Ransomware Negotiators Accused of Conducting Their Own Ransomware Attacks
Three former employees of cybersecurity firms have been accused of conducting ALPHV/BlackCat ransomware attacks on five companies in the United States, including three healthcare organizations. Two of those individuals have been indicted over the attacks, while the third is believed to have been an accomplice but has yet to be charged. The recently unsealed indictment alleges that Ryan Clifford Goldberg of Roanoke, Texas, and Kevin Tyler Martin of Watkinsville, Georgia, gained unauthorized access to protected computers and deployed ALPHV/BlackCat ransomware in an attempt to extort five U.S. victims.
The attacks were conducted while the three individuals were employed by cybersecurity firms. Goldberg was employed as an incident response manager at the cybersecurity firm Sygnia, while Martin and the unnamed co-conspirator were employed as ransomware negotiators at the cyber threat and incident response firm DigitalMint. Goldberg and Martin are alleged to have used knowledge gained as insiders to enrich themselves by conducting their own ransomware attacks. Prosecutors allege that they used insider knowledge to conduct attacks when they were least likely to be detected, bypass their victims’ defenses, and attempt to extort their victims.
The ALPHV/BlackCat ransomware group operates under the affiliate model, where individuals are recruited to conduct attacks for a cut of any ransom payments they generate. According to court documents, Goldberg and Martin conducted five ransomware attacks between May 2023 and November 2023, assisted by an unnamed third individual. The first attack was on a Florida-based medical device company in May 2023 and led to a $10 million ransom demand. The company negotiated and paid approximately $1.3 million in cryptocurrency to recover its encrypted files and prevent the publication of stolen data.
The next attack was also conducted in May, this time on a Maryland pharmaceutical company. The ransom amount was not disclosed, and it was not paid. In July 2023, a medical practice in California was attacked and faced a $5 million ransom demand, although no payment was made. Then, in October and November, a California engineering company and a Virginia-based drone manufacturer were attacked. Neither victim paid a ransom.
Goldberg and Martin have been charged with conspiracy to interfere with interstate commerce via extortion, intentionally damaging a protected computer, and extortion. If convicted, they each face up to 50 years in jail. The two cybersecurity firms were not targets of the investigation and assisted with the law enforcement investigation. “Immediately upon learning of the situation, [Goldberg] was terminated,” explained a spokesperson for Sygnia in a statement. “While Sygnia is not a target of this investigation, we are continuing to work closely with the FBI. We cannot provide further comment on the ongoing federal investigation.”
“The former employee, acting completely outside the scope of his employment, purportedly conspired with two individuals, one named [Martin] and one not named – the last who may have also been a company employee – of using AlphV/BlackCat ransomware to conduct the attacks,” said a spokesperson for DigitalMint. “As expected, the indictment does not allege that the company had any knowledge of or involvement in the criminal activity. DigitalMint has been and continues to be a cooperating witness in the investigation and not an investigative target.”
Goldberg and Martin were arraigned on October 7, and Martin was released on a $400,000 federal bond. Goldberg remains in custody as he is considered a flight risk. Goldberg’s trial commences on November 17, 2025, and Martin’s trial starts on December 1, 2025.
