Two U.S. Cybersecurity Professionals Plead Guilty to Acting as ALPHV/BlackCat Affiliates
A federal district court in the Southern District of Florida has accepted guilty pleas from two cybersecurity professionals, Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas. They admitted to conspiring to obstruct commerce through extortion…
A federal district court in the Southern District of Florida has accepted guilty pleas from two cybersecurity professionals, Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas. They admitted to conspiring to obstruct commerce through extortion in connection with ransomware attacks conducted throughout 2023.
The defendants utilized their cybersecurity expertise to deploy ALPHV BlackCat ransomware against multiple victims across the United States between April and December 2023. They operated as affiliates within the ransomware-as-a-service model, agreeing to pay ALPHV BlackCat administrators a 20% share of ransom proceeds in exchange for access to the ransomware and extortion infrastructure.
The group successfully extorted approximately $1.2 million in Bitcoin from one victim, dividing their 80% share three ways and laundering the cryptocurrency through various channels. Their cybersecurity backgrounds provided them with specialized knowledge of network defenses and vulnerabilities, which they exploited to compromise victim systems.
They admitted to conspiring to obstruct commerce through extortion in connection with ransomware attacks conducted throughout 2023.
ALPHV, also known as BlackCat, targeted over 1,000 victims globally through a sophisticated ransomware-as-a-service operation. Developers maintained the malware and infrastructure, while affiliates like Goldberg and Martin identified high-value targets and executed attacks. Ransom payments were divided between developers and affiliates according to pre-established agreements.
The Justice Department previously disrupted ALPHV BlackCat operations in December 2023, when the FBI developed a decryption tool distributed to hundreds of victims through field offices and international law enforcement partners. This intervention saved victims approximately $99 million in ransom payments. Concurrently, the FBI seized multiple websites operated by the ransomware group.
Both defendants pleaded guilty to one count of conspiracy to obstruct commerce by extortion under 18 U.S.C. § 1951(a). Sentencing is scheduled for March 12, 2026, with each facing a maximum penalty of 20 years in prison. The FBI Miami Field Office leads the investigation with assistance from the U.S. Secret Service, while prosecutors from the Justice Department’s Computer Crime and Intellectual Property Section handle the case.
Based on reporting by GBHackers.
