Two former cybersecurity employees have been sentenced to four years in prison for their roles in BlackCat ransomware attacks targeting U.S. companies. The convictions mark a rare case of insider involvement in major ransomware operations.
The defendants worked for incident response firms Sygnia and DigitalMint before participating in BlackCat (ALPHV) attacks. Their positions gave them access to sensitive information about victims and incident response strategies, which they leveraged for the ransomware operation.
BlackCat emerged as one of the most prolific ransomware-as-a-service groups, targeting hundreds of organizations across critical infrastructure and other sectors. The group demanded millions in ransom payments and threatened to leak stolen data.
The case underscores vulnerabilities within the cybersecurity industry itself, where trusted employees can become threats. Insider involvement in ransomware operations complicates detection and response efforts, as attackers gain knowledge of defensive measures.
Federal prosecutors have intensified efforts against ransomware actors and their facilitators following increased attacks on critical infrastructure and healthcare systems. These convictions reflect broader enforcement actions against individuals supporting major cybercriminal groups.
Anthropic has signed out some Claude users and removed saved payment methods after infostealer malware on their computers hijacked active sessions to drain API usage credits. The company is issuing refunds for unauthorized charges.
Former NYC Traffic Commissioner Sam Schwartz warns that autonomous vehicle expansion creates significant cybersecurity risks, including the potential for bad actors to seize control of connected cars and weaponize them.
More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.
A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.