The BlackCat insider case involved five victim organisations
Assessment
There are two separate groups of five in this case, and coverage reporting "five victims" appears to describe only the first. The first group is the organisations whose networks the defendants attacked as BlackCat affiliates — reported as a Tampa medical device manufacturer, a Maryland pharmaceutical company, a California doctor's office, a California engineering firm and a Virginia drone manufacturer. The second group is distinct. The Department of Justice states that Angelo Martino was "working as a negotiator on behalf of five different ransomware victims" when he provided BlackCat attackers with confidential information about their negotiating position and strategy, including insurance policy limits. Those five were attacked by other BlackCat actors. The defendants did not breach them. What the defendants did was ensure they paid more than they otherwise would have. The second group are victims of this case in a real sense — they suffered a quantifiable financial harm caused by a defendant's conduct — and they are absent from the count that circulates. Rated Unverified rather than False because "five" is accurate for the group most reporting describes. What is unsupported is its use as the total, and the omission is not incidental: the missing five are the victims of the conduct that makes this case unusual.
Where this claim appeared
TechCrunch · 2025-11-03
https://techcrunch.com/2025/11/03/doj-accuses-us-ransomware-negotiators-of-launching-their-own-ransomware-attacks/What “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
BlackCat Insider Case: Ransomware Negotiators Who Attacked and Betrayed Their Own ClientsThink this assessment is wrong? Report an error.