What happened
US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.
How the deception worked
This was a trusted-insider abuse rather than an external deception. The defendants worked in roles that put them inside the ransomware economy, negotiating on behalf of victims and responding to intrusions, which gave them privileged knowledge of how victims behave, what they pay and how affiliates operate. Prosecutors alleged they used that position to run attacks of their own with the ALPHV/BlackCat toolkit and extort the companies. The trust abused was institutional: organisations hand incident responders and negotiators deep access and complete candour during a crisis, and the employers' own vetting did not surface the conduct until federal investigators did.
The control that would have caught it· our reading, not a claim from the sources
Firms handling victim data and ransom negotiations need separation of duties, monitored access to case material and periodic re-vetting of staff with that level of insight.
Sources (2)
- DOJ accuses US ransomware negotiators of launching their own ransomware attacksTechCrunch·techcrunch.comOpen ↗
- Ransomware responders plead guilty to using ALPHV in attacks on US organizationsThe Record·therecord.mediaOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.