Technology

How a Ransomware Negotiator Became an Extortionist — and What It Reveals About a Hidden Risk

Martin HollowayPublished 3w ago5 min readBased on 2 sources
Reading level
How a Ransomware Negotiator Became an Extortionist — and What It Reveals About a Hidden Risk

How a Ransomware Negotiator Became an Extortionist — and What It Reveals About a Hidden Risk

Angelo Martino, a 41-year-old ransomware negotiator from Land O'Lakes, Florida, has been sentenced to 70 months in prison after pleading guilty to conspiring to interfere with interstate commerce through extortion Engadget. The sentence falls short of the 20-year statutory maximum but significantly exceeds the 24-month term he sought under his plea agreement.

Martino worked for DigitalMint, a firm that negotiates ransom payments on behalf of ransomware victims. DigitalMint has cooperated fully with investigators and says it had no knowledge of Martino's conduct.

The Scheme: Trading Insider Information for Money

Beginning in April 2023, Martino colluded with the BlackCat ransomware group, also known as ALPHV. He sold the gang confidential details about victims' negotiating strategies and financial positions — the kind of information that would help attackers extract larger ransom payments. Think of it this way: a negotiator's job is to drive down what a victim must pay. Martino did the opposite, handing attackers the leverage they needed to push the price up.

Four companies and a non-profit fell victim to the scheme, paying ransoms ranging from $213,000 to $26.8 million, for a combined total exceeding $75 million. Martino's involvement went further than intelligence-sharing. Together with two co-conspirators, he also deployed ransomware directly against five additional victims, including a medical device company that ultimately paid a $1.2 million ransom. Both co-conspirators were previously sentenced to 48 months each.

Law enforcement seized $10 million in assets traced to the scheme. Martino must also pay 10 percent of any post-release salary toward restitution to victims. Brett Leatherman, assistant director of the FBI's Cyber Division, said Martino "sold out the very victims he was hired to represent" Engadget.

Disrupting BlackCat — and the Wider Ransomware Ecosystem

This case is one piece of a larger federal effort against BlackCat. In December 2023, the Department of Justice announced it had disrupted the group. That operation included a decryption tool the FBI distributed to more than 500 BlackCat victims, sparing them over $68 million in ransom payments, alongside a standing reward of up to $10 million for information on BlackCat administrators and affiliates Engadget.

Why This Matters: A Vulnerability That Firewalls Can't Catch

Ransomware negotiation firms like DigitalMint, Coveware, and GroupSense occupy an unusual role. They act as trusted middlemen, handling cryptocurrency payments, communicating with threat actors, and checking payments against sanctions lists on behalf of breached companies — often at the worst possible moment, when a company's operations are under siege. This entire model rests on a simple assumption: the negotiator's interests align with the victim's, not the attacker's.

Martino's case reveals a specific weakness in that assumption. An insider with legitimate access to a victim's financial details and negotiating strategy can monetize that information by selling it to the attacker. This is a different kind of threat than most security teams prepare for. No firewall, no endpoint monitoring system, no zero-trust network segmentation stops a negotiator from handing over information directly to the attacker. The vulnerability sits elsewhere: in how organizations choose and oversee incident response vendors, in contractual controls, and in structural questions about how much unsupervised discretion a third-party negotiator should have during an active crisis.

The broader context here is that cases like this tend to prompt organizations to rethink how they select and monitor incident response vendors when they are under attack and under time pressure. Cyber insurance carriers, who often mandate or recommend specific negotiation firms as part of their incident response coverage, may face pressure to add auditing or oversight requirements to those relationships.

A Pattern in Ransomware Disruptions

Looking at how several major ransomware groups have been dismantled, a pattern has emerged. Technical countermeasures — in BlackCat's case, a working decryption key distributed to hundreds of victims — combined with financial incentives aimed at insiders and affiliates, have proven more effective than simply seizing infrastructure. Ransomware-as-a-service groups tend to resurface under new names once their technical infrastructure is disrupted. Whether BlackCat's operators have rebranded and reappeared elsewhere is unclear from the current record, but Martino's case adds an important data point: the economics of ransomware extend well beyond the malware itself. They flow through the professional services layer built around incident response, and that layer can be compromised from within.