Threats & Adversaries · Ransomware
Former Incident Responders Joined BlackCat Extortion Crew The risk is not just ransomware access. It is trusted defenders turning their incident-response skills into affiliate work for an extortion crew, which gives attackers better judgment about victims, negotiations, and pressure points than a typical criminal recruit.
Two former employees of Sygnia and DigitalMint were sentenced to four years each after pleading guilty to serving as BlackCat (ALPHV) affiliates from May to November 2023. Prosecutors said they paid for access to BlackCat's ransomware and extortion platform, hit multiple U.S. victims, and targeted sectors including healthcare, manufacturing, engineering, drone manufacturing, and a doctor's office.
The pattern matters because it shows ransomware groups can recruit people who already know how defenders think and how victims respond. That makes insider expertise part of the threat landscape, not just insider access.
8 sources · May 4
Timeline Sources May 4 Help Net Security
Two cybersecurity pros get prison time for helping ransomware gang - Help Net Security
cybersecurity experts sentenced to 4 years for ALPHV/BlackCat ransomware attacks, extorting victims and laundering millions.
original May 1 The Hacker News
Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks
Two cybersecurity experts got 4-year sentences after enabling 2023 BlackCat attacks, exposing insider abuse and $1.2M ransom impact.
original May 1 The Record from Recorded Future
Cyber incident responders who carried out ransomware attacks given 4-year sentences
Two cybersecurity incident responders who abused their positions to carry out covert ransomware attacks were sentenced to four years in prison.
original Part of the PlainSec briefing for 2026-05-01
Every edition of this story: Former Incident Responders Joined BlackCat Extortion Crew
More from today
Threats & Adversaries · Ransomware
Former Incident Responders Joined BlackCat Extortion Crew The risk is not just ransomware access. It is trusted defenders turning their incident-response skills into affiliate work for an extortion crew, which gives attackers better judgment about victims, negotiations, and pressure points than a typical criminal recruit.
Two former employees of Sygnia and DigitalMint were sentenced to four years each after pleading guilty to serving as BlackCat (ALPHV) affiliates from May to November 2023. Prosecutors said they paid for access to BlackCat's ransomware and extortion platform, hit multiple U.S. victims, and targeted sectors including healthcare, manufacturing, engineering, drone manufacturing, and a doctor's office.
The pattern matters because it shows ransomware groups can recruit people who already know how defenders think and how victims respond. That makes insider expertise part of the threat landscape, not just insider access.
8 sources · May 4
Timeline Sources May 4 Help Net Security
Two cybersecurity pros get prison time for helping ransomware gang - Help Net Security
cybersecurity experts sentenced to 4 years for ALPHV/BlackCat ransomware attacks, extorting victims and laundering millions.
original May 1 The Hacker News
Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks
Two cybersecurity experts got 4-year sentences after enabling 2023 BlackCat attacks, exposing insider abuse and $1.2M ransom impact.
original May 1 The Record from Recorded Future
Cyber incident responders who carried out ransomware attacks given 4-year sentences
Two cybersecurity incident responders who abused their positions to carry out covert ransomware attacks were sentenced to four years in prison.
original Part of the PlainSec briefing for 2026-05-01
Every edition of this story: Former Incident Responders Joined BlackCat Extortion Crew
More from today