Last Update: 09/22/2026 at 11:34 PM EST
BlackCat Ransomware Insider Misuse
Coverage from BleepingComputer, The Record, and others

Recent U.
S. enforcement actions and prison sentences show former ransomware negotiators and incident response workers using insider access to help BlackCat extort victims, leak data, and split ransom proceeds.
Looking Back
71 Day Timeline
May 1
May 13
May 25
Jun 6
Jun 16
Jun 28
Jul 10
History
07/21/2026
The story has broadened from a narrow sentencing-focused BlackCat matter into a larger enforcement narrative centered on insider misuse by ransomware negotiators and incident response workers. The current version adds a new defendant and frames the cases more explicitly around coordinated extortion, payment-sharing, and data-access abuse.
All Articles6 articles
Additional
6/7/2026 • Cybersecurity (Privacy-Relevant) • General
5/1/2026 • Cybersecurity (Privacy-Relevant) • General
5/1/2026 • Cybersecurity (Privacy-Relevant) • General
7/10/2026 • Cybersecurity (Privacy-Relevant) • General
5/1/2026 • Cybersecurity (Privacy-Relevant) • General
7/10/2026 • Cybersecurity (Privacy-Relevant) • General
