Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 1 / 2
26 résultats taggé ALPHV  ✕
US cybersecurity experts plead guilty to BlackCat ransomware attacks https://www.bleepingcomputer.com/news/security/us-cybersecurity-experts-plead-guilty-to-blackcat-alphv-ransomware-attacks/
31/12/2025 00:52:29
QRCode
archive.org
thumbnail

bleepingcomputer.com
By Sergiu Gatlan
December 30, 2025

Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023.
Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023.

33-year-old Ryan Clifford Goldberg of Watkinsville, Georgia (in federal custody since September 2023), and 28-year-old Kevin Tyler Martin of Roanoke, Texas, who were charged in November, have now pleaded guilty to conspiracy to obstruct commerce by extortion and are set to be sentenced on March 12, 2026, facing up to 20 years in prison each.

Together with a third accomplice, the two BlackCat ransomware affiliates breached the networks of multiple victims across the United States between May 2023 and November 2023, paying a 20% share of ransoms in exchange for access to BlackCat's ransomware and extortion platform.

Goldberg is a former Sygnia incident response manager, and Martin worked at DigitalMint as a ransomware threat negotiator (just as the unnamed co-conspirator).

"These defendants used their sophisticated cybersecurity training and experience to commit ransomware attacks — the very type of crime that they should have been working to stop," said Assistant Attorney General A. Tysen Duva. "Extortion via the internet victimizes innocent citizens every bit as much as taking money directly out of their pockets."

According to court documents, their alleged victims include a Maryland pharmaceutical company, a California engineering firm, a Tampa medical device manufacturer, a Virginia drone manufacturer, and a California doctor's office.

While they have demanded ransoms ranging from $300,000 to $10 million, prosecutors said they were only paid $1.27 million by the Tampa medical device company after encrypting its servers and demanding $10 million in May 2023. While other victims also received ransom demands, the indictment does not indicate whether additional payments were made.

As BleepingComputer previously reported, the Justice Department was also investigating a former DigitalMint negotiator in July for allegedly working with ransomware groups. However, the DOJ and FBI did not comment on the investigation, and it is unclear if this case is related to it.

In December 2023, the FBI created a decryption tool after breaching BlackCat's servers to monitor their activities and obtain decryption keys. The FBI also found that the BlackCat operation collected at least $300 million in ransom payments from more than 1,000 victims until September 2023.

In a February 2024 joint advisory, the FBI, CISA, and the Department of Health and Human Services (HHS) also warned that Blackcat affiliates were primarily targeting organizations in the U.S. healthcare sector.

bleepingcomputer.com EN 2025 Affiliates ALPHV BlackCat DigitalMint Ransomware Sygnia USA
https://www.forescout.com/blog/draytek-routers-exploited-in-massive-ransomware-campaign-analysis-and-recommendations/ https://www.forescout.com/blog/draytek-routers-exploited-in-massive-ransomware-campaign-analysis-and-recommendations/
16/12/2024 09:24:00
QRCode
archive.org
  • Our 2024 Dray:Break report revealed 14 new vulnerabilities in DrayTek devices
    *See our upcoming presentation at Black Hat Europe for more details
  • PRODAFT shared threat intelligence from 2023 on a ransomware campaign exploiting DrayTek devices
  • This is the first time this campaign is discussed publicly
  • Our analysis shows sophisticated attack workflows to deploy ransomware including possible:
    • Zero-day vulnerabilities
    • Credential harvesting and password cracking
      VPN and tunneling abuse
forescout en 2024 draytek ALPHV ransomware
Timeline and Details of the Change Healthcare Breach https://www.secjuice.com/change-healthcare-breach/
24/06/2024 11:28:24
QRCode
archive.org
thumbnail

Discover how this healthcare breach unfolds and learn crucial defense strategies. Dive into our expert analysis for actionable insights.

secjuice EN timeline Change Healthcare Breach ALPHV
IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment – The DFIR Report https://thedfirreport.com/2024/06/10/icedid-brings-screenconnect-and-csharp-streamer-to-alphv-ransomware-deployment/
11/06/2024 21:34:35
QRCode
archive.org
thumbnail

Key Takeaways In October 2023, we observed an intrusion that began with a spam campaign, distributing a forked IcedID loader. The threat actor used Impacket’s wmiexec and RDP to install Scree…

thedfirreport EN 2024 analysis IceID ScreenConnect incident ALPHV Ransomware
Round 2: Change Healthcare Targeted in Second Ransomware Attack https://www.darkreading.com/cyberattacks-data-breaches/round-2-change-healthcare-targeted-second-ransomware-attack
10/04/2024 10:05:51
QRCode
archive.org
thumbnail

RansomHub, which is speculated to have some connection to ALPHV, has stolen 4TB of sensitive data from the beleaguered healthcare company.

darkreading 2024 Change-Healthcare ALPHV Ransomware Attack
US offers $10 million bounty for info on 'Blackcat' hackers who hit UnitedHealth https://www.reuters.com/technology/cybersecurity/us-offers-10-million-bounty-info-blackcat-hackers-who-hit-unitedhealth-2024-03-27/
28/03/2024 14:53:41
QRCode
archive.org

The U.S. State Department on Wednesday offered up to $10 million for information on the "Blackcat" ransomware gang who hit the UnitedHealth Group's tech unit and snarled insurance payments across America.
"The ALPHV Blackcat ransomware-as-a-service group compromised computer networks of critical infrastructure sectors in the United States and worldwide," the department said in a statement announcing the reward offer.

reuters EN 2024 US bounty ALPHV Blackcat
Blackcat ransomware site reportedly seized but UK agency denies responsibility https://www.reuters.com/technology/cybersecurity/blackcat-ransomware-site-claims-it-was-seized-uk-law-enforcement-denies-being-2024-03-05/
05/03/2024 17:27:00
QRCode
archive.org

website used by hackers responsible for a breach at UnitedHealth Group (UNH.N), opens new tab has been replaced by a notice saying it has been seized by international law enforcement.
But at least one of the agencies allegedly responsible said it had nothing to do with the seizure, raising the possibility that the hackers - who also go by the moniker ALPHV - faked their own takedown.
A message posted to the website of the Blackcat hacking gang on Tuesday said it had been impounded "as part of a coordinated law enforcement action" by U.S. authorities and other law enforcement agencies. Among the logos of non-American agencies involved were those of Europol and Britain's National Crime Agency.

reuters EN 2024 AlphV UnitedHealth-Group BlackCat ransomware UK denies
Developing: AlphV allegedly scammed Change Healthcare and its own affiliate (1) https://www.databreaches.net/developing-alphv-allegedly-scammed-change-healthcare-and-its-own-affiliate/
05/03/2024 17:25:41
QRCode
archive.org

Developing: Someone claiming to be an “affiliate plus” for AlphV claims they were responsible for the Change Healthcare attack but that AlphV stole the payment Change Healthcare had made and suspended the affiliate’s account.

The affiliate’s claims appeared on Ramp Forum and have been circulating since then. The post can be seen below, via @vx-underground:

databreaches.net EN 2024 AlphV affiliate scam Change Healthcare
BlackCat ransomware shuts down in exit scam, blames the "feds" https://www.bleepingcomputer.com/news/security/blackcat-ransomware-shuts-down-in-exit-scam-blames-the-feds/
05/03/2024 16:57:00
QRCode
archive.org
thumbnail

The BlackCat ransomware gang is pulling an exit scam, trying to shut down and run off with affiliates' money by pretending the FBI seized their site and infrastructure.

bleepingcomputer EN 2024 ALPHV BlackCat Exit-Scam Ransomware
BlackCat ransomware turns off servers amid claim they stole $22 million ransom https://www.bleepingcomputer.com/news/security/blackcat-ransomware-turns-off-servers-amid-claim-they-stole-22-million-ransom/
04/03/2024 19:18:05
QRCode
archive.org
thumbnail

The ALPHV/BlackCat ransomware gang has shut down its servers amid claims that they scammed the affiliate responsible for the attack on Optum, the operator of the Change Healthcare platform, of $22 million.

bleepingcomputer EN 2024 ALPHV BlackCat Healthcare Optum Ransomware UnitedHealth-Group
Hackers Behind the Change Healthcare Ransomware Attack Just Received a $22 Million Payment https://www.wired.com/story/alphv-change-healthcare-ransomware-payment/
04/03/2024 19:14:36
QRCode
archive.org
thumbnail

The transaction, visible on Bitcoin's blockchain, suggests the victim of one of the worst ransomware attacks in years may have paid a very large ransom.

wired EN 2024 ransomware bitcoin blockchain crime healthcare ALPHV Alphv-BlackCat
ALPHV/BlackCat hits healthcare after retaliation threat, FBI says https://www.scmagazine.com/news/alphv-blackcat-hits-healthcare-after-retaliation-threat-fbi-says?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
04/03/2024 12:35:41
QRCode
archive.org
thumbnail

The gang claimed responsibility for a high-profile attack against Change Healthcare Wednesday.

scmagazine EN 2024 CISA ALPHV BlackCat FBI CISA Healthcare
US prescription market hamstrung for 9 days (so far) by ransomware attack | Ars Technica https://arstechnica.com/security/2024/03/us-prescription-market-hamstrung-for-9-days-so-far-by-ransomware-attack/
03/03/2024 20:08:28
QRCode
archive.org
thumbnail

Patients having trouble getting lifesaving meds have the AlphV crime group to thank.

arstechnica EN 2024 AlphV ransomware US prescription Healthcare
New RustDoor macOS malware impersonates Visual Studio update https://www.bleepingcomputer.com/news/security/new-rustdoor-macos-malware-impersonates-visual-studio-update/
09/02/2024 17:20:46
QRCode
archive.org
thumbnail

A new Rust-based macOS malware spreading as a Visual Studio update to provide backdoor access to compromised systems uses infrastructure linked to the infamous ALPHV/BlackCat ransomware gang.

bleepingcomputer EN 2024 ALPHV Backdoor BlackCat Data-Exfiltration macOS Malware Ransomware
ALPHV Ransomware Claims Cyberattack on US Firm Ultra Intelligence and Communications https://thecyberexpress.com/cyberattack-on-ultra-intelligence-and-communications/
07/01/2024 12:50:41
QRCode
archive.org
thumbnail

Russian-speaking BlackCat/ALPHV ransomware group has claimed to have carried out a cyberattack on Ultra Intelligence and Communications, a US-based company

thecyberexpress EN 2023 ALPHV US Ultra-Intelligence-&-Communications
Ransomware : Alphv/BlackCat, touché et presque coulé ? https://www.lemagit.fr/actualites/366563912/Ransomware-Alphv-est-tombe-mais-BlackCat-sest-releve
19/12/2023 15:16:50
QRCode
archive.org

Le site vitrine de la franchise Alphv/BlackCat affiche désormais un message indiquant qu’il a été saisi par les autorités. Mais une vitrine alternative est en ligne, mais le coup est très sérieux.

lemagit FR 2023 Alphv BlackCat Alphv-BlackCat Ransomware vitrine
Justice Department Disrupts Prolific ALPHV/Blackcat Ransomware Variant | United States Department of Justice https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant
19/12/2023 15:12:33
QRCode
archive.org
thumbnail

The Justice Department announced today a disruption campaign against the Blackcat ransomware group — also known as ALPHV or Noberus — that has targeted the computer networks of more than 1,000 victims and caused harm around the world since its inception, including networks that support U.S. critical infrastructure.

justice.gov EN 2023 ALPHV Blackcat ransomware group Disrupts announce
Authorities claim seizure of notorious ALPHV ransomware gang's dark web leak site | TechCrunch https://techcrunch.com/2023/12/19/alphv-blackcat-ransomware-seizure/
19/12/2023 15:10:57
QRCode
archive.org
thumbnail

The FBI says it has released a decryption tool allowing hundreds of ALPHV/BlackCat victims to restore their scrambled files.

techcrunch EN 2023 ALPHV BlackCat cyberattack cybersecurity law-enforcement ransomware seizure
AlphV’s bid to report its victim to the SEC could backfire https://readme.synack.com/alphvs-bid-to-report-its-victim-to-the-sec-could-backfire
13/12/2023 09:13:47
QRCode
archive.org
thumbnail

The ransomware group AlphV reported a victim to the SEC for failing to report a cybersecurity incident, placing government regulators in a precarious position.

synack.com EN AlphV SEC report strategy
SIM Swappers Are Working Directly with Ransomware Gangs Now https://www.404media.co/sim-swappers-are-working-directly-with-ransomware-gangs-now/
27/10/2023 13:54:34
QRCode
archive.org
thumbnail

Hackers connected to “the Comm,” a nebulous group that includes SIM swappers, are working with ALPHV, a ransomware group that has impacted some of the biggest companies on the planet, including MGM Casinos.

404media EN 2023 ALPHV the-Comm SIMSwappers ransomware
page 1 / 2
4961 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn