal sensitive data.
Technical Mitigations AI-generated
• Block or hunt for indicators of ALPHV/BlackCat's extortion platform, such as suspicious Bitcoin transactions. • Patch systems against the BlackCat ransomware-as-a-service (RaaS) scheme by applying updates to prevent exploitation. • Detect and monitor for signs of abuse of confidential information about insurance policy limits shared with BlackCat operators.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ALPHVALPHVBlackCatBlackCat
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎December 2025
The three men agreed to pay the ALPHV BlackCat administrators a 20% share of any ransoms received in exchange for access to the ransomware and ALPHV/BlackCat's extortion platform.
victims 1,000 victims
Tactical Metrics
Metrics
victims
1,000
Victims
Intelligence Sources