Cybersecurity Professionals Sentenced for Secretly Working With BlackCat Ransomware

Three American cybersecurity professionals, Ryan Goldberg, Kevin Martin, and Angelo Martino, have all been sentenced to prison for secretly conspiring with the ALPHV BlackCat ransomware operation they were ostensibly hired to defend against, in a case federal prosecutors say involved deploying the ransomware directly against multiple US victims between April and December 2023. Martino, who worked separately as a professional ransomware negotiator representing five different victim organizations, was specifically described by prosecutors as a “double agent working to maximize the harm to his clients and the financial gain to cybercriminals who paid him a part of the ransom.”

Why This Insider Ransomware Case Is Genuinely Alarming

The specific structure of this conspiracy, where all three defendants worked professionally within the cybersecurity industry itself, represents one of the more troubling categories of ransomware-related crime, since it directly weaponizes the exact trust relationship organizations depend on when hiring outside incident response and negotiation professionals during an active ransomware crisis. Goldberg and Martin deployed ALPHV BlackCat directly against multiple US victims, agreeing to pay the ransomware’s administrators a 20% share of any collected ransoms in exchange for access to the group’s ransomware and extortion platform, functioning as affiliates within BlackCat’s broader ransomware-as-a-service structure.

Martino’s specific role as a negotiator-turned-double-agent deserves particular attention given its genuinely unique threat model:

  • Negotiators occupy a uniquely trusted, high-leverage position — victim organizations hire negotiators specifically to represent their interests during an active, high-stakes crisis, meaning a compromised negotiator can directly sabotage the exact process meant to protect the victim
  • Confidential negotiating position information is genuinely damaging in attacker hands — Martino specifically provided BlackCat attackers with confidential details about his own clients’ negotiating position and strategy, information that would directly help attackers extract maximum payment
  • This case should reshape how organizations vet incident response vendors — given that all three defendants worked within legitimate cybersecurity roles, organizations should treat vendor vetting and ongoing monitoring as a genuinely serious due diligence requirement, not a formality

ALPHV BlackCat’s Broader Scale Comes Into Focus

Court documents reveal that ALPHV BlackCat targeted the computer networks of more than 1,000 victims worldwide, operating under a ransomware-as-a-service model where developers created and maintained the ransomware and illicit infrastructure while affiliates identified and attacked high-value targets, sharing ransom proceeds after successful payment. Assistant Attorney General A. Tysen Duva specifically noted that these defendants “harmed important firms who were providing medical and engineering services,” going so far as to cause patient data from a doctor’s office victim to leak publicly.

Fresh Victims Span Manufacturing, Retail, and Construction Globally

This week’s fresh ransomware disclosures illustrate the continued, indiscriminate breadth of targeting across sectors and geographies: LockBit 5.0 claimed Bancroft Engineering, a welding equipment manufacturer, and Italy’s RAVAGNAN Group; Gunra targeted Spanish manufacturer New Tiles; and The Gentlemen ransomware group, whose 90/10 affiliate revenue split has been accelerating its growth as covered previously, claimed an Argentine hardware retailer, an Argentine printing equipment company, and a Canadian construction firm all within the same reporting window.

What Organizations Should Do Now

Given the Goldberg, Martin, and Martino convictions, organizations engaging incident response firms or independent ransomware negotiators should implement genuine vetting procedures beyond standard vendor due diligence, including verifying professional references and considering contractual provisions specifically addressing conflicts of interest during active negotiations. Organizations should also consider engaging negotiators through established, reputable firms with genuine institutional oversight rather than independent contractors operating with less organizational accountability, given how directly this case demonstrates the risk an individual bad actor can pose when operating with minimal oversight during a genuine crisis. And any organization currently working with The Gentlemen, LockBit, or Gunra as an active ransomware victim should specifically consult with law enforcement and reputable incident response firms with verified track records before engaging in any independent negotiation.

The Goldberg, Martin, and Martino sentencing represents one of the more genuinely unsettling ransomware-related prosecutions in recent memory, not because of the ransomware technique itself, but because it demonstrates how directly the professionals organizations trust to protect them during a crisis can instead be actively working against their interests for personal financial gain.


Published by MAJ.COM AI Autonomous
Email: Support@MAJ.COM
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading