Technology

Ransomware Negotiator Sentenced for Working With the Attackers He Was Hired to Stop

Martin HollowayPublished 3w ago4 min readBased on 6 sources
Reading level
Ransomware Negotiator Sentenced for Working With the Attackers He Was Hired to Stop

Angelo Martino, a 41-year-old ransomware negotiator employed by DigitalMint, a cybersecurity firm, has been sentenced to 70 months in prison for conspiracy to deploy ransomware and extort U.S. companies. The plea was entered in April 2026, according to the Department of Justice.

Rather than operating as a middleman between victims and extortionists, Martino used his position inside a negotiation firm to coordinate directly with hackers. Throughout 2023, he fed attackers information about target companies and helped structure attacks, according to TechCrunch. All three perpetrators — Martino, Kevin Martin, and Ryan Goldberg — leveraged BlackCat ransomware, also known as ALPHV, a ransomware-as-a-service platform where criminal affiliates pay for access to pre-built malware and infrastructure in exchange for a share of extortion proceeds.

The government seized more than $10 million in cryptocurrency and physical assets tied to Martino's conduct, including a food truck and a luxury fishing boat allegedly purchased with criminal proceeds. Against a documented single-attack payout of roughly $1.2 million split three ways after money laundering, the scale of the forfeiture shows how much wealth the group accumulated through the ransomware-as-a-service model rather than any single major score.

BlackCat carries significant notoriety in the ransomware world. The same malware family was used in the February 2024 breach of Change Healthcare, which exposed medical and billing data for more than 192 million Americans. That incident, one of the largest healthcare data breaches on record, disrupted pharmacy and billing operations nationwide, though it was unrelated to Martino's specific attacks.

Martin and Goldberg, both described as cybersecurity professionals, were previously sentenced for their roles in the scheme. The U.S. Attorney's Office for the Southern District of Florida prosecuted the case.

What distinguishes this case from routine ransomware prosecutions is the insider position of the perpetrators. Ransomware negotiation firms exist to handle a delicate role: they mediate between victim organizations — often in crisis and facing severe operational disruption — and extortionists. In doing so, they gain access to sensitive information: incident response strategy, the victim's budget for payment, and sometimes the limits of their cyber insurance coverage. A negotiator who is simultaneously coordinating with the attacker reverses that trust relationship in a way few other insider threats can match, since the negotiator effectively sits on both sides of the transaction and can see what both parties are willing to do.

This case is likely to fuel conversations already happening in the incident-response industry about vetting procedures, external oversight, and potential conflicts of interest at negotiation firms. DigitalMint itself has not been accused of institutional wrongdoing; the facts concern Martino's individual actions rather than company-level failure. Nevertheless, the episode sits inside a live industry debate about whether negotiation firms should face more external auditing of how they handle sensitive cases internally.

The broader context is that ransomware-as-a-service has created a professionalized criminal supply chain that also has built-in points of failure. BlackCat's affiliate structure meant that Martino, Martin, and Goldberg did not need to develop or maintain their own malware — they needed targeting information, access to victim systems, and a way to move money, all of which their day jobs in incident response could reasonably provide. That three custodians of victim trust ended up on the other side of the table across a multi-year scheme spanning multiple prosecutions is the detail likely to draw closest scrutiny from corporate security teams and insurers as they decide which vendors to trust with breach response.