Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Legal Action Insider Threat topic

No spam. Unsubscribe anytime.

DOJ charges a former ransomware negotiator; prosecutors say insiders exploited trusted access

Ahead of the Threat (FBI Cyber Division podcast) · March 27, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Department of Justice charged a former incident‑response negotiator with conspiring to extort victims while working as an affiliate of BlackCat/ALPHV; two co‑defendants pled guilty and prosecutors say victims paid more than $75 million in ransoms across attributed attacks.

On March 13 the Department of Justice announced charges against an individual formerly employed as a ransomware negotiator at an incident response firm, accusing the person of conspiring with the BlackCat/ALPHV group to extort victims while simultaneously negotiating ransoms for companies the conspirators had attacked.

Brett Leatherman summarized the indictment on the podcast, saying prosecutors allege the individual used trusted access and incident response roles to further criminal activity. Leatherman noted the FBI Miami Field Office led the investigation.

Two co‑conspirators named in the transcript, Ryan Goldberg and Kevin Martin, previously pled guilty in December to conspiracy to obstruct commerce by extortion and face up to 20 years in prison, Leatherman said. Prosecutors attributed more than $75 million in ransom payments to attacks linked with the group.

Leatherman and Maeve Healy framed the charges as a reminder that third‑party risk and careful vetting of incident‑response partners are central to enterprise security. Healy said some firms responded appropriately upon notification of the investigation by suspending access for suspected individuals and tightening audit and logging practices.

The transcript quotes the U.S. attorney in the Southern District of Florida as saying, "Ransomware is not just a foreign threat. It can come from inside our own borders as well," language included in public court filings and press statements.

The podcast did not provide additional court filings, arraignment dates or the defendant's name; it focused instead on the operational and vendor‑management lessons for executives and general counsel.

Leatherman and Healy urged organizations to include law enforcement in incident response planning and to exercise tabletop scenarios that bring executives and legal counsel into the response process.