Technology

Ransomware Negotiator Who Sold Out His Own Clients Gets 70 Months

Martin HollowayPublished 3w ago5 min readBased on 2 sources
Reading level
Ransomware Negotiator Who Sold Out His Own Clients Gets 70 Months

Angelo Martino, a 41-year-old ransomware negotiator from Land O'Lakes, Florida, has been sentenced to 70 months in prison after pleading guilty to conspiring to interfere with interstate commerce through extortion Engadget. The sentence falls well short of the 20-year statutory maximum, but far exceeds the 24-month term Martino had sought under his plea agreement Engadget.

Martino worked for DigitalMint, a firm that negotiates ransom payments on behalf of ransomware victims, and was assigned to handle the cases at the center of the scheme. DigitalMint has cooperated fully with investigators and says it had no knowledge of Martino's conduct Engadget.

Beginning in April 2023, Martino colluded with the BlackCat ransomware group, also known as ALPHV, selling the gang confidential details about victims' negotiating strategies and financial positions so it could extract larger ransom payments Engadget. The arrangement inverted the basic premise of the job: a negotiator hired to minimize a client's exposure was instead feeding the attacker the leverage needed to maximize it.

Four companies and a non-profit fell victim to the scheme, paying ransoms ranging from $213,000 to $26.8 million, for a combined total exceeding $75 million Engadget. Martino did not limit his involvement to intelligence-sharing. Together with two co-conspirators, he also deployed ransomware directly against five additional victims, including a medical device company that ultimately paid a $1.2 million ransom Engadget. Both co-conspirators were previously sentenced to 48 months each.

As part of the case, law enforcement seized $10 million in assets traced to the scheme. Martino must also pay 10 percent of any post-release salary toward victim restitution Engadget. Brett Leatherman, assistant director of the FBI's Cyber Division, said Martino "sold out the very victims he was hired to represent" Engadget.

The case closes out one thread of a broader federal effort against BlackCat, which the Department of Justice announced it had disrupted in December 2023. That operation included a decryption tool the FBI distributed to more than 500 BlackCat victims, sparing them over $68 million in ransom payments the gang would otherwise have collected, alongside a standing reward of up to $10 million for information on BlackCat administrators and affiliates Engadget.

The ransomware negotiation industry occupies an unusual position in the incident response ecosystem: firms like DigitalMint, Coveware and GroupSense operate as trusted intermediaries handling cryptocurrency payments, threat actor communications and OFAC sanctions screening on behalf of breached organizations, often at the most acute moment of a company's operational crisis. That trust model depends entirely on the assumption that the negotiator's incentives align with the client's, not the attacker's.

Martino's case demonstrates a specific failure mode within that model: an insider with legitimate access to victim financials and negotiating posture monetizing that access on the other side of the table. Worth flagging is that this is a different threat surface than the technical intrusion vectors most CISOs plan around. No firewall, EDR deployment, or zero-trust segmentation addresses a negotiator selling information to the attacker directly. The exposure sits in vendor vetting, contractual controls and possibly in structural questions about how much unsupervised discretion a third-party negotiator should have during an active incident.

In this author's view, the case is likely to prompt renewed scrutiny of how organizations select and monitor incident response vendors during a live ransomware event, when time pressure and technical urgency tend to compress the vetting that would ordinarily accompany bringing an outside party into sensitive financial and legal discussions. Cyber insurance carriers, who frequently mandate or recommend specific negotiation firms as part of a covered incident response panel, may face pressure to add auditing or oversight requirements to those panel relationships.

The broader disruption of BlackCat itself illustrates a pattern that has recurred across several major ransomware takedowns: technical countermeasures, in this instance a working decryptor distributed to hundreds of victims, combined with financial incentives aimed at insiders and affiliates, have proven more durable than infrastructure seizures alone, since ransomware-as-a-service groups tend to reconstitute under new branding once their backend is disrupted. Whether BlackCat's operators have resurfaced elsewhere is not addressed in the current record, but the mechanics of this case, an insider selling access rather than a purely external intrusion, add a data point to how ransomware economics extend well beyond the malware itself into the professional services layer built around incident response.