Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Two US Cybersecurity Pros Plead Guilty Over Ransomware Attacks

Ryan Goldberg and Kevin Martin have admitted being affiliates of the BlackCat/Alphv ransomware group.

BlackCat ransomware

Two cybersecurity professionals from the United States have pleaded guilty to charges related to their role in BlackCat/Alphv ransomware attacks, the Justice Department announced this week.

Three individuals were charged in October for allegedly conducting ransomware attacks against several US-based companies. Two of the suspects, 36-year-old Kevin Martin from Texas and an unnamed individual, were employed as ransomware negotiators at threat intelligence and incident response firm DigitalMint.

The third suspect, 40-year-old Ryan Goldberg from Georgia, worked as an incident response manager at cybersecurity company Sygnia.

The three are accused of hacking into the systems of several companies, stealing valuable information, and deploying BlackCat ransomware. 

Based on the Justice Department’s description of the scheme, the suspects were BlackCat ransomware affiliates, paying 20% of the ransoms they received from victims to the administrators of the ransomware operation in exchange for access to the file-encrypting malware and a platform designed for managing extortions.

According to the DOJ, the three men received a ransom of $1.2 million in Bitcoin from one victim.

Advertisement. Scroll to continue reading.

Goldberg and Martin have each pleaded guilty to conspiracy to commit extortion for their roles in crippling business operations through the use of ransomware. They face up to 20 years in prison, with sentencing scheduled for March 12, 2026. 

More than 1,000 organizations were targeted in the BlackCat ransomware operation between November 2021 and December 2023, when the cybercrime enterprise was disrupted as part of a law enforcement action. The cybercriminals continued to operate for a few more months until they received a $22 million ransom from Change Healthcare, and they pulled an exit scam.

The United States has been offering a $10 million reward since early 2024 for information on key members of the BlackCat ransomware group, but no charges have been announced to date.

The announcement of the Goldberg and Martin guilty pleas came just days after Ukrainian national Artem Stryzhak pleaded guilty in a US court to charges related to his role as a Nefilim ransomware affiliate.

Related: Ransomware Payments Surpassed $4.5 Billion: US Treasury

Related: Feds Seize Password Database Used in Massive Bank Account Takeover Scheme

Related: ATM Hackers Using ‘Ploutus’ Malware Charged in US

Related: Third DraftKings Hacker Pleads Guilty

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.