Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label BlackCat Ransomware. Show all posts

Former DigitalMint negotiator sentenced to 70 months for conspiring with BlackCat ransomware affiliates

 



A former ransomware negotiator who was hired to help organizations respond to cyber extortion incidents has been sentenced to 70 months in federal prison after admitting he secretly worked with BlackCat ransomware affiliates, using confidential client information to increase ransom payments while participating in additional ransomware attacks.

The U.S. Department of Justice said Angelo Martino, 41, abused his position at incident response firm DigitalMint by sharing privileged information obtained during ransomware negotiations with BlackCat, also tracked as ALPHV. Prosecutors said the information allowed the ransomware group to negotiate from a stronger position while victims remained unaware that details intended to protect them had been disclosed to the attackers.

As part of his role, Martino managed active ransomware cases for organizations seeking assistance after cyberattacks. His work gave him access to confidential information that companies typically share only with trusted negotiators, including cyber insurance policy limits, internal assessments of how much they were prepared to pay, and negotiation strategies developed during incident response.

According to court documents, Martino began providing that information to BlackCat operators in April 2023. Prosecutors said he communicated with the group through multiple channels connected to BlackCat's extortion platform. While one conversation took place through the standard negotiation interface used during ransomware incidents, he also relied on an intermediary chat feature within the group's panel and the encrypted messaging application Tox to exchange information directly with the attackers outside the victims' view.

Federal prosecutors said those private communications were intended to help BlackCat maximize ransom demands. In exchange for sharing confidential information, including insurance coverage limits and the negotiating positions of victim organizations, Martino received a portion of the cryptocurrency paid by ransomware victims.

The Justice Department said five organizations whose cases were handled by Martino collectively paid more than $75 million to BlackCat affiliates between April and September 2023. Prosecutors argued that access to confidential negotiation data enabled the attackers to demand higher payments than they otherwise might have secured. The affected organizations operated in the financial services, healthcare, retail, hospitality, and nonprofit sectors, with several experiencing operational disruption alongside the financial losses associated with the attacks.

Investigators also determined that Martino later became an active participant in BlackCat's ransomware operation. In May 2023, he obtained affiliate access to the ransomware-as-a-service platform, permissions generally granted to trusted partners responsible for compromising victim networks and deploying the malware.

Court filings state that Martino shared those affiliate credentials with Kevin Martin and Ryan Goldberg, both cybersecurity professionals. The three men subsequently carried out additional ransomware attacks and agreed to divide ransom proceeds among themselves while paying 20% of each payment to BlackCat's administrators in exchange for continued access to the group's malware and extortion infrastructure.

One attack targeted a medical device manufacturer that ultimately paid approximately $1.2 million in ransom. Other organizations refused to pay but still incurred costs associated with business interruption, system recovery, and incident response following the attacks.

Prosecutors said Martino received millions of dollars in cryptocurrency through the conspiracy. Federal investigators recovered and seized more than $10 million in assets connected to the case, although authorities said some proceeds had already been used to purchase residential properties, vehicles, and a boat. As part of his sentence, Martino must forfeit assets linked to the criminal activity and pay 10% of his future income following his release from prison.

Before sentencing, Martino requested a reduced 24-month prison term, citing his cooperation with investigators during the prosecution of his co-conspirators. Martin and Goldberg were each sentenced to four years in prison earlier this year after pleading guilty for their involvement in the BlackCat attacks.

"Angelo Martino sold out the very victims he was hired to represent, handing their confidential negotiating positions to BlackCat actors to drive up ransoms and enrich himself," FBI Cyber Division Assistant Director Brett Leatherman said following the sentencing.

BlackCat operates as a ransomware-as-a-service platform, providing malware and extortion infrastructure to affiliates that compromise organizations and share a percentage of ransom payments with the group's administrators. The FBI has linked the operation to more than 1,000 victims and at least $300 million in ransom payments through September 2023. Although law enforcement disrupted parts of the group's infrastructure and previously released a decryptor for some victims, affiliates continued launching attacks after those actions.

DigitalMint said it was unaware of Martino's conduct until it was contacted by the Department of Justice and described itself as another victim of the scheme. The company said the employees involved were terminated immediately after the allegations came to light and that it fully cooperated with investigators throughout the criminal investigation.

The company also said Martino deliberately bypassed internal safeguards by communicating with threat actors through unauthorized channels that were not visible within its monitoring systems. According to DigitalMint, its security controls aligned with industry practices, but the unauthorized communications were intentionally concealed from the company's oversight mechanisms.

BlackCat Ransomware Claims Breach of Healthcare Giant Henry Schein

 


The BlackCat (ALPHV) ransomware gang says they successfully hacked into Henry Schein, a major healthcare company. They claim to have taken a large amount of data, including employee payroll and shareholder information. Henry Schein operates in 32 countries and made over $12 billion in revenue in 2022. Over the past few years, BlackCat has shown a noticeable rise in malicious activities. 

The group has been targeting various sectors such as healthcare, education, electricity, and natural gas in their recent attacks. According to an FBI FLASH report from April 2022, the BlackCat/ALPHV ransomware service had successfully breached at least 60 organizations globally by the close of March 2022. 

On October 15, Henry Schein on its official website revealed Henry Schein Provides Information on Cybersecurity Incident - Henry Schein that it had to temporarily shut down some of its systems in response to a cyberattack affecting its manufacturing and distribution divisions just the day prior. 

The company acted swiftly, implementing precautionary measures like temporarily disabling certain systems and other steps aimed at containing the incident. This proactive approach has resulted in a temporary disruption to some of Henry Schein's business operations. 

The company is actively working towards a swift resolution of the situation. Despite experiencing disruptions in certain business operations, Henry Schein reassures that its Henry Schein One practice management software remains unaffected. The company has taken proactive steps by notifying pertinent law enforcement agencies about the incident. Additionally, they have enlisted the expertise of external cybersecurity and forensics professionals to probe for any potential data breach resulting from the attack. 

In a letter issued a week subsequent to revealing the cyberattack, the healthcare services provider encourages its customers to place orders through their designated Henry Schein representative or by utilizing dedicated telesales phone numbers. 

About two weeks later, the BlackCat/ALPHV ransomware group posted on their dark web leak site, saying they hacked into Henry Schein's system and took 35 terabytes of important files. Additionally, The group said they locked up the company's devices again, even after Henry Schein had almost fixed everything because they could not agree on a deal.