{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:19:39.261Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2025-us-ransomware-negotiators-charged-with-running-their-own-blackcat-attack","title":"US ransomware negotiators charged with running their own BlackCat attacks","date":"2025-11-03","date_precision":"day","year":2025,"victim_org":"US medical device company, pharmaceutical firm, drone maker and other victims","sector":"Professional Services","country":"United States","primary_vector":"Insider Recruitment","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Extortion","Insider Access"],"loss_usd":1274000,"loss_kind":"ransom_paid","loss_note":"One victim, a Florida medical device company, paid about $1.27 million in bitcoin according to the indictment.","records_affected":null,"threat_actor":"ALPHV / BlackCat affiliates","summary":"US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.","how_it_worked":"This was a trusted-insider abuse rather than an external deception. The defendants worked in roles that put them inside the ransomware economy, negotiating on behalf of victims and responding to intrusions, which gave them privileged knowledge of how victims behave, what they pay and how affiliates operate. Prosecutors alleged they used that position to run attacks of their own with the ALPHV/BlackCat toolkit and extort the companies. The trust abused was institutional: organisations hand incident responders and negotiators deep access and complete candour during a crisis, and the employers' own vetting did not surface the conduct until federal investigators did.","lessons":"Firms handling victim data and ransom negotiations need separation of duties, monitored access to case material and periodic re-vetting of staff with that level of insight.","confidence":"Confirmed","sources":[{"title":"DOJ accuses US ransomware negotiators of launching their own ransomware attacks","url":"https://techcrunch.com/2025/11/03/doj-accuses-us-ransomware-negotiators-of-launching-their-own-ransomware-attacks/","publisher":"TechCrunch"},{"title":"Ransomware responders plead guilty to using ALPHV in attacks on US organizations","url":"https://therecord.media/ransomware-responders-guilty-plea-using-alphv-blackcat-us-attacks","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-ransomware-negotiators-charged-with-running-their-own-blackcat-attack"}]}