Skip to content
NetarxImpact Database
Insider RecruitmentNo AI reportedConfirmed

US ransomware negotiators charged with running their own BlackCat attacks

US medical device company, pharmaceutical firm, drone maker and other victims · Professional Services · United States · November 3, 2025

Ransom paid
$1,274,000
An extortion payment the victim chose to make.
One victim, a Florida medical device company, paid about $1.27 million in bitcoin according to the indictment.

What happened

US prosecutors announced in November 2025 that incident response professionals then employed at ransomware negotiation firm DigitalMint and at security company Sygnia had been charged with conducting ALPHV/BlackCat ransomware attacks against American companies. Victims named in the indictment included a Florida medical device maker that paid roughly $1.27 million, a Maryland pharmaceutical firm, a California drone manufacturer and a Virginia doctor's office. Guilty pleas followed.

How the deception worked

This was a trusted-insider abuse rather than an external deception. The defendants worked in roles that put them inside the ransomware economy, negotiating on behalf of victims and responding to intrusions, which gave them privileged knowledge of how victims behave, what they pay and how affiliates operate. Prosecutors alleged they used that position to run attacks of their own with the ALPHV/BlackCat toolkit and extort the companies. The trust abused was institutional: organisations hand incident responders and negotiators deep access and complete candour during a crisis, and the employers' own vetting did not surface the conduct until federal investigators did.

The control that would have caught it· our reading, not a claim from the sources

Firms handling victim data and ransom negotiations need separation of duties, monitored access to case material and periodic re-vetting of staff with that level of insight.

Sources (2)

  1. DOJ accuses US ransomware negotiators of launching their own ransomware attacks
    TechCrunch·techcrunch.comOpen ↗
  2. Ransomware responders plead guilty to using ALPHV in attacks on US organizations
    The Record·therecord.mediaOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.