Last Update: 09/22/2026 at 11:34 PM EST

BlackCat Ransomware Insider Misuse

Coverage from BleepingComputer, The Record, and others

BlackCat Ransomware Insider Misuse topic image

Recent U.

S. enforcement actions and prison sentences show former ransomware negotiators and incident response workers using insider access to help BlackCat extort victims, leak data, and split ransom proceeds.

Looking Back
71 Day Timeline
May 1May 15May 29Jun 12Jun 26Jul 10
History
07/21/2026

The story has broadened from a narrow sentencing-focused BlackCat matter into a larger enforcement narrative centered on insider misuse by ransomware negotiators and incident response workers. The current version adds a new defendant and frames the cases more explicitly around coordinated extortion, payment-sharing, and data-access abuse.

All Articles6 articles
Additional6 articles · CI Score below 45
BleepingComputer / Lawrence Abrams
6/7/2026 • Cybersecurity (Privacy-Relevant) • General
The Record / Jonathan Greig
5/1/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Sergiu Gatlan
5/1/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Sergiu Gatlan
7/10/2026 • Cybersecurity (Privacy-Relevant) • General
The Hacker News
5/1/2026 • Cybersecurity (Privacy-Relevant) • General
TechCrunch
7/10/2026 • Cybersecurity (Privacy-Relevant) • General