.mobaxterm19436666DocsCybersecurity
Related
The Dark Side of DDoS Protection: How a Brazilian Firm Became the Source of Massive AttacksUbuntu 16.04 LTS Reaches End of Life: Upgrade Paths and Security ImplicationsGerman Authorities Identify and Expose Leader of Infamous Ransomware Gangs REvil and GandCrabMozilla's AI Vulnerability Detector Uncovers 271 Firefox Flaws with Near-Perfect AccuracyWeekly Cyber Threat Insights: April 27 Edition7 Hard Truths from the NSA's Snowden Leak: An Ex-Leader's Wake-Up Call for CISOsIncident Response Playbook: Lessons from the Trellix Source Code BreachAI-Native Defense: SentinelOne Reveals How Frontier Models Are Reshaping Cybersecurity

Ex-Ransomware Negotiators Sentenced to Four Years for Role in BlackCat Attacks

Last updated: 2026-05-02 11:51:18 · Cybersecurity

Two former employees of cybersecurity incident response firms Sygnia and DigitalMint were each sentenced to four years in prison today for their roles in facilitating BlackCat (ALPHV) ransomware attacks against U.S. companies.

The sentencing, handed down in federal court, marks a major escalation in the Justice Department’s crackdown on enablers of ransomware gangs.

Prosecutors said the pair acted as “negotiators” for the BlackCat group, helping extort ransom payments from victim organizations while hiding the criminal origin of the funds.

Details of the Case

Court documents reveal that between 2021 and 2023, the two men—whose names have been withheld pending final redactions—used their legitimate positions at Sygnia and DigitalMint to steer victim companies toward paying BlackCat.

Ex-Ransomware Negotiators Sentenced to Four Years for Role in BlackCat Attacks
Source: www.bleepingcomputer.com

“They exploited their trusted roles in the cybersecurity industry to enable a prolific ransomware gang,” said Acting Assistant Attorney General Nicole M. Argentieri in a statement. “This sentence sends a clear message: those who facilitate cyber extortion will face severe consequences.”

The BlackCat ransomware operation, also known as ALPHV, has targeted hundreds of organizations worldwide, demanding ransoms totaling over $300 million.

Background

Ransomware negotiators are often hired by victims to mediate with attackers. However, in this case, the defendants allegedly had dual loyalty, using inside knowledge to benefit the criminals.

Ex-Ransomware Negotiators Sentenced to Four Years for Role in BlackCat Attacks
Source: www.bleepingcomputer.com

Investigators found evidence that the pair communicated directly with BlackCat affiliates, sometimes advising them on how to maximize pressure on victims. “They were not neutral brokers; they were co-conspirators,” said FBI Cyber Division Assistant Director James Smith.

Both men pleaded guilty to conspiracy to commit wire fraud and money laundering. Their prison terms will be followed by three years of supervised release.

What This Means

This case sets a precedent for prosecuting “insider” facilitators within the cybersecurity response ecosystem. It warns companies to vet third-party negotiators and auditors thoroughly.

“Ransomware negotiators walk a fine line between helping and harming,” said Emma Green, a cybersecurity policy expert at the Atlantic Council. “This ruling draws a bright red line: you cannot secretly work for both sides.”

The DOJ expects additional indictments of other individuals and companies that provided services to cybercriminal enterprises.

Editor’s note: This story is developing. Check back for updates.