Two U.S. CyberSecurity Pros Plead Guilty for Working as ALPHV/BlackCat Affiliates
A federal court in the Southern District of Florida has accepted guilty pleas from two cybersecurity professionals involved in ransomware activities. Ryan Goldberg, 40, from Georgia, and Kevin Martin, 36, from Texas, admitted to conspiracy to commit…
A federal court in the Southern District of Florida has accepted guilty pleas from two cybersecurity professionals involved in ransomware activities. Ryan Goldberg, 40, from Georgia, and Kevin Martin, 36, from Texas, admitted to conspiracy to commit extortion through ransomware operations.
The individuals participated in deploying ALPHV BlackCat ransomware against multiple U.S. victims between April and December 2023. They exploited their expertise in computer security to compromise systems instead of safeguarding them.
The plea agreement disclosed that the defendants agreed to pay ALPHV BlackCat administrators 20% of ransom payments for access to the ransomware and extortion platform. They extorted approximately $1.2 million in Bitcoin from one victim, which they subsequently laundered.
This case highlights the misuse of technical skills for criminal purposes by insiders. ALPHV BlackCat operates on a ransomware-as-a-service model, where developers maintain the malware and infrastructure, while affiliates target high-value victims. The group has impacted over 1,000 victims globally, causing significant financial losses.
A federal court in the Southern District of Florida has accepted guilty pleas from two cybersecurity professionals involved in ransomware activities.
The Justice Department has been actively working to disrupt ALPHV BlackCat operations. In December 2023, the FBI developed a decryption tool that assisted hundreds of victims in restoring their systems without paying ransoms, saving approximately $99 million. The FBI also seized several websites operated by the group.
Goldberg and Martin face up to 20 years in prison for their involvement in the conspiracy to commit extortion, with sentencing scheduled for March 12, 2026. The investigation was led by the FBI’s Miami Field Office, with support from the U.S. Secret Service, demonstrating a coordinated effort to address ransomware threats.
This case emphasizes the potential risk posed by trusted cybersecurity professionals when compromised. It underscores the importance for organizations to enforce rigorous background checks, monitoring, and ethical training for security personnel.
The guilty pleas serve as a warning that domestic ransomware operators will face legal consequences, regardless of their technical skills or industry status.
Based on reporting by Cyber Security News.
