Ryuk operator pleads guilty as AlphV conspirator draws 70 months
Two federal cases mark rare prosecutions of ransomware operators, with convictions in Oregon and Florida targeting Ryuk and Blackcat infrastructure.
A man accused of deploying Ryuk ransomware pleaded guilty Wednesday in Oregon federal court to conspiracy and computer fraud charges. The plea represents one of the few successful prosecutions of a hands-on-keyboard ransomware operator in U.S. jurisdiction.
Separately, a Florida federal court sentenced another individual to 70 months in prison for assisting the Blackcat/AlphV ransomware operation. The defendant helped the gang extort multiple victims, though the court record does not specify the number of organizations compromised or total ransom demands.
Both Ryuk and Blackcat represent top-tier ransomware operations. Ryuk, active from 2018 through 2021, targeted hospitals, municipalities, and enterprises, often demanding seven-figure payments. Blackcat—also known as AlphV—emerged in late 2021 as a ransomware-as-a-service platform and became one of the most prolific operations before an FBI disruption campaign in late 2023. The group resurfaced briefly in 2024.
- 01Ransomware operators face tangible prosecution risk if they enter cooperative jurisdictions or operate domestically.
- 02Organizations previously hit by Ryuk or Blackcat may see investigative leads resurface during sentencing proceedings.
- 03Cybersecurity insurers may adjust risk models as conviction rates for ransomware actors slowly increase.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.