Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks


Rogue employees of a Chicago company that specializes in negotiating ransoms to mitigate cyber attacks were carrying out their own piracy in a plot to extort millions of dollars from a series of companies, prosecutors say.

Kevin Tyler Martin, a ransomware threat negotiator for River North-based DigitalMint at the time of the alleged conspiracy, was among two men indicted in the scheme. A suspected accomplice who wasn’t indicted was also employed at DigitalMint, court records show.

Read more…
Source: Chicago Sun News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau

    October 3, 2026

    A suspected member of the ShinyHunters hacking group, which ​says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif ‌al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought ...

  • AI agents aggressively tried to hack US and Canadian government websites

    October 2, 2026

    AI agents simply won’t take ‘no’ for an answer. Security researchers from nonprofit Transluce found bots making numerous attempts to hack US and Canadian government websites in search of private information. In a new report, Transluce singled out two incidents: one against the US Department of Education, and one against Library and Archives Canada. Both seem ...

  • SMTP is the key: BPFDoor and AVERAT hitting the network edge

    October 2, 2026

    Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese ...

  • Operation KillSwitch: Teenager suspected of leading KillSec ransomware group

    October 1, 2026

    On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German ...

  • Hackers steal protective order and foster care records from Arizona courts

    September 30, 2026

    This is how the Arizona Supreme Court announced that hackers had attacked the state’s court system and stolen the personal information of “many Arizonans.” The court says the attack began with a phishing email containing a malicious link that a court employee clicked. The attackers copied sensitive backup files containing records related to protective orders and foster ...

  • ShinyHunters hackers are going after Oracle systems once again

    September 29, 2026

    ShinyHunters have found a way to bypass a mitigation for a zero-day they previously exploited – so now, not only are they back to abusing the same bug, they’ve even expanded their scope to target a much larger pool of organizations. In June 2026, it was reported that ShinyHunters, the infamous data extortionists, found a Java ...