BlackCat Ransomware Insider Attack Campaign | MSSP Advisory
Critical
DateMay 1, 2026
📋Executive Summary
Two cybersecurity professionals received four-year prison sentences for deploying BlackCat ransomware against multiple U.S. victims between April and December 2023. Ryan Goldberg of Georgia and Kevin Martin of Texas used their cybersecurity credentials to facilitate these attacks. The DoJ prosecution demonstrates that insider threats from credentialed security professionals represent an active enforcement priority.
⚠️Why It Matters for MSSPs
Your clients trust you with administrative access to their most sensitive systems, making this case a direct threat to MSSP credibility and client retention. Every client conversation about security now includes the question of whether their MSSP could go rogue. Background checks and security clearances mean nothing when professionals with legitimate credentials choose to become threat actors.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Insider Threat
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.