A former ransomware negotiator who was hired to help organizations respond to cyber extortion incidents has been sentenced to 70 months in federal prison after admitting he secretly worked with BlackCat ransomware affiliates, using confidential client information to increase ransom payments while participating in additional ransomware attacks.
The U.S. Department of Justice said Angelo Martino, 41, abused his position at incident response firm DigitalMint by sharing privileged information obtained during ransomware negotiations with BlackCat, also tracked as ALPHV. Prosecutors said the information allowed the ransomware group to negotiate from a stronger position while victims remained unaware that details intended to protect them had been disclosed to the attackers.
As part of his role, Martino managed active ransomware cases for organizations seeking assistance after cyberattacks. His work gave him access to confidential information that companies typically share only with trusted negotiators, including cyber insurance policy limits, internal assessments of how much they were prepared to pay, and negotiation strategies developed during incident response.
According to court documents, Martino began providing that information to BlackCat operators in April 2023. Prosecutors said he communicated with the group through multiple channels connected to BlackCat's extortion platform. While one conversation took place through the standard negotiation interface used during ransomware incidents, he also relied on an intermediary chat feature within the group's panel and the encrypted messaging application Tox to exchange information directly with the attackers outside the victims' view.
Federal prosecutors said those private communications were intended to help BlackCat maximize ransom demands. In exchange for sharing confidential information, including insurance coverage limits and the negotiating positions of victim organizations, Martino received a portion of the cryptocurrency paid by ransomware victims.
The Justice Department said five organizations whose cases were handled by Martino collectively paid more than $75 million to BlackCat affiliates between April and September 2023. Prosecutors argued that access to confidential negotiation data enabled the attackers to demand higher payments than they otherwise might have secured. The affected organizations operated in the financial services, healthcare, retail, hospitality, and nonprofit sectors, with several experiencing operational disruption alongside the financial losses associated with the attacks.
Investigators also determined that Martino later became an active participant in BlackCat's ransomware operation. In May 2023, he obtained affiliate access to the ransomware-as-a-service platform, permissions generally granted to trusted partners responsible for compromising victim networks and deploying the malware.
Court filings state that Martino shared those affiliate credentials with Kevin Martin and Ryan Goldberg, both cybersecurity professionals. The three men subsequently carried out additional ransomware attacks and agreed to divide ransom proceeds among themselves while paying 20% of each payment to BlackCat's administrators in exchange for continued access to the group's malware and extortion infrastructure.
One attack targeted a medical device manufacturer that ultimately paid approximately $1.2 million in ransom. Other organizations refused to pay but still incurred costs associated with business interruption, system recovery, and incident response following the attacks.
Prosecutors said Martino received millions of dollars in cryptocurrency through the conspiracy. Federal investigators recovered and seized more than $10 million in assets connected to the case, although authorities said some proceeds had already been used to purchase residential properties, vehicles, and a boat. As part of his sentence, Martino must forfeit assets linked to the criminal activity and pay 10% of his future income following his release from prison.
Before sentencing, Martino requested a reduced 24-month prison term, citing his cooperation with investigators during the prosecution of his co-conspirators. Martin and Goldberg were each sentenced to four years in prison earlier this year after pleading guilty for their involvement in the BlackCat attacks.
"Angelo Martino sold out the very victims he was hired to represent, handing their confidential negotiating positions to BlackCat actors to drive up ransoms and enrich himself," FBI Cyber Division Assistant Director Brett Leatherman said following the sentencing.
BlackCat operates as a ransomware-as-a-service platform, providing malware and extortion infrastructure to affiliates that compromise organizations and share a percentage of ransom payments with the group's administrators. The FBI has linked the operation to more than 1,000 victims and at least $300 million in ransom payments through September 2023. Although law enforcement disrupted parts of the group's infrastructure and previously released a decryptor for some victims, affiliates continued launching attacks after those actions.
DigitalMint said it was unaware of Martino's conduct until it was contacted by the Department of Justice and described itself as another victim of the scheme. The company said the employees involved were terminated immediately after the allegations came to light and that it fully cooperated with investigators throughout the criminal investigation.
The company also said Martino deliberately bypassed internal safeguards by communicating with threat actors through unauthorized channels that were not visible within its monitoring systems. According to DigitalMint, its security controls aligned with industry practices, but the unauthorized communications were intentionally concealed from the company's oversight mechanisms.
Ransomware groups claimed responsibility for 2,279 attacks worldwide during the second quarter of 2026, marking a 7% increase from the previous quarter and a 43% jump compared with the same period last year, according to GuidePoint Security's latest quarterly ransomware report. Researchers also recorded the highest number of active ransomware groups seen in a single quarter, reflecting an ecosystem that continues to attract new threat actors even as attacks remain concentrated among a relatively small number of established operations.
Despite the growing number of ransomware groups, a handful of operators continue to dominate victim claims. GuidePoint found that the five most active groups were collectively responsible for more than 40% of all publicly reported ransomware incidents during the quarter, suggesting that while new groups continue to emerge, only a few have achieved sustained operational scale.
Qilin remained the most active ransomware operation during Q2, accounting for approximately 13% of all recorded victim claims. It was closely followed by The Gentlemen, a comparatively new group that has expanded rapidly in recent months. Together with Akira and DragonForce, the two groups make up what GuidePoint describes as a "four-headed monster," representing the most prolific ransomware operations currently shaping the threat landscape.
Rather than relying on a single dominant ransomware syndicate, today's ransomware ecosystem is distributed across several highly active groups capable of absorbing affiliates from disrupted operations. Researchers noted that this structure could reduce the long-term impact of law enforcement takedowns, as affiliates displaced from one ransomware-as-a-service (RaaS) platform may quickly transition to another established operation without substantially disrupting attack activity.
The United States remained the country most frequently targeted by ransomware groups during the quarter, accounting for 40% of publicly claimed victims. Germany ranked second with 32%. However, GuidePoint observed a noticeable shift in targeting patterns, with the U.S. accounting for a smaller proportion of victims than in previous quarters, when roughly half of all reported incidents involved American organizations.
Researchers linked this broader geographic distribution to increased activity from groups including Qilin, The Gentlemen and LockBit, each of which claimed a larger share of victims outside the United States during Q2. The findings suggest that ransomware affiliates are expanding their operations across a wider range of regions instead of concentrating primarily on U.S.-based organizations.
Alongside changes in victim targeting, the report examined how artificial intelligence is being incorporated into ransomware operations. While concerns have grown around the possibility of AI creating entirely new forms of cyberattacks, GuidePoint found little evidence to support that scenario. Instead, threat actors are primarily using large language models (LLMs) to accelerate tasks that previously required significant manual effort, allowing them to improve efficiency without fundamentally changing their attack methods.
One case study highlighted in the report involved the data extortion group FulcrumSec. After obtaining a large volume of stolen information, the group reportedly used an LLM to examine complex databases and identify individuals appearing across multiple datasets. According to researchers, completing this level of analysis manually would have required either extensive knowledge of the victim's database architecture or a substantial investment of time by human operators.
The information extracted from the stolen data was then paired with AI-generated negotiation messages written in English. By demonstrating a detailed understanding of the compromised information, FulcrumSec strengthened its position during ransom negotiations, providing victims with evidence of the data in its possession while using those findings to justify its ransom demands.
GuidePoint also documented DragonForce's use of large language models during extortion negotiations. Researchers said the group generated convincing messages that sought to increase pressure on victims, including claims that it had legal counsel available to advise its operations. Although the report describes that assertion as almost certainly false, it illustrates how AI can help cybercriminals produce persuasive communications intended to exploit concerns around regulatory obligations, legal consequences and reputational damage.
According to the researchers, the effectiveness of these messages does not necessarily depend on their accuracy. Instead, their value lies in presenting information in a manner that appears credible enough to influence decision-making during negotiations. Large language models, which are capable of generating fluent and convincing text within seconds, are increasingly being used to support these psychological tactics.
Taken together, the findings indicate that AI is currently serving as an operational force multiplier rather than introducing an entirely new category of ransomware attacks. Tasks such as analyzing stolen data, organizing information, preparing victim communications and drafting negotiation messages can now be completed more quickly, enabling threat actors to devote more time to other stages of their operations.
At the same time, the continued concentration of attacks among a small group of highly active ransomware operations suggests that scale, organization and affiliate networks remain key drivers of today's ransomware economy. While new groups continue to enter the ecosystem, a limited number of established operators continue to account for a disproportionate share of publicly claimed attacks, reinforcing their influence across the global ransomware ecosystem.
Dutch authorities have arrested multiple suspects as part of an international investigation into an alleged investment fraud network that investigators believe defrauded victims worldwide through fake online investment schemes, with the operation at one point generating more than €100 million in monthly proceeds.
According to the Dutch Police, the criminal organization is suspected of operating an extensive network of approximately 20 call centers staffed by more than 700 individuals who allegedly posed as professional financial advisers. Investigators said the operation targeted victims across multiple countries, with teams assigned to specific regions and responsibilities to maximize the effectiveness of the fraudulent campaigns.
The investigation's primary suspect, a 46-year-old dual Israeli-Polish national, was arrested in Poland on May 26 before being extradited to the Netherlands, where he has been placed in pre-trial detention. Dutch authorities allege that he played a central technical role in building and maintaining the infrastructure that enabled the organization to conduct its activities while making it more difficult for law enforcement agencies to identify those involved.
Police also noted that publicly available information indicates the suspect had previously faced prosecution in connection with cyberattacks targeting several foreign government organizations. Authorities now believe he occupied an indispensable position within the investment fraud network.
The investigation expanded further between July 7 and July 10, when law enforcement officers arrested several Dutch and Belgian nationals in Cyprus, Greece, and Belgium for their suspected involvement in the scheme. Officials said the investigation remains active and additional arrests are possible as authorities continue to identify other members of the organization.
Investigators describe the alleged operation as a highly organized criminal enterprise that functioned similarly to a legitimate international business. Multiple call centers reportedly operated under centralized coordination while individual teams focused on victims in different countries. Employees allegedly used false identities, pseudonyms, and technical measures designed to conceal both their real identities and their physical locations during communications with potential victims.
According to investigators, the fraud relied heavily on long-term social engineering rather than immediate financial deception. Victims were first approached by individuals presenting themselves as experienced investment advisers who gradually established trust through repeated conversations. Once that trust had been developed, victims were encouraged to invest relatively small amounts through professional-looking online investment platforms that appeared to display genuine market activity and growing returns.
Authorities said these platforms did not reflect legitimate investments. Instead, the displayed profits were fabricated to create the impression of successful trading and encourage victims to continue depositing larger sums. Many of the payments were made using cryptocurrency, making it incredibly more difficult to recover stolen funds after they had been transferred. While victims believed their portfolios were increasing in value, investigators said the money was instead diverted directly to the criminal organization.
Dutch investigators have linked at least 550 fraud reports and approximately €25 million in reported losses in the Netherlands to the organization. Belgian authorities have also connected around 200 complaints to the same network. Police believe these figures represent only a fraction of the total impact, estimating that the operation may have claimed tens of thousands of victims globally, with many individuals losing more than €10,000 each.
Authorities believe the organization has been active since at least 2021 and employed sophisticated operational security practices to avoid detection. Investigators said members routinely relied on pseudonyms, concealed calling locations, and other technical methods to obscure their identities while communicating with victims.
The investigation ultimately progressed after authorities traced digital evidence, including IP addresses, financial transaction routes, and other forensic artifacts that helped identify critical infrastructure associated with the operation. The examination of technical equipment provided investigators with additional insight into how the organization functioned and helped establish the locations of several suspects.
Dutch Police said the investigation was conducted in cooperation with international law enforcement partners, while commercial service providers also assisted in disrupting elements of the group's digital infrastructure. Authorities emphasized that efforts to identify additional suspects and victims remain ongoing.
Police have also warned the public to remain cautious of so-called recovery services that claim they can retrieve money lost to investment scams. Investigators noted that, in some cases, such offers are themselves fraudulent attempts to exploit victims a second time by demanding additional payments under the false promise of recovering stolen funds.
After this, the attacker could read chats, steal user data, and command bots to send hacker-written texts such as re-entering a password.
Cyber security firm Varonis discovered the tactic and called it ‘Rogue Agent.’ The bug impacted only businesses that make agents with custom Code Blocks and Dialogflow’s Playbooks, which allows hackers to add their own Python. The attack was not remote, or unauthorized.
For the attack to happen, it required the dialogflow.playbooks.update green light one such agent, which restricts the hacker to an infected insider or a breached developer account, not some stranger on the web. From that point, the reach extended to every agent inside the project.
Google has patched the bug, and Varonis and Google have said there are no signs that the flaw was deployed in a real attack or campaign.
Dialogflow’s Code Blocks allows developers to add custom Python to a chatbot’s flow to test input, invoke defined tools, and control behavior.
The code runs within a Google-operated Cloud Run environment, and every agent that uses Code Blocks in the similar Google Cloud project shares one incident of it. The customer cannot control or see the environment that Google runs, meanwhile Varonis discovered no real separation between the agents within it.
When the agent runs a Code Block, the code is added to internal setup code and sent to Python’s exec()function. The functions and variables that block can touch are defined by the setup.
Functions consist(), which makes the bot reply with a given string, whereas variables consist of a history of full chats and state for session information such as the session ID.
Varonis discovered code_execution_env.py, the file that does this wrapping, lying in the shared environment with write access.
As the file was writable, a single Code Block could change it. The block downloads an altered code_execution_env.py from a threat actor-controlled server and overwrites the original within the running container.
After that, the attacker’s variant commands every Code Block deployment throughout every agent that shares the environment. The attacker’s code sits in the same place as the real code, with similar access to respond(), state, and history,
The IDE is employed by more than half of the Fortune 500. Both RCE flaws, called “DuneSlide,” were given a 9.8 CVSS score. The security bugs are tracked as CVE-2026-50548 and CVE-2026-50549.
The bugs demonstrated how prompt injection can move beyond the LLM layer and reveal classical bugs in code paths that were earlier not thought of as part of the attack surface.
A threat actor can exploit either of these bugs to overwrite critical system files (such as cursorsandbox binary), changing sandboxed comments into unsandboxed RCE and resulting in a full system hack on both the victim device and linked SaaS workspaces.
Bugs found: Cato AI Labs found two separate, critical bugs in Cursor IDE, resulting in non-sandboxed RCEs on the victim’s system.
Arbitrary file write through prompt injection: Via zero-click prompt injection, these bugs could let a threat actor use zero-click prompt injections to write arbitrary files on the target’s local system.
Escaping sandbox and RCE: If leveraged, a threat actor can jump out of the terminal sandbox and attain a full RCE and a complete device exploit.
Zero-click attack vector: The exploit doesn’t need any prior user privileges or particular interaction. It is prompted when a target makes an “makes an innocuous prompt that inadvertently ingests a threat actor-controlled payload from an untrusted source, such as an MCP server or a web search result,” Cato AI Labs reported.
The first bug surfaces from how the sandbox creates its security boundaries based on tool parameters. If a sandbox command is executed, Cursor creates a seatbelt policy that allows writing into the present working directory.
This means that a remote hacker cannot command the working directory of a sandboxed operation because coding agents are a unique part of software. But, in this bug, a prompt injection works as the passageway to that part of the code.
The second vulnerability is fully independent of the first and exists in Cursor’s file path resolution edge instances. It allows hackers to avoid beyond-limits write restrictions via symbolic links.
In most traditional software, an external hacker cannot remotely generate symlinks on the target's system. In this scenario, a prompt injection changed the Cursor agent to a bridgehead for non-trivial activities that end in a full system compromise.
After an investigation of the breach, the organization discovered that between March and April, the hacker accessed files carrying personal data of employees.
It is a Japanese industrial manufacturer famous for its construction and agricultural work. Kubota has plants in 120 counties and currently employs over 52,000 people. Kubota has an annual revenue of $20 billion.
The North American division consists of facilities that make utility vehicles, tractors, and mowers.
“We discovered that files maintained by our human resources team were accessed as part of this incident. We carefully reviewed these files, and on June 16, 2026, we determined that one or more files may have contained personal information related to certain employees and their dependents,” Kubota reported on its site.
As per the announcement posted on the Kubota USA portal, the following employee information may have been revealed:
The specific data that was exposed varies per person. Kubota also started sending personalised mails to inform the individuals about the exact impact on them.
The notification information consists step by step instructions for using Kroll identity protection to help the targets address the threats coming from the leak of their personal data.
Kubota has specially advised people to look out for bank accounts and healthcare related statements and promptly report any malicious activity to the concerned authorities.
Kubot has implemented robust security measures to avoid such incidents from happening in the future.
No cybercrime gangs, data extortion gangs, or ransomware gangs have claimed responsibility for the Kubota breach.
Kubota did not report any operational or business disruptions due to the breach.
On ensuring employee safety, Kubota said, “We take the privacy and confidentiality of our employees’ information very seriously. To help prevent something like this from happening again, we have taken and will continue to take steps to further enhance our existing security measures.”