BlackCat Operators Plead Guilty in U.S. Case Involving $1.2 Million Bitcoin Ransom

BlackCat Operators Plead Guilty in U.S. Case Involving $1.2 Million Bitcoin Ransom

N
News Editor 01
2026-07-23 02:35:14
The U.S. Justice Department said two American men pleaded guilty to using ALPHV BlackCat ransomware in 2023. In one attack, a victim was extorted for about $1.2 million in bitcoin. Sentencing is set for March 2026.
BlackCatransomwarebitcoinDOJcybersecurity

The U.S. Department of Justice said a federal court in the Southern District of Florida has accepted plea agreements from two American men who admitted taking part in ransomware attacks using ALPHV, also known as BlackCat. Prosecutors said the pair conspired in 2023 to target multiple victims in the United States and use digital extortion to obtain illicit proceeds.

Defendants had experience in the cybersecurity industry

Court documents identified the defendants as Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas. Along with another co-conspirator, they deployed BlackCat ransomware against several U.S. targets between April and December 2023. The case drew added attention because all three had previously worked in cybersecurity and had experience with network defense and system protection.

That detail sits at the center of the DOJ’s message. The department said ransomware threats do not come only from foreign actors; domestic offenders with insider-level technical knowledge can also pose serious risks.

BlackCat used a ransomware-as-a-service revenue split

According to the DOJ, ALPHV BlackCat operated as a ransomware-as-a-service (RaaS) platform. Developers supplied the malware and supporting infrastructure, while affiliates carried out the actual intrusions. To gain access to the service, Goldberg and his associates agreed to hand over 20% of each successful ransom payment to BlackCat’s administrators.

In one attack, the group extorted roughly $1.2 million worth of bitcoin from a single victim. After the proceeds were divided, they used multiple methods to launder the funds and conceal the origin of the money.

More than 1,000 victims were linked to the group

The Justice Department said ALPHV BlackCat attacked more than 1,000 victims worldwide, making it one of the most destructive ransomware operations in recent years. In December 2023, the FBI carried out a major enforcement action against the group, developed a decryption tool, and helped hundreds of victims recover their systems.

U.S. authorities estimated that operation prevented about $99 million in ransom losses. Investigators also seized several websites operated by BlackCat. The DOJ said enforcement efforts will continue across the ransomware chain, including people and entities that knowingly assist or profit from the activity.

Sentencing is scheduled for March 2026

Goldberg and Martin each pleaded guilty to one count of conspiracy to commit an offense involving extortionate interference with commerce. They are scheduled to be sentenced on March 12, 2026. The charge carries a maximum penalty of 20 years in prison, though the final sentence will be decided by the judge under federal sentencing guidelines and the facts of the case.

The DOJ also urged companies and institutions to contact law enforcement quickly after a ransomware incident to limit losses and reduce the number of future victims.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.