ThreatPaper
Unverified

The BlackCat insider attacks ran from May to November 2023

Assessment

Three windows appear across sources, and two of them are the Department of Justice's own. The sentencing announcement of 30 April 2026 states the defendants deployed ALPHV BlackCat "between April 2023 and December 2023". The Martino plea announcement of 20 April 2026 gives "April to November 2023" for the deployment conspiracy, while separately dating his disclosure of clients' negotiating positions to "beginning April 2023". Secondary reporting gives May to November 2023. The likeliest explanation is that these describe overlapping but distinct conduct — the conspiracy, the deployments, and the betrayal each having their own span — rather than any source being wrong. But that is an inference, and none of the released statements sets out which window belongs to which conduct. Recorded because dwell time and campaign duration are quantities defenders reason with, and a two-month discrepancy at both ends is not a rounding difference. This paper uses the widest documented window and says so.

Where this claim appeared

BleepingComputer · 2025-11-03

https://www.bleepingcomputer.com/news/security/us-cybersecurity-experts-indicted-for-blackcat-ransomware-attacks/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

BlackCat Insider Case: Ransomware Negotiators Who Attacked and Betrayed Their Own Clients

Think this assessment is wrong? Report an error.