Ryan Goldberg managed incident response at Sygnia, a cybersecurity firm that helps companies recover from attacks. Kevin Martin negotiated ransom payments at DigitalMint, a company victims call when they need to pay attackers in cryptocurrency. Both men pleaded guilty in Miami federal court to running BlackCat ransomware operations against US companies while collecting paychecks from the firms hired to stop exactly that, according to the Department of Justice.
Between April and December 2023, Goldberg (40, Georgia), Martin (36, Texas), and an unnamed third co-conspirator deployed ALPHV/BlackCat ransomware against at least five US companies, as reported by SecurityWeek. Three of the targets were healthcare organizations. They successfully extorted approximately $1.2 million in Bitcoin from one victim, kept their 80% affiliate share, split it three ways, and laundered the proceeds. Each faces up to 20 years in prison.
The case was investigated by the FBI and US Secret Service and prosecuted by the Southern District of Florida.
The BlackCat Operation They Joined
ALPHV/BlackCat was one of the most prolific ransomware-as-a-service operations in recent history. The FBI reported in September 2023 that BlackCat had compromised over 1,000 victims and collected nearly $300 million in ransom payments. The franchise model was simple. Affiliates got the malware, the infrastructure, and the negotiation playbooks. Operators took a 20% cut. The DOJ disrupted BlackCat’s operations in December 2023, recovering approximately $99 million in potential ransom payments.
But before that takedown, in February 2024, a BlackCat affiliate hit Change Healthcare in what became one of the most damaging cyberattacks in US history. Change Healthcare paid $22 million in ransom, with total losses likely exceeding $1.5 billion, according to IBM’s analysis. The FBI and CISA issued a joint advisory warning that after the December 2023 disruption, BlackCat administrators actively encouraged affiliates to target hospitals.
Goldberg and Martin were part of this ecosystem. They weren’t outsiders who stumbled into ransomware. They were credentialed security professionals who understood incident response timelines, negotiation dynamics, and how victims behave under pressure, because helping victims was their day job.
Healthcare Was the Obvious Target
Three of their five victims were healthcare organizations. This tracks with a broader pattern. Healthcare has been the most expensive sector for data breaches for 14 consecutive years, averaging $9.77 million per incident in 2024, according to IBM. The HIPAA Journal reported that healthcare cyberattacks costing over $200,000 rose 400% in a single year. In 2024 alone, 458 ransomware events were tracked in the healthcare sector, with 65% of ransom demands exceeding $1 million.
Hospitals can’t afford downtime. Patient care is the leverage. When you encrypt a hospital’s systems, you’re threatening to disrupt treatment for real people in real time. Goldberg and Martin knew this. They chose healthcare targets knowing the pressure dynamics would maximize the likelihood of payment.
And they did it while working at companies that healthcare organizations call for help during exactly these situations.
The Insider Threat Is Getting Worse
This case fits into a trend the industry is tracking but struggling to address. The 2025 Verizon Data Breach Investigations Report found that internal actors were responsible for 29% of breaches. Only 17% of organizations reported zero insider incidents in 2024, down from 40% in 2023. Malicious insider attacks are the single most expensive breach type, averaging $4.92 million per incident.
North American organizations faced average insider incident costs of $22.2 million in 2025.
Goldberg and Martin represent the most dangerous version of this problem. They weren’t disgruntled employees stealing data on their way out. They were active security professionals using their legitimate access and expertise to moonlight as ransomware affiliates. Goldberg’s job was to respond to the exact type of attack he was launching. Martin’s job was to help victims pay ransoms, which means he understood the negotiation dynamics, the payment timelines, and the pressure points from the victim’s side of the table.
What the Industry Doesn’t Want to Sit With
The security industry runs on trust. When a company brings in an incident response firm during a ransomware attack, they hand over admin credentials, network maps, and forensic access. They have to. That’s how incident response works. The assumption is that the people on the other end of those credentials are operating in good faith.
There’s no external verification mechanism for that assumption in the private sector. Security clearances exist for government work, but private-sector cybersecurity hiring runs on certifications, references, and interviews. Nobody is monitoring what an incident responder does with the access they’re granted during an engagement.
The financial incentive is real. An 80% affiliate cut on a seven-figure ransom dwarfs a senior security professional’s annual salary. And the operational knowledge required to avoid detection? These are the people who teach detection.
Goldberg and Martin got caught. The FBI and Secret Service built the case and secured guilty pleas. Good.
But they operated for eight months, hit at least five companies, extorted over a million dollars, and laundered the proceeds before anyone connected them to the attacks. The industry will issue statements about trust, integrity, and vetting. It will point to this prosecution as proof the system works. That framing is convenient and wrong. The system didn’t prevent anything. It cleaned up afterward. Eight months of operations, three healthcare victims, and over a million dollars in extorted payments happened first.
The cybersecurity industry sells protection. It charges billions for it. And it has no structural mechanism to verify that the people delivering that protection aren’t also the ones running the attacks. Certifications don’t screen for motive. Background checks don’t catch moonlighting. The trust model is “we assume good faith until proven otherwise,” and the proof only comes after the damage.
That’s not a system that works. That’s a system that got lucky twice.
—
Lamar covers cybersecurity, enterprise tech, and the systems that shape how power and technology interact. Follow Laterstack for critical analysis of the stories that matter.