Last Update: 08/01/2026 at 1:00 PM EST

BlackCat Ransomware Insider Misuse

Coverage from BleepingComputer, TechCrunch, and others

Articles

6

Active Days

71

The Topic

BlackCat Ransomware Insider Misuse topic image

Recent U.S. enforcement actions and prison sentences show former ransomware negotiators and incident response workers using insider access to help BlackCat extort victims, leak data, and split ransom proceeds.

First Article: 05/01/26

Latest Article: 07/10/26

Summary

  • Federal cases against former incident response and ransomware negotiation employees dominate the current signal.
  • BlackCat (ALPHV) remains the central ransomware operation, with repeated references to affiliate access, encrypted systems, and threatened data leaks.
  • The conduct described is not just external hacking; it includes insider misuse of cybersecurity roles and sharing victim insurance or negotiation information.
  • Court actions emphasize financial recovery through ransom demands, laundering, and asset seizure, alongside prison sentences for the defendants.
  • The privacy harm pathway is consistent: network intrusion, theft of sensitive data, and coercive pressure to pay to limit exposure.
  • Organizations named in the reporting are mostly U.S. businesses and service providers, including medical, financial, nonprofit, and school-related victims.
  • Some reporting also points to post-case controls, such as tighter negotiation oversight at DigitalMint.

History

07/21/2026

The story has broadened from a narrow sentencing-focused BlackCat matter into a larger enforcement narrative centered on insider misuse by ransomware negotiators and incident response workers. The current version adds a new defendant and frames the cases more explicitly around coordinated extortion, payment-sharing, and data-access abuse.

Featured

Timeline: 71 Days

May 1May 15May 29Jun 12Jun 26Jul 10

Additional Articles

⭐⭐⭐⭐⭐

The Record / Jonathan Greig05-01-2026
Ryan Goldberg and Kevin Martin were sentenced in 2023 ransomware extortion cases tied to ALPHV/BlackCat, using incident response roles and contributing to a patient data leak.

⭐⭐⭐

TechCrunch07-10-2026
U.S. Department of Justice announced Angelo Martino was sentenced for BlackCat ransomware conspiracy while serving as a ransomware negotiator, with cryptocurrency assets seized exceeding $10 million.
The Hacker News05-01-2026
The U.S. Department of Justice announced four-year sentences for Ryan Goldberg and Kevin Martin for BlackCat ransomware facilitation of 2023 attacks across the United States.