Cybersecurity experts face 20 years in prison following ransomware campaign
Two men used their tech expertise to carry out ALPHV BlackCat ransomware attacks
Two US cybersecurity experts have pleaded guilty to using ALPHV BlackCat ransomware to extort businesses across the USA during a seven-month campaign in 2023.
40-year-old Ryan Goldberg of Georgia and 36-year-old Kevin Martin of Texas, admitted conspiring to obstruct, delay, or affect commerce through extortion in a federal district court in the Southern District of Florida.
Goldberg was an incident response manager at the time he and Martin, as well as one other unnamed individual, turned their skills to nefarious activities. Martin, meanwhile, was a ransomware threat negotiator.
Their campaign, which ran from April to December 2023, saw the trio turn to ALPHV BlackCat ransomware as a service operators, who they agreed to pay 20% share of any ransoms received in exchange for access to the ransomware and extortion platform
They then successfully used the malware against numerous US targets, including a pharmaceutical company based in Maryland, an engineering company based in California, a drone manufacturer in Virginia, and a medical company from Florida, where the case was heard.
One victim paid the equivalent of $1.2 million in Bitcoin in order to put an end to the attack, with the proceeds split three ways between the conspirators after they had given the ALPHV BlackCat administrators their cut.
Assistant attorney general A. Tysen Duva of the Justice Department’s Criminal Division said: “These defendants used their sophisticated cybersecurity training and experience to commit ransomware attacks — the very type of crime that they should have been working to stop.”
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Millions of dollars saved following ransomware disruption
ALPHV BlackCat was active for 18 months before the FBI developed a decryption tool for the ransomware, extorting millions of dollars from businesses primarily in the US before going dark in December 2023. The law enforcement agency estimates it saved victims in the order of $99 million in ransomware payments.
“The FBI remains committed to working alongside its law enforcement partners to disrupt and dismantle criminal enterprises involved in ransomware attacks and to hold accountable not only the perpetrators but also anyone who knowingly enables or profits from them,” said special agent in charge Brett Skiles of the FBI Miami Field Office.
US attorney Jason A Reding Quiñones, representing the Southern District of Florida, said: “Goldberg and Martin used trusted access and technical skill to extort American victims and profit from digital coercion.”
“Their guilty pleas make clear that cybercriminals operating from within the United States will be found, prosecuted, and held to account,” he added.
The pair are set to be sentenced on 12 March 2026 and face a maximum penalty of 20 years in prison.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
- Jane McCallionManaging Editor
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals

