DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Insider Extortion Conspiracy

DigitalMint Ransomware Negotiator Angelo Martino Sentenced (TL-2026-1155), also tracked as DigitalMint Insider Extortion Scheme, is a high-severity tracked intrusion set, first published 2026-07-09. It is attributed to BlackCat with high confidence, affects DigitalMint Ransomware Negotiation / Incident Response Services, maps to 26 MITRE ATT&CK techniques (T1003, T1020, T1021), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1155

Threat ID
TL-2026-1155
Also known as
DigitalMint Insider Extortion Scheme, Operation involving Martino/Martin/Goldberg BlackCat affiliate insiders
Severity
HIGH
Status
RESOLVED
Category
THREAT_INTEL
First published
2026-07-09
Last reviewed
2026-07-09
Attribution
BlackCat
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
nonprofit, financial services, hospitality, retail, health, pharmacy, manufacturing drone, engineering, cybersecurity incident-response
Target regions
united states of america, Florida, Maryland, California, Virginia, Texas, georgia
Detection rules
9
Indicators of compromise
20

Malware and tooling in DigitalMint Ransomware Negotiator Angelo Martino Sentenced

Malware and tooling: BlackCat/ALPHV, AnyDesk, Brute Ratel C4 - S1063, Cobalt Strike, Splashtop, evilginx2 - S9003, metasploit

Angelo John Martino III, a former ransomware negotiator at incident-response firm DigitalMint, was sentenced to 70 months in federal prison for conspiring with BlackCat/ALPHV ransomware affiliates. While negotiating on behalf of victim organizations, Martino secretly leaked confidential client negotiating positions and cyber-insurance policy limits to the attackers, helping them extort five victims out of a combined $75.3 million.

How DigitalMint Ransomware Negotiator Angelo Martino Sentenced works

On July 9, 2026, a U.S. District Court in the Southern District of Florida sentenced Angelo John Martino III, 41, of South Florida, to 70 months in prison for conspiracy to obstruct, delay, or affect commerce by extortion, in violation of the Hobbs Act (18 U.S.C. § 1951). Martino was employed by DigitalMint, a third-party ransomware negotiation and incident-response firm, from 2022 until his termination in April 2025 after the scheme surfaced. In his role, Martino was trusted by victim organizations to negotiate ransom payments on their behalf with BlackCat (also known as ALPHV) ransomware affiliates. Instead of acting in his clients' interest, Martino covertly funneled confidential negotiation intelligence -- including victims' internal negotiating positions, walk-away thresholds, and cyber-insurance policy coverage limits -- directly to the BlackCat threat actors he was ostensibly negotiating against. This intelligence allowed the affiliates to calibrate ransom demands to the maximum amount each victim could plausibly pay, rather than guessing blind. Between April and September 2023, this scheme extorted a combined $75.3 million from five victim organizations: a nonprofit ($26.8M), a financial-services company ($25.7M), a hospitality company ($16.5M), a second hospitality/retail victim ($6.1M), and a medical-industry victim ($213,000). An additional five organizations were targeted between April and November 2023 with undisclosed outcomes. Martino received a cut of the illicit proceeds for his participation. The scheme came to light through a parallel DOJ investigation into two other cybersecurity-industry insiders operating the same trusted-insider playbook: Kevin Tyler Martin, a fellow DigitalMint negotiator, and Ryan Clifford Goldberg, an incident-response manager at rival firm Sygnia. Martin and Goldberg, along with an unnamed third co-conspirator, directly attacked and encrypted victim networks using ALPHV/BlackCat ransomware between April and December 2023, targeting a Florida medical company, a Maryland pharmaceutical company, a California doctor's office (whose patient photos were later published on the ALPHV leak site), a Virginia drone manufacturer, and a California engineering firm, netting roughly $1.3 million from the medical company alone and paying BlackCat administrators a 20% affiliate cut for access to the ransomware and leak-site infrastructure. Martin and Goldberg pleaded guilty in December 2024 and were each sentenced to four years in prison in April 2026. Martino was indicted and surrendered in March 2026, released on a $500,000 bond, pleaded guilty in April 2026, and was sentenced July 9, 2026. The DOJ seized roughly $10 million in assets from Martino, including two Florida properties (a Bayfront home worth $1.68 million and a second home worth $396,000), cryptocurrency wallets, multiple vehicles, a food truck, and a 29-foot luxury fishing boat. A restitution hearing is scheduled for September 17, 2026. The case represents a novel insider-threat vector for the incident-response and ransomware-negotiation industry: threat actors co-opting a trusted third-party crisis-response vendor -- normally a defender-side asset -- to leak the exact information (negotiating leverage, insurance limits, walk-away points) that ransomware affiliates need to maximize extortion payouts. BlackCat/ALPHV itself was one of the most prolific ransomware-as-a-service operations, victimizing nearly 70 organizations by leak-site count in a single quarter before being disrupted by an FBI-led operation in December 2023 that seized infrastructure and released a decryption tool credited with saving victims an estimated $99 million; the brand nonetheless continued affiliate activity into 2024 with high-profile hits on MGM Resorts, Fidelity National Financial, and UnitedHealth/Change Healthcare. ALPHV Blackcat affiliates' standard technical playbook -- documented in CISA/FBI/HHS joint advisory AA23-353A -- uses Cobalt Strike and Brute Ratel C4 for command and control, legitimate remote-access tools (AnyDesk, Splashtop) and Mega.nz/Dropbox for exfiltration staging, the Evilginx2 adversary-in-the-middle framework to steal MFA tokens and session cookies, and Metasploit to evade allowlisting controls, before deploying the BlackCat/ALPHV Rust-based locker for double-extortion (encrypt + leak-site publication) impact.

MITRE ATT&CK techniques used in TL-2026-1155

Credential Access

T1003 OS Credential Dumping; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Lateral Movement

T1021 Remote Services

Defense Evasion

T1036 Masquerading

Discovery

T1046 Network Service Discovery; T1087 Account Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing

Privilege Escalation

T1078 Valid Accounts

Collection

T1119 Automated Collection; T1213 Data from Information Repositories; T1560 Archive Collected Data

Persistence

T1133 External Remote Services

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft

Resource Development

T1585 Establish Accounts

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in DigitalMint Ransomware Negotiator Angelo Martino Sentenced

  • DigitalMint — Ransomware Negotiation / Incident Response Services
    Vulnerable versions: Negotiation engagements 2022-2025 involving Angelo Martino
    Fixed in: N/A - personnel terminated April 2025
  • Sygnia — Incident Response Services
    Vulnerable versions: Engagements involving Ryan Clifford Goldberg, 2023
    Fixed in: N/A - personnel terminated

Remediation for DigitalMint Ransomware Negotiator Angelo Martino Sentenced

Immediate actions

  • Audit and re-vet all third-party ransomware negotiation and incident-response (IR) vendors for insider-conflict-of-interest controls
  • Enforce strict need-to-know compartmentalization of negotiating position, walk-away threshold, and insurance policy limit data during active ransomware negotiations
  • Require dual-control / two-person review for any external party sharing victim financial ceiling data with negotiators
  • Contractually require IR/negotiation vendors to disclose any prior or concurrent affiliate relationships with ransomware operators
  • Rotate and restrict access to cyber-insurance policy documents during active incidents to a minimal need-to-know group

Workarounds

  • Engage outside/independent counsel to hold sensitive insurance-limit and negotiating-position data separate from the assigned negotiator
  • Use multiple, competitively-sourced negotiators or advisors for high-value incidents to reduce single-point-of-trust exposure

Longer-term hardening

  • Build insider-threat monitoring into vendor management programs covering IR and ransomware-negotiation firms
  • Establish independent, siloed communication channels between counsel/insurer and negotiator that cannot be unilaterally bypassed by a single negotiator
  • Deploy anomaly detection on negotiator communications channels (email, chat, negotiation portal logs) for unauthorized data transfer
  • Require background checks and periodic re-vetting of personnel with access to ransom negotiation intelligence
  • Diversify and independently verify ransomware-negotiation vendor selection rather than relying on a single trusted firm across the incident lifecycle

Weaknesses (CWE) in DigitalMint Ransomware Negotiator Angelo Martino Sentenced

CWE-284, CWE-668, CWE-862

Timeline of DigitalMint Ransomware Negotiator Angelo Martino Sentenced

  • Angelo Martino is hired as a ransomware negotiator at incident-response firm DigitalMint.
  • BlackCat/ALPHV affiliate campaign begins; Martino starts leaking client negotiating positions and insurance limits to affiliates while representing victims in negotiations; Goldberg/Martin/co-conspirator begin directly attacking victim networks with ALPHV/BlackCat.
  • A Florida medical company pays approximately $1.3 million ransom to the Goldberg/Martin/co-conspirator BlackCat cell; 20% of proceeds sent to ALPHV administrators.
  • Five primary victims represented by Martino via DigitalMint pay a combined $75.3 million in ransoms (nonprofit $26.8M, financial services $25.7M, hospitality $16.5M, retail/hospitality $6.1M, medical $213K) after Martino leaked their negotiating leverage and insurance limits to BlackCat affiliates.
  • An additional five organizations are targeted by the conspiracy between April and November 2023, with outcomes not publicly disclosed.
  • FBI-led international law enforcement operation disrupts ALPHV/BlackCat ransomware infrastructure and releases a decryption tool credited with saving victims an estimated $99 million; CISA/FBI/HHS publish joint advisory AA23-353A.
  • Ryan Clifford Goldberg (Sygnia) and Kevin Tyler Martin (DigitalMint) plead guilty in the Southern District of Florida to conspiracy to obstruct commerce by extortion for directly deploying ALPHV/BlackCat ransomware against victim networks.
  • DigitalMint terminates Angelo Martino after the DOJ investigation surfaces his role leaking client data to BlackCat affiliates.
  • Angelo Martino surrenders to federal authorities and is released on a $500,000 bond.
  • Goldberg and Martin are each sentenced to four years in prison for their BlackCat ransomware attacks.
  • Martino pleads guilty to one count of conspiracy to obstruct, delay, or affect commerce by extortion under the Hobbs Act.
  • Martino is sentenced to 70 months in federal prison; DOJ seizes roughly $10 million in assets including two Florida properties, cryptocurrency, vehicles, a food truck, and a 29-foot fishing boat.
  • A restitution hearing for victims is scheduled in the Southern District of Florida.

Sources cited for DigitalMint Ransomware Negotiator Angelo Martino Sentenced

Threats related to DigitalMint Ransomware Negotiator Angelo Martino Sentenced

Detection coverage for TL-2026-1155

As of 2026-07-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1155 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats