Technology

A Ransomware Negotiator Betrayed His Clients. Here's Why That Matters

Martin HollowayPublished 3w ago4 min readBased on 2 sources
Reading level
A Ransomware Negotiator Betrayed His Clients. Here's Why That Matters

A Ransomware Negotiator Betrayed His Clients. Here's Why That Matters

Angelo Martino, a 41-year-old man from Florida, was sentenced to nearly six years in prison after admitting he secretly helped ransomware criminals steal millions of dollars from the people who hired him Engadget. The sentence was far harsher than the two years he had asked for.

Martino worked for DigitalMint, a company that negotiates ransom payments when criminals lock up a business's computer files and demand money to unlock them. His job was to help victims pay as little as possible. Instead, starting in April 2023, he sold the criminals confidential information about his clients — how much money they had, what they were willing to pay, and their negotiating strategy. This gave the criminals an unfair advantage, letting them demand much larger ransoms Engadget. DigitalMint says it had no idea what Martino was doing.

Four companies and one nonprofit fell victim to Martino's betrayal, paying ransoms between $213,000 and $26.8 million. In total, they lost more than $75 million Engadget. Martino didn't stop there. Working with two other men, he also directly deployed the ransomware himself against five additional victims, including a medical device company that paid $1.2 million. His two co-conspirators each received four-year sentences Engadget. The government seized $10 million connected to the scheme, and Martino must give 10 percent of his future earnings to his victims Engadget.

An FBI official described the betrayal simply: Martino "sold out the very victims he was hired to represent" Engadget.

Martino worked with a notorious ransomware gang called BlackCat, also known as ALPHV. The FBI and federal prosecutors disrupted BlackCat's operations in December 2023, releasing a decryption tool that freed more than 500 victims from paying ransom — saving them over $68 million Engadget. Federal agencies also offered a reward of up to $10 million for information about the gang's leaders. Martino's case was one piece of the broader effort to shut down BlackCat.

Why This Matters Beyond One Man's Crime

Companies facing a ransomware attack need outside help. They hire negotiation firms like DigitalMint to talk to the criminals, arrange payments, and make sure they comply with U.S. law regarding where the money comes from. These negotiators handle some of the most sensitive information a company has: how much money it can actually afford to lose, what its vulnerabilities are, how desperate the situation is. They occupy a position of complete trust.

Martino's case reveals a blind spot that most companies don't think about. When a business gets hit with ransomware, it typically focuses on the technical side — the computer systems, the firewalls, the software defenses. Security experts spend years building walls to keep attackers out. But Martino didn't break through any wall. He walked in through the front door as someone the company trusted, then sold what he learned to the criminals. No amount of cybersecurity software would have caught that.

This creates an unusual problem for companies and their insurance companies. When selecting a negotiation firm during a crisis, urgency and panic tend to push aside the careful vetting that would normally happen before bringing an outside party into sensitive conversations about money and legal matters. In this author's view, companies are likely to start asking harder questions about who they hire to negotiate ransoms — checking references more carefully, demanding audits, and possibly requiring oversight during active incidents. Cyber insurance companies, which often recommend specific negotiators to their customers, may also add more supervision and accountability requirements to these relationships.

Ransomware gangs have repeatedly shown they can rebuild after police and the FBI disrupt their infrastructure and kick them off the internet. What makes these law enforcement operations work better is a combination of tools — like that free decryption key released to BlackCat victims — along with financial incentives designed to turn insiders and affiliates against the gang. This case illustrates something important: ransomware is not just a technical problem solved by better software. It also lives in the world of professional services, criminal networks, and human decisions about whether to stay loyal or sell out.