Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Two Cybersecurity Workers Jailed for BlackCat Ransomware Attacks

May 1, 2026

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

May 1, 2026

Anthropic Rolls Out Claude Security for AI Vulnerability Scanning

May 1, 2026
Facebook X (Twitter) Instagram
Friday, May 1
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Two Cybersecurity Workers Jailed for BlackCat Ransomware Attacks
News

Two Cybersecurity Workers Jailed for BlackCat Ransomware Attacks

Team-CWDBy Team-CWDMay 1, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Two American cybersecurity workers have been sentenced to jail for helping the BlackCat ransomware gang conduct attacks against multiple organizations in the US.

Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas were each sentenced to four years in prison for their roles in facilitating ransomware attacks during 2023, the US Department of Justice said in a statement published on April 30.

Goldberg and Martin pleaded guilty to the charges in December 2025.

The two men worked alongside, Angelo Martino, 41, of Florida, who pleaded guilty to working for BlackCat on April 20. The former ransomware negotiator is set to be sentenced in July.

The BlackCat ransomware operation, also known as ALPHV, first emerged in 2021. Between 2022 and 2024, it was one of the most active and notorious ransomware groups targeting victims globally.

Attackers regularly demanded millions of dollars in ransom payments for decryption keys. BlackCat members also used double-extortion tactics and leaked stolen data from victims who refused to pay.

Cybersecurity Staff Worked for Cybercriminals

According to court documents, Goldberg and Martin helped launch ransomware attacks against a range of victims and paid BlackCat administrators a 20% share of any ransom payments they received.

In one case, Goldberg, Martin and Martino received a Bitcoin ransom worth $1.2m, sharing 20% with BlackCat, while they split the remaining 80% between themselves.

In another attack, the former cybersecurity workers leaked patient data from a victim in the healthcare industry.

Prosecutors condemned the men for how they used the specialist skills they had acquired working in the cybersecurity industry to actively commit the harm that they were supposed to protect victims against.  

“These were supposed to be cybersecurity specialists who did good and helped businesses and people. Instead, they used their high-level cyber skills to feed their greed,” said assistant attorney general A. Tysen Duva of the US Justice Department.

“Ransomware attackers like this should be punished and removed from society to serve their lawful sentences so they cannot harm others,” he added.

Prior to being detained by the FBI, Goldberg had tried to flee, but agents tracked him across ten countries to capture him.

“Today’s sentencings show that ransomware criminals can operate anywhere, including right here in the United States, and that the FBI is actively working to track them down and dismantle their networks — wherever they exist,” said assistant director Brett Leatherman of the FBI’s cyber division

“Goldberg and Martin leveraged their technical skills and cyber security knowledge to extort millions from victims across the U.S., but the FBI’s global reach ensured that they ultimately faced justice,” he added.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMalicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Team-CWD
  • Website

Related Posts

News

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

May 1, 2026
News

Anthropic Rolls Out Claude Security for AI Vulnerability Scanning

May 1, 2026
News

Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens

May 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Don’t let “back to school” become “back to bullying”

September 11, 2025

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Watch out for SVG files booby-trapped with malware

September 22, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.