Two cybersecurity professionals have been sentenced to four years in federal prison for their roles in a 2023 ransomware conspiracy tied to ALPHV BlackCat attacks against victims in the United States.
Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, were sentenced after pleading guilty in December 2025 to one count of conspiracy to obstruct, delay, or affect commerce by extortion. Prosecutors said the men helped deploy BlackCat ransomware against multiple victims between April and December 2023.
The case stands out because all three alleged participants worked in cybersecurity. Prosecutors said Goldberg, Martin, and Angelo Martino, 41, of Florida, had experience protecting computer systems from the same kind of harm they later helped carry out.
How Prosecutors Described the Scheme
According to federal authorities, the three men used the ALPHV BlackCat ransomware-as-a-service operation to attack victims and pressure them for payment. In exchange for access to the ransomware and the group’s extortion platform, they agreed to give BlackCat administrators 20% of any ransom proceeds.
The remaining 80% was allegedly split among the three conspirators. In one case, prosecutors said a victim paid about $1.2 million in Bitcoin. The men then divided their share and laundered the funds through different methods to conceal the source of the money.
For related context, see Goldman Sachs Warns on Anthropic Mythos AI Risks.
BlackCat, also known as ALPHV, was one of the most active ransomware brands before law enforcement disruption efforts weakened its operation. The group has been linked to attacks on more than 1,000 victims worldwide, including businesses and organizations that faced data theft, system lockouts, and extortion pressure.
Crucial X9 Pro Portable SSD
A portable SSD can support offline backup rotation for key files, recovery documents, and incident response materials. It should be part of a tested backup plan, not the only recovery control.
Insider Knowledge Turned Against Victims
Federal prosecutors emphasized that the defendants were not outsiders with limited technical skill. They worked in roles connected to incident response, ransomware negotiation, or cybersecurity services.
Martino and Martin worked for DigitalMint, a company known for helping organizations handle cryptocurrency payments, including in ransomware incidents. Goldberg worked as an incident response manager for Sygnia, a cybersecurity company.
That background made the allegations especially serious. Prosecutors said the defendants understood how victims respond during ransomware incidents and used that knowledge to increase pressure, conceal activity, and profit from attacks.
Martino pleaded guilty in April 2026 to the same conspiracy charge. His sentencing is scheduled for July 9, 2026. Prosecutors said he also abused his position as a ransomware negotiator by sharing confidential information about victims, including insurance policy limits, with threat actors to push for higher ransom payments.
Why the Case Matters for Incident Response
The case is a reminder that ransomware risk is not limited to malware, phishing, or exposed systems. Trust in third-party responders, negotiators, and technical advisers can become a point of failure when sensitive incident details are mishandled or deliberately abused.
For organizations, that means ransomware preparation should include stronger controls around who receives access to response plans, insurance details, payment discussions, forensic findings, and executive communications during a crisis.
Basic due diligence is not enough once an incident is already unfolding. Companies should document decision authority before an attack, limit sensitive disclosures to need-to-know personnel, preserve logs of external access, and separate negotiation, legal, forensic, and payment workflows where possible.
Yubico YubiKey 5 NFC Security Key
Hardware security keys can add phishing-resistant MFA to email, cloud, password manager, and admin accounts used during incident response. Teams should confirm platform compatibility before deploying them broadly.
Law enforcement has continued to frame BlackCat as a major ransomware threat even after disruption actions against the group’s infrastructure. The sentencing of Goldberg and Martin adds another layer to that story: people hired or trained to defend networks can become part of the threat when access, trust, and specialized knowledge are misused.


