Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationinsider-threat-incidentenforcement-actionhealthcare-sector-threat

Insider Ransomware Attacks by Cybersecurity Professionals Using BlackCat

Updated 3mo agoFirst seen Nov 3, 202511 sources

Three former employees of cybersecurity firms DigitalMint and Sygnia have been indicted for orchestrating a series of BlackCat (ALPHV) ransomware attacks against five U.S. companies between May and November 2023. The accused, including Kevin Tyler Martin and Ryan Clifford Goldberg, allegedly abused their positions as incident response professionals to gain unauthorized access to victim networks, deploy ransomware, steal sensitive data, and demand cryptocurrency ransoms ranging from $300,000 to $10 million. The Department of Justice and FBI state that the group operated as BlackCat affiliates, with at least one successful extortion resulting in a $1.27 million payment from a Tampa medical device manufacturer after its servers were encrypted.

The indictment details additional targets, including a Maryland pharmaceutical company, a California doctor's office, a California engineering firm, and a Virginia drone manufacturer, though it is unclear if further ransom payments were made. DigitalMint and Sygnia have both denied organizational involvement, terminated the implicated employees, and are cooperating with law enforcement. The case highlights the risk of insider threats within cybersecurity firms and the sophisticated tactics used by ransomware operators to exploit trusted access for criminal gain.

Share:
Insider Ransomware Attacks by Cybersecurity Professionals Using BlackCat
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Nov 5, 20258mo ago

DigitalMint denies involvement and says it cooperated

DigitalMint publicly denied any role in the attacks and said it cooperated with law enforcement after the case became public.

Martin pleads not guilty in federal court

Following the indictment, Kevin Tyler Martin pleaded not guilty to the federal charges tied to the alleged ransomware and extortion campaign.

Nov 3, 20258mo ago

U.S. prosecutors indict former cyber professionals

The U.S. Department of Justice unsealed charges against Ryan Clifford Goldberg and Kevin Tyler Martin, alleging they used insider access and expertise from firms including Sygnia and DigitalMint to conduct BlackCat ransomware attacks and extortion.

Nov 2, 20258mo ago

Goldberg is arrested in Mexico City after attempted flight

According to later reporting, Goldberg tried to flee to Europe but was apprehended in Mexico City as authorities moved against the group.

FBI investigation identifies suspects and obtains confession

The FBI traced the alleged operation, including cryptocurrency laundering through wallets and mixers, and obtained admissions from Ryan Clifford Goldberg, who reportedly said he joined the scheme because of debt.

Apr 1, 20251y ago

Alleged scheme continues until April 2025

Court filings and later reporting say the conspiracy remained active through April 2025, even though no additional victims after 2023 were publicly named in the referenced coverage.

Dec 31, 20232y ago

Attack campaign expands to five U.S. companies

Across 2023, the accused allegedly targeted at least five U.S. companies in multiple states, stealing data, deploying BlackCat ransomware, and demanding between $300,000 and $10 million. Prosecutors say only one victim paid, while the other extortion attempts failed.

Dec 1, 20233y ago

International operation seizes ALPHV/BlackCat servers

U.S. and European law enforcement partners seized ALPHV/BlackCat infrastructure in December 2023. Later reporting said evidence from that disruption may have helped investigators identify the suspects.

May 1, 20233y ago

Florida medical company pays $1.27 million ransom

In the first successful extortion case, the group allegedly attacked a Tampa-area Florida medical company and secured a cryptocurrency ransom payment of about $1.27 million after an initial demand reportedly reached as high as $10 million.

BlackCat affiliates begin targeting U.S. companies

Federal prosecutors allege three Florida men, including cybersecurity professionals employed in incident response and ransomware negotiation roles, began a string of ALPHV/BlackCat ransomware attacks against U.S. companies in May 2023.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

82 LINKEDOpen in app
Affected products
12 linked
FacebookAndroidTelegramWindowsWhatsappInstagramTiktokWordpressLinux KernelGmailLinux KernelAlpine Linux
Organizations
47 linked
DigitalMintSygniafbiALPHV/BlackCatUS Attorney’s OfficeU.S. Department of JusticeCheck Point Software TechnologiesAcronisSublime SecurityJfrogUnitedHealth GroupZscalerTechCrunchTrenchantCybereasonKELAOpen MeasuresOperation ZeroSPLXAdvanced Micro DevicesBugcrowdMeta PlatformsTrustwaveCrowdStrikeBlackCat ransomwareReliaQuestOpenaiSnapXAppleProofpointMicrosoft CorporationRedditSuperGroszSK TelecomBloombergBitdefenderMayhem SecurityBalancer LabsAbnormal AIIANS ResearchGoogleKickChicago Sun-TimesRKONOut of BoundsScaleSec
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Insider Ransomware Attacks by Cybersecurity Professionals Using BlackCat | Mallory