Florida Ransomware Negotiator Sentenced to 70 Months for Conspiring With Hackers He Was Hired to Fight

A Florida man who worked as a ransomware negotiator for a U.S. cybersecurity firm has been sentenced to 70 months in prison for conspiring with hackers to deploy ransomware against the same kinds of companies he was ostensibly hired to protect. Angelo Martino, 41, of Land O'Lakes, was sentenced this week after pleading guilty to conspiracy to deploy ransomware and extort U.S. victims, according to the Department of Justice. The plea itself was entered and announced on April 20, 2026, per an earlier DOJ filing.
Martino was employed by DigitalMint, a cybersecurity company that provides ransomware negotiation and incident-response services, according to CyberScoop. Rather than acting purely as an intermediary between victim companies and extortionists, prosecutors say Martino used his position to work directly with the hackers he was supposedly negotiating against, feeding them information and helping structure attacks against U.S. companies throughout 2023, as detailed by TechCrunch.
The government seized more than $10 million in cryptocurrency and other assets tied to Martino's conduct, including a food truck and a luxury fishing boat allegedly purchased with proceeds from the hacks, per the same TechCrunch report and the DOJ's announcement. The scale of the forfeiture, set against a documented single-attack payout of roughly $1.2 million split three ways after laundering, gives some indication of how much of the group's wealth accumulation depended on the ransomware-as-a-service economics of the operation rather than any one large payday.
Martino is the third person to be incarcerated in connection with this scheme. Kevin Martin and Ryan Goldberg, both described as cybersecurity professionals, were previously sentenced for their roles, according to TechCrunch's reporting. All three used BlackCat ransomware — also known as ALPHV, a ransomware-as-a-service platform through which affiliates lease access to the malware and infrastructure in exchange for a cut of extortion proceeds — to compromise victim networks.
BlackCat carries particular notoriety in the ransomware landscape. The strain was used in the February 2024 breach of Change Healthcare, an attack that exposed the medical and billing data of more than 192 million people in the United States, per TechCrunch. That incident, one of the largest healthcare data breaches on record, disrupted pharmacy and billing operations nationwide and is unrelated to Martino's specific attacks but stems from the same malware family and underlying affiliate model.
The U.S. Attorney's Office for the Southern District of Florida prosecuted the case, according to DOJ's Southern District filing.
What makes this case distinct from the broader run of ransomware prosecutions is the insider position of the perpetrators. Ransomware negotiation firms occupy a role built almost entirely on trust: victim organizations, often mid-crisis and facing existential operational risk, hand these firms visibility into their incident response, their willingness to pay, and sometimes their cyber insurance limits. A negotiator who is simultaneously coordinating with the attacker inverts that trust relationship in a way that few other insider-threat scenarios can match, since the negotiator sees both sides of the transaction in real time.
Worth flagging: this case is likely to accelerate conversations already underway in the incident-response industry about vetting, oversight, and potential conflicts of interest at ransomware negotiation firms, particularly given that negotiators sometimes have latitude over which threat actors they engage with and how transparently they report back to victims and insurers. DigitalMint itself has not been accused of wrongdoing as a company in the materials reviewed here, and the facts as reported concern Martino's individual conduct rather than any institutional failure, but the episode nonetheless sits inside a live industry debate about whether negotiation firms need more external audit of their internal handling of cases.
The broader context here is that ransomware-as-a-service has professionalized both the criminal supply chain and, unintentionally, its point of failure. BlackCat's affiliate structure meant that Martino, Martin, and Goldberg didn't need to build or maintain their own malware — they needed access, targeting information, and a channel to launder proceeds, all of which their day jobs in cybersecurity incident response could plausibly supply. That three custodians of victim trust ended up on the other side of the table, across a scheme spanning multiple prosecutions and multiple years, is the detail likely to draw the most scrutiny from corporate security teams and insurers evaluating which vendors get access to breach response.


