Three former employees of cybersecurity firms DigitalMint and Sygnia have been indicted for orchestrating a series of BlackCat (ALPHV) ransomware attacks against five U.S. companies between May and November 2023. The accused, including Kevin Tyler Martin and Ryan Clifford Goldberg, allegedly abused their positions as incident response professionals to gain unauthorized access to victim networks, deploy ransomware, steal sensitive data, and demand cryptocurrency ransoms ranging from $300,000 to $10 million. The Department of Justice and FBI state that the group operated as BlackCat affiliates, with at least one successful extortion resulting in a $1.27 million payment from a Tampa medical device manufacturer after its servers were encrypted.
The indictment details additional targets, including a Maryland pharmaceutical company, a California doctor's office, a California engineering firm, and a Virginia drone manufacturer, though it is unclear if further ransom payments were made. DigitalMint and Sygnia have both denied organizational involvement, terminated the implicated employees, and are cooperating with law enforcement. The case highlights the risk of insider threats within cybersecurity firms and the sophisticated tactics used by ransomware operators to exploit trusted access for criminal gain.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
DigitalMint publicly denied any role in the attacks and said it cooperated with law enforcement after the case became public.
Following the indictment, Kevin Tyler Martin pleaded not guilty to the federal charges tied to the alleged ransomware and extortion campaign.
The U.S. Department of Justice unsealed charges against Ryan Clifford Goldberg and Kevin Tyler Martin, alleging they used insider access and expertise from firms including Sygnia and DigitalMint to conduct BlackCat ransomware attacks and extortion.
According to later reporting, Goldberg tried to flee to Europe but was apprehended in Mexico City as authorities moved against the group.
The FBI traced the alleged operation, including cryptocurrency laundering through wallets and mixers, and obtained admissions from Ryan Clifford Goldberg, who reportedly said he joined the scheme because of debt.
Court filings and later reporting say the conspiracy remained active through April 2025, even though no additional victims after 2023 were publicly named in the referenced coverage.
Across 2023, the accused allegedly targeted at least five U.S. companies in multiple states, stealing data, deploying BlackCat ransomware, and demanding between $300,000 and $10 million. Prosecutors say only one victim paid, while the other extortion attempts failed.
U.S. and European law enforcement partners seized ALPHV/BlackCat infrastructure in December 2023. Later reporting said evidence from that disruption may have helped investigators identify the suspects.
In the first successful extortion case, the group allegedly attacked a Tampa-area Florida medical company and secured a cryptocurrency ransom payment of about $1.27 million after an initial demand reportedly reached as high as $10 million.
Federal prosecutors allege three Florida men, including cybersecurity professionals employed in incident response and ransomware negotiation roles, began a string of ALPHV/BlackCat ransomware attacks against U.S. companies in May 2023.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcenews.risky.biz
Open sourcebankinfosecurity.com
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourcechicago.suntimes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.