Two American incident-response professionals were sentenced to four years in federal prison on April 30, 2026 for using ALPHV BlackCat ransomware against companies they were supposed to protect. ALPHV BlackCat is a ransomware-as-a-service operation — its administrators rent out encryption software to affiliates, who break into victim networks and split the ransom. That sentencing is the clearest disclosure of 2026, but it closes only one small part of the case. The people who ran the service itself remain unidentified, the ransomware brand shut down in 2024 after an apparent exit scam, and researchers are still arguing over whether a newer group inherited its code.
Table of Contents
- Who was sentenced, and what they did
- The insider-threat problem this case exposes
- How big ALPHV BlackCat actually was
- Why paying did not work for the largest victim
- Is ALPHV back under a new name?
- What the open questions still are
- Frequently Asked Questions
Who was sentenced, and what they did
Ryan Clifford Goldberg, 40, of Georgia, and Kevin Tyler Martin, 36, of Texas, each received four-year sentences for conspiracy to interfere with commerce by extortion. According to the Justice Department announcement, both held incident-response jobs at US cybersecurity firms — the roles companies hire to contain breaches — while attacking US victims between April and December 2023. The Justice Department says the affiliates agreed to pay ALPHV BlackCat's administrators a 20% cut of every ransom in exchange for the encryptor and access to the group's extortion platform. They hit five US companies: a Florida medical-device maker, a Maryland pharmaceutical firm, a California doctor's office, a California engineering firm, and a Virginia drone manufacturer.
The Florida medical-device maker was extorted for $1.2 million and paid. The case is not finished. The two men pleaded guilty in December 2025, and a third co-conspirator, Angelo Martino, 41, of Florida, pleaded guilty to the same single extortion-conspiracy count in April 2026. Martino's sentencing has not been reported.
The insider-threat problem this case exposes
Both sentenced men worked in incident response. That is the discipline with the most privileged view of how defenders detect intrusions, what logging companies keep, and which negotiation tactics move a victim toward paying. A responder turned affiliate carries that knowledge to the other side of the table.
Security vendors rarely screen their own responders the way a bank screens a trader. There is no industry-wide clearance, no standard for continuous monitoring of staff with domain-admin access to client networks, and no central register of practitioners barred from the field. For companies buying incident-response services, a few checks are worth asking about before signing:.
- Does the firm log and review its own consultants' access to your environment, and will it share those logs with you?
- Is client access time-boxed and revoked automatically when an engagement closes?
- Does more than one person hold the credentials used during a response, so no single consultant works unobserved?
- Does the firm run background re-checks on staff, not just at hire?
How big ALPHV BlackCat actually was
The scale behind these five victims was enormous. FBI investigations placed the group's compromised entities at more than 1,000 as of September 2023, according to the joint FBI, CISA and HHS advisory on the group. That advisory was updated in February 2024 with a darker finding: healthcare had become the most-victimized sector, after ALPHV's administrator urged affiliates to attack hospitals in retaliation for the December 2023 law-enforcement takedown.
The retaliation was aimed at police and produced casualties in emergency rooms. The disruption itself worked. The State Department's Rewards for Justice program records that the FBI's December 2023 action included a decryption tool that helped dozens of victims restore systems and avoided roughly $99 million in ransom demands. In this case, recovery came from law enforcement, not from paying.
Why paying did not work for the largest victim
The Change Healthcare breach is the counter-example every board should know. The company paid ALPHV roughly $22 million in bitcoin on March 1, 2024, according to BleepingComputer's reporting on the group's shutdown. The administrators kept the entire payment, closed the leak site, and abandoned the affiliate who had done the intrusion — known as "Notchy." That affiliate still held the stolen data.
He moved it to RansomHub, a rival extortion operation, and demanded payment a second time. UnitedHealth ultimately notified 192.7 million people. The $22 million bought neither deletion of the data nor an end to the extortion, because the people who took the money were not the people holding the files.
Is ALPHV back under a new name?
Researchers at TRM Labs assess that Embargo — a Rust-based ransomware-as-a-service that emerged in mid-2024 — is a probable ALPHV successor. As Recorded Future News reported, the overlaps are in Rust log-file structure, encryption tooling, leak-site design and wallet infrastructure, with about $34.2 million in associated cryptocurrency flows traced in roughly a year. Treat that as inference rather than attribution.
TRM Labs' own analysis notes that code, infrastructure and staff can be resold or reused between groups; no indictment or government advisory names Embargo as ALPHV reborn, and no public evidence reviewed through mid-2026 shows the original ALPHV service resuming. The practical reading for defenders: the ALPHV brand is gone, the tradecraft is not. Detection engineering built around Rust-based encryptors, rapid data staging and double-extortion leak sites remains useful regardless of which name appears on the ransom note.
What the open questions still are
The core operators have never been identified or charged. The State Department still offers up to $10 million for information identifying or locating anyone in a key leadership position in the ALPHV/Blackcat organization, plus up to $5 million for information leading to the arrest or conviction of anyone participating in its attacks — terms published by Rewards for Justice. Those rewards remaining open is itself the status report.
Three specific things are unresolved: who the administrators are, where the roughly $22 million from Change Healthcare went after the exit scam, and whether Embargo's operators are the same people or merely customers of the same toolchain. Anyone with information relevant to ALPHV's leadership can submit it through the Rewards for Justice program, which accepts tips via a Tor-based reporting channel. The $10 million figure applies to leadership identification specifically — the $5 million tier covers participants in individual attacks, including affiliates.
Frequently Asked Questions
Is ALPHV BlackCat still operating?
No public evidence reviewed through mid-2026 shows the original service resuming. It shut down in 2024 after keeping Change Healthcare's $22 million payment and closing its leak site.
Were the two sentenced men the leaders of ALPHV?
No. They were affiliates who rented the ransomware and paid administrators a 20% cut. The administrators remain unidentified, which is why multimillion-dollar State Department rewards for information about them are still open.
Did the FBI takedown help victims recover?
Yes. The December 2023 disruption included a decryption tool that helped dozens of victims restore systems and avoided roughly $99 million in ransom demands.
You Might Also Like
- Cybersecurity — Credit Card Skimmer Update 2026: Disclosure, Response, and Open Questions
- Ransomware Attacks FAQ for September 2026: Source-Checked Answers to Common Questions
- Ransomware Attacks 2026 Guide: exposure, response, and recovery; Key Facts and Questions to Ask