DOJ Watch: July 10, 2026 — Ransomware Insider Who Betrayed Victims Gets 70 Months

ByEduardo Bacci

July 10, 2026
The Robert F. Kennedy Department of Justice Building, headquarters of the U.S. Department of Justice in Washington, D.C.U.S. Department of Justice headquarters, Washington, D.C. (Public domain photo via Wikimedia Commons)

DOJ Watch is The Investigative Journal’s daily digest of federal enforcement activity, drawn entirely from public Justice Department records, court filings, and official announcements. Every case below links to its primary source. Charges described as allegations remain unproven, and defendants who have not been convicted are presumed innocent.

The Justice Department’s public docket over July 8 and 9, 2026 captured the breadth of federal enforcement in a single 48-hour window: a cybersecurity insider who sold out the ransomware victims he was paid to protect, a decade-long investment fraud that swept in more than 10,000 investors, a telehealth executive convicted of flooding the country with stimulants, and two national security sentencings that closed out separate terrorism and violent-extremism prosecutions. Those actions arrived on the heels of one of the largest corporate resolutions of the year — a $600 million settlement with Alibaba and its U.S. payment affiliate. Below, TIJ summarizes eight notable enforcement actions, what the records show, and why they matter.

1. Ransomware negotiator who betrayed his own clients sentenced to 70 months

Angelo Martino, 41, of Land O’Lakes, Florida, was sentenced on July 9 to 70 months in prison in the Southern District of Florida for conspiring with operators of the BlackCat/ALPHV ransomware variant to extort multiple U.S. victims. According to court documents, Martino was employed at a U.S.-based cyber incident-response firm — the very kind of company businesses hire to help them survive a ransomware attack — and beginning in April 2023 he was paid by BlackCat actors to hand over the confidential negotiating positions and strategy of his employer’s clients, allowing the attackers to drive ransoms higher.

Prosecutors said Martino went further, conspiring with two other former cybersecurity professionals, Kevin Martin, 36, of Texas, and Ryan Goldberg, 41, of Georgia, to deploy BlackCat ransomware against additional victims between April and November 2023. After extorting one victim for roughly $1.2 million in Bitcoin, the three split the proceeds and laundered the funds, records indicate. Martino pleaded guilty on April 14 to a single count of conspiring to interfere with interstate commerce through extortion; Martin and Goldberg were each sentenced to 48 months in May. To date, law enforcement has seized approximately $10 million in assets tied to the scheme, including cryptocurrency, vehicles, a food truck and a luxury fishing boat. A restitution hearing is set for September 17.

The significance here is the insider-threat dimension. The Justice Department framed the case as part of Operation Riptide, the FBI’s sustained campaign against cyber-enabled crime, and officials emphasized that they will pursue not only the hackers who deploy ransomware but the trusted professionals who enable them. For companies that rely on incident-response vendors during their most vulnerable moments, the case is a pointed warning about supply-chain and personnel risk inside the security industry itself.

2. Alibaba and Alipay US affiliate to pay $600 million over illegal marketplace sales

Alibaba Group Holding Limited and its U.S.-based payment processor, AUS Merchant Services Inc. (formerly Alipay US), entered a non-prosecution agreement on July 1 to pay $600 million to resolve Justice Department allegations that they failed to prevent merchants from selling and importing illegal pharmaceuticals, controlled substances, listed chemicals and pill-press equipment into the United States through Alibaba.com and AliExpress.com. The resolution, reached in the District of Rhode Island, is the largest monetary settlement in that district’s history.

According to the agreement, Alibaba admitted that between January 2016 and December 2024 it failed to stop roughly 80,000 product sales involving U.S. imports, with a combined gross merchandise value exceeding $200 million. Federal agents made more than 40 undercover purchases of pharmaceuticals and counterfeiting equipment during the investigation. AUS separately admitted that gaps in its anti-money-laundering and transaction-monitoring systems allowed some Alibaba merchants to route payments through U.S. bank accounts. Under the agreement, Alibaba will pay a $125 million criminal penalty and forfeit $200 million, while AUS will pay an $85 million penalty and forfeit $190 million; both companies agreed to strengthen compliance and cooperate with future investigations.

The case is a significant statement on platform liability. The department credited the companies’ remedial steps and cooperation in structuring a non-prosecution agreement rather than an indictment — a resolution model that TIJ will continue to scrutinize for whether such settlements meaningfully change corporate behavior or function as a cost of doing business for the world’s largest e-commerce operators.

3. Telehealth founder convicted in $90 million Adderall scheme sentenced

Ruthia He, founder and former chief executive of the California-based digital mental-health company Done Global Inc., was sentenced on July 7 to six years in prison and a $1 million fine in the Northern District of California for orchestrating a scheme that used the company’s technology platform, incentive structure and clinical protocols to unlawfully distribute more than 37 million pills of Adderall and defraud insurers of over $12 million. Co-defendant David Brody, the company’s former clinical president, was separately sentenced to two years. Both were convicted at trial in November 2025.

According to trial evidence, the defendants built a “subscription for prescription” model that paid clinicians who signed Adderall prescriptions rapidly while pressuring or firing those who resisted, and used an auto-refill feature that kept stimulants flowing to some patients who went years without a clinical visit — in some instances continuing after patients had died. Prosecutors said He later moved operations and assets to China, used disappearing-message apps, deleted records, and researched non-extradition countries as investigators closed in. The department described the prosecution as a landmark case for its Health Care Fraud Unit.

The implications extend across the telehealth sector, which expanded rapidly during and after the pandemic. Records in this case detail how growth-at-all-costs incentives can be engineered directly into a digital health platform, and the outcome signals that federal prosecutors will hold corporate decision-makers — not only individual prescribers — responsible for controlled-substance distribution.

4. Co-conspirators sentenced in $45 million fraud targeting thousands of investors

Neil Suresh Chandran, 54, a foreign national residing in Nevada and California, and Bryan Lee, 60, of Las Vegas, were sentenced on July 9 to 136 months and 36 months in prison, respectively, in the District of Nebraska for a scheme that defrauded thousands of investors between 2018 and 2022. According to court documents, Chandran created companies he falsely claimed were about to be acquired by a consortium of billionaires at extraordinary valuations, and he and others solicited more than $45 million from over 10,000 investors on the strength of those misrepresentations.

Lee served as the nominee owner and sole officer of ViMarket, a Chandran-controlled entity that received millions in investor funds. Prosecutors said the two spent investor money on luxury cars and real estate. Chandran pleaded guilty to mail fraud and Lee to conspiracy to commit mail and wire fraud in April 2026. The FBI’s Washington Field Office investigated. The case is a reminder that affinity- and hype-driven investment schemes — promising imminent buyouts or guaranteed returns — remain among the most durable forms of financial fraud, and that recovery for victims often lags far behind the losses.

5. Member of ‘764’-linked extremist network sentenced to 40 years

Alexis Aldair Chavez, 19, of San Antonio, was sentenced on July 8 to 40 years in prison, followed by lifetime supervised release, in the Western District of Texas for racketeering activity and offenses related to the sexual exploitation of children. According to court documents, Chavez was an administrator and online leader of the “8884” network, an offshoot of the broader “764” nihilistic violent extremist movement that federal officials say seeks to sow social instability by coercing vulnerable victims — including minors — into acts of self-harm, violence and exploitation.

Chavez pleaded guilty in December 2025 to one count of racketeering and two child-exploitation counts. The Justice Department’s National Security Division and the FBI’s Counterterrorism Division handled the case, and prosecutors used the sentencing to urge parents to monitor their children’s online activity. The case reflects a growing federal focus on 764-linked networks, which the department has described as an evolving domestic and transnational threat that operates across gaming platforms, chat apps and social media. TIJ is tracking the wave of related prosecutions as a distinct enforcement trend.

6. Maryland man sentenced to 15 years for attempting to support ISIS

Michael Sam Teekaye Jr., 22, of Maryland, was sentenced on July 8 to 15 years in prison, followed by lifetime supervised release, for attempting to provide material support to ISIS. According to court documents, Teekaye told an undercover officer he wanted to travel abroad to fight for the group and described a “plan B” to carry out an attack in the United States. Prosecutors said he purchased ammunition and range time, attempted to buy a rifle, and had obtained travel documents and airline tickets before FBI agents arrested him at Baltimore/Washington International Airport in October 2024.

Teekaye pleaded guilty in January 2026 to one count of attempting to provide material support to a designated foreign terrorist organization. The department noted that searches on his phone included specific Jewish and Israeli individuals and organizations, and that a rabbi provided a victim-impact statement at sentencing. The prosecution, handled by the FBI’s Joint Terrorism Task Force and the National Security Division, illustrates the continued use of undercover operations to interdict aspirational attackers before they act.

7. Michigan tax preparers indicted in alleged false-return conspiracy

A federal grand jury in the Eastern District of Michigan returned an indictment on July 9 charging three tax preparers — Jamar Harten of Shelby Township, Tabitha Scott of Davisburg, and Tyree Monroe Jr. of Detroit — with conspiring to defraud the United States and preparing false tax returns. According to the indictment, the three worked at Harten’s business, First Class Tax and Consulting, and allegedly prepared returns containing fraudulent deductions and credits that generated refunds their clients were not entitled to receive.

The charges are allegations, and all three defendants are presumed innocent unless and until proven guilty. If convicted, each faces up to five years in prison for the conspiracy count and three years for each count of assisting in the preparation of a false return. IRS Criminal Investigation is handling the case, which the department attributed to its newly created National Fraud Enforcement Division. It is one of several recent tax-preparer prosecutions — three preparers in Texas were sentenced the prior day in a separate scheme — underscoring a sustained federal emphasis on return-preparer fraud heading into future filing seasons.

8. Bulgarian national charged with stealing $290,000 in forfeited cryptocurrency

Rossen G. Iossifov, 53, a Bulgarian national already serving a federal sentence, made an initial appearance in the Eastern District of Kentucky on charges announced July 9, including removal of property to prevent seizure and conspiracy to commit money laundering. Prosecutors allege that in January 2024 Iossifov conspired to move roughly $290,000 in cryptocurrency that had been ordered forfeited to the United States following his 2021 conviction, routing it through multiple exchanges and mixing services.

The allegations are unproven, and Iossifov is presumed innocent. Records indicate he was serving a 111-month sentence tied to an earlier online auction fraud scheme in which, according to trial evidence, he had laundered nearly $5 million in cryptocurrency over less than three years and was ordered to pay more than $2.6 million in restitution. If convicted on the new charges, he faces up to 25 years in prison. The U.S. Secret Service investigated. The case is an unusual test of the government’s ability to secure assets it has already won in court — a recurring challenge as forfeiture increasingly involves cryptocurrency that can be moved from behind bars.

Cases TIJ is watching

Several threads from this week’s docket warrant deeper reporting. The first is the 764/nihilistic violent extremist network: the San Antonio sentencing is one of a growing number of federal cases against this decentralized online movement, and the pattern of prosecutions raises questions about scale, recruitment and the platforms involved. The second is the China nexus in the Done Global case — records describe the founder moving operations and assets abroad and researching non-extradition countries, a fact pattern that intersects with broader questions about cross-border accountability for U.S.-facing digital-health ventures.

The third is the insider threat inside the cybersecurity industry. The Martino prosecution, arriving the same week the department highlighted the extradition of an alleged “Scattered Spider” member, suggests federal attention is shifting toward the professionals and intermediaries who enable ransomware, not just the operators. Finally, the Alibaba non-prosecution agreement invites scrutiny of whether large corporate settlements — even record ones — produce durable compliance change or simply price in the risk. TIJ will continue to follow these cases as they develop.


Sourcing note: This digest is based on U.S. Department of Justice press releases and related court records published July 1–9, 2026, each linked above. Figures, charges and sentences are as stated in those public records. Where cases remain pending, allegations are unproven and defendants are presumed innocent. TIJ summarizes source material in its own words and quotes sparingly under fair use.

ByEduardo Bacci

Investigative journalist and founder of The Investigative Journal. Specializing in OSINT-driven reporting on corporate malfeasance, government accountability, and institutional corruption.