Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
UtiliaCS 320x100
HackTheBox 970x120 1
Double-dealing: employees of a company that resolved ransomware attacks were launching them themselves

Double-dealing: employees of a company that resolved ransomware attacks were launching them themselves

7 November 2025 10:54

Three former DigitalMint employees, who investigated ransomware incidents and negotiated with ransomware groups, are accused of hacking into the networks of five American companies. According to the U.S. Department of Justice, they participated in BlackCat (ALPHV) ransomware attacks and extorted millions of dollars from victims.

The case involves a 28-year-old and a 33-year-old Georgia man and their accomplice. They are charged with conspiracy to interfere with interstate commerce by racketeering, actual interference with commerce, and intentional damage to protected computers. These charges carry a maximum sentence of 50 years in prison.

According to the Chicago Sun-Times , one of the two and an unidentified accomplice worked at DigitalMint, specializing in ransomware negotiations, while the other was responsible for incident response at another company, Sygnia.

Investigators allege that the defendants became complicit in the BlackCat extortion scheme, hacking into corporate networks, stealing data, and spreading ransomware. The victims were then asked to pay a ransom in cryptocurrency to decrypt their data and “keep the stolen information confidential.”

According to court documents , the group targeted a Tampa-based medical device manufacturer , a Maryland pharmaceutical company , a California engineering firm and medical clinic , and a Virginia-based drone developer .

Ransom demands ranged from $300,000 to $10 million. However, the only payment the hackers actually received was $1.27 million, transferred from a Tampa-based company after the May 2023 attack.

BlackCat (also known as ALPHV) is one of the most active hacker groups in recent years. According to the FBI, in its first two years alone, its partners have carried out over 1,000 attacks and collected at least $300 million in ransoms.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

Cropped RHC 3d Transp2 1766828557 300x300
The editorial staff of Red Hot Cyber is composed of IT and cybersecurity professionals, supported by a network of qualified sources who also operate confidentially. The team works daily to analyze, verify, and publish news, insights, and reports on cybersecurity, technology, and digital threats, with a particular focus on the accuracy of information and the protection of sources. The information published is derived from direct research, field experience, and exclusive contributions from national and international operational contexts.