Former Incident Responders Joined BlackCat Extortion Crew

The risk is not just ransomware access. It is trusted defenders turning their incident-response skills into affiliate work for an extortion crew, which gives attackers better judgment about victims, negotiations, and pressure points than a typical criminal recruit. Two former employees of Sygnia and DigitalMint were sentenced to four years each after pleading guilty to serving as BlackCat (ALPHV) affiliates from May to November 2023. Prosecutors said they paid for access to BlackCat's ransomware and extortion platform, hit multiple U.S. victims, and targeted sectors including healthcare, manufacturing, engineering, drone manufacturing, and a doctor's office. The pattern matters because it shows ransomware groups can recruit people who already know how defenders think and how victims respond. That makes insider expertise part of the threat landscape, not just insider access.

Part of the PlainSec briefing for 2026-05-01

Sources