In a striking case of insider threat, two American cybersecurity professionals have pleaded guilty to deploying ALPHV BlackCat ransomware against multiple U.S. victims, the U.S. Department of Justice announced on December 30, 2025.
Cybersecurity Insiders Turned Attackers
Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, along with an unnamed co-conspirator, successfully deployed ALPHV BlackCat ransomware between April and December 2023 against multiple victims across the United States. All three men worked in the cybersecurity industry — possessing the very skills designed to defend against the attacks they were committing.
"These defendants used their sophisticated cybersecurity training and experience to commit ransomware attacks — the very type of crime that they should have been working to stop," said Assistant Attorney General A. Tysen Duva.
The RaaS Deal: 80/20 Split
The conspirators agreed to pay ALPHV BlackCat administrators a 20% share of any ransoms received in exchange for access to the ransomware and the group's extortion platform. After successfully extorting one victim for approximately $1.2 million in Bitcoin, the three men split their 80% share and laundered the proceeds through various means.
U.S. Attorney Jason A. Reding Quiñones emphasized the domestic dimension of the threat:
"Ransomware is not just a foreign threat — it can come from inside our own borders."
ALPHV BlackCat's Global Toll
The ALPHV BlackCat operation targeted the networks of more than 1,000 victims worldwide using its Ransomware-as-a-Service model. The DOJ's December 2023 disruption operation saw the FBI develop a decryption tool that helped hundreds of victims restore their systems, saving an estimated $99 million in ransom payments. The FBI also seized several websites operated by the group.
Sentencing and Implications
Goldberg and Martin each pleaded guilty to one count of conspiracy to obstruct commerce through extortion under 18 U.S.C. § 1951(a). They face a maximum penalty of 20 years in prison and are scheduled for sentencing on March 12, 2026. The FBI Miami Field Office led the investigation with assistance from the U.S. Secret Service and Mexico's Policía de Investigación.
The case underscores the FBI's commitment to pursuing ransomware operators regardless of nationality. Special Agent in Charge Brett Skiles urged businesses to exercise due diligence when engaging third parties for incident response and to report suspicious behavior promptly.