Cybersecurity Negotiator Sentenced for Helping Hackers Instead of Victims

A man who worked as a ransomware negotiator for a U.S. cybersecurity company has been sent to prison for 70 months for conspiring with hackers to attack companies. Angelo Martino, 41, worked for DigitalMint, a firm hired by businesses to help them deal with ransomware attacks. Instead of helping those companies, he was working directly with the hackers, giving them information and helping them plan attacks throughout 2023, according to the Department of Justice.
When a company gets hit by ransomware — malicious software that locks up their computers and files until they pay money — these negotiators normally act as go-betweens. They talk to the attackers and try to reduce the ransom demand, much like a hostage negotiator working to get the best outcome for the victim. Martino did the opposite. He used his insider knowledge to help hackers target companies and structure their attacks.
Two other cybersecurity professionals, Kevin Martin and Ryan Goldberg, were also sentenced for their roles in the same scheme. The three men used BlackCat, a type of malicious software that criminals rent out to other criminals in exchange for a cut of whatever money they extort. Government investigators seized over $10 million in assets tied to the plot, including cryptocurrency, a food truck, and a luxury fishing boat, according to TechCrunch.
BlackCat is known for being used in some of the worst cyberattacks in recent years. In early 2024, the same malware was used to breach Change Healthcare, a major medical billing company. That attack exposed personal and health information for more than 192 million Americans and disrupted pharmacy and medical billing systems across the country.
What makes this case unusual is that the attackers were not outsiders — they were people who worked in cybersecurity and had trusted access to sensitive information about victim companies. When a business hires a negotiator during a crisis, they tell that person confidential details: how much money they might be willing to pay, what their insurance covers, what systems are affected. Martino and his co-conspirators were using that information to help the attackers, essentially betraying the trust placed in them.
This case is likely to change how companies think about hiring negotiators and what oversight they put in place. Security teams and insurance companies will probably become more careful about which vendors they work with and what access they give them. The incident-response industry is already having conversations about vetting and potential conflicts of interest, and this case will likely make those conversations more urgent.


