DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Insider Extortion Conspiracy
DigitalMint Ransomware Negotiator Angelo Martino Sentenced (TL-2026-1155), also tracked as DigitalMint Insider Extortion Scheme, is a high-severity tracked intrusion set, first published 2026-07-09. It is attributed to BlackCat with high confidence, affects DigitalMint Ransomware Negotiation / Incident Response Services, maps to 26 MITRE ATT&CK techniques (T1003, T1020, T1021), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1155
- Threat ID
- TL-2026-1155
- Also known as
- DigitalMint Insider Extortion Scheme, Operation involving Martino/Martin/Goldberg BlackCat affiliate insiders
- Severity
- HIGH
- Status
- RESOLVED
- Category
- THREAT_INTEL
- First published
- 2026-07-09
- Last reviewed
- 2026-07-09
- Attribution
- BlackCat
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- nonprofit, financial services, hospitality, retail, health, pharmacy, manufacturing drone, engineering, cybersecurity incident-response
- Target regions
- united states of america, Florida, Maryland, California, Virginia, Texas, georgia
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in DigitalMint Ransomware Negotiator Angelo Martino Sentenced
Malware and tooling: BlackCat/ALPHV, AnyDesk, Brute Ratel C4 - S1063, Cobalt Strike, Splashtop, evilginx2 - S9003, metasploit
Angelo John Martino III, a former ransomware negotiator at incident-response firm DigitalMint, was sentenced to 70 months in federal prison for conspiring with BlackCat/ALPHV ransomware affiliates. While negotiating on behalf of victim organizations, Martino secretly leaked confidential client negotiating positions and cyber-insurance policy limits to the attackers, helping them extort five victims out of a combined $75.3 million.
How DigitalMint Ransomware Negotiator Angelo Martino Sentenced works
On July 9, 2026, a U.S. District Court in the Southern District of Florida sentenced Angelo John Martino III, 41, of South Florida, to 70 months in prison for conspiracy to obstruct, delay, or affect commerce by extortion, in violation of the Hobbs Act (18 U.S.C. § 1951). Martino was employed by DigitalMint, a third-party ransomware negotiation and incident-response firm, from 2022 until his termination in April 2025 after the scheme surfaced. In his role, Martino was trusted by victim organizations to negotiate ransom payments on their behalf with BlackCat (also known as ALPHV) ransomware affiliates. Instead of acting in his clients' interest, Martino covertly funneled confidential negotiation intelligence -- including victims' internal negotiating positions, walk-away thresholds, and cyber-insurance policy coverage limits -- directly to the BlackCat threat actors he was ostensibly negotiating against. This intelligence allowed the affiliates to calibrate ransom demands to the maximum amount each victim could plausibly pay, rather than guessing blind. Between April and September 2023, this scheme extorted a combined $75.3 million from five victim organizations: a nonprofit ($26.8M), a financial-services company ($25.7M), a hospitality company ($16.5M), a second hospitality/retail victim ($6.1M), and a medical-industry victim ($213,000). An additional five organizations were targeted between April and November 2023 with undisclosed outcomes. Martino received a cut of the illicit proceeds for his participation. The scheme came to light through a parallel DOJ investigation into two other cybersecurity-industry insiders operating the same trusted-insider playbook: Kevin Tyler Martin, a fellow DigitalMint negotiator, and Ryan Clifford Goldberg, an incident-response manager at rival firm Sygnia. Martin and Goldberg, along with an unnamed third co-conspirator, directly attacked and encrypted victim networks using ALPHV/BlackCat ransomware between April and December 2023, targeting a Florida medical company, a Maryland pharmaceutical company, a California doctor's office (whose patient photos were later published on the ALPHV leak site), a Virginia drone manufacturer, and a California engineering firm, netting roughly $1.3 million from the medical company alone and paying BlackCat administrators a 20% affiliate cut for access to the ransomware and leak-site infrastructure. Martin and Goldberg pleaded guilty in December 2024 and were each sentenced to four years in prison in April 2026. Martino was indicted and surrendered in March 2026, released on a $500,000 bond, pleaded guilty in April 2026, and was sentenced July 9, 2026. The DOJ seized roughly $10 million in assets from Martino, including two Florida properties (a Bayfront home worth $1.68 million and a second home worth $396,000), cryptocurrency wallets, multiple vehicles, a food truck, and a 29-foot luxury fishing boat. A restitution hearing is scheduled for September 17, 2026. The case represents a novel insider-threat vector for the incident-response and ransomware-negotiation industry: threat actors co-opting a trusted third-party crisis-response vendor -- normally a defender-side asset -- to leak the exact information (negotiating leverage, insurance limits, walk-away points) that ransomware affiliates need to maximize extortion payouts. BlackCat/ALPHV itself was one of the most prolific ransomware-as-a-service operations, victimizing nearly 70 organizations by leak-site count in a single quarter before being disrupted by an FBI-led operation in December 2023 that seized infrastructure and released a decryption tool credited with saving victims an estimated $99 million; the brand nonetheless continued affiliate activity into 2024 with high-profile hits on MGM Resorts, Fidelity National Financial, and UnitedHealth/Change Healthcare. ALPHV Blackcat affiliates' standard technical playbook -- documented in CISA/FBI/HHS joint advisory AA23-353A -- uses Cobalt Strike and Brute Ratel C4 for command and control, legitimate remote-access tools (AnyDesk, Splashtop) and Mega.nz/Dropbox for exfiltration staging, the Evilginx2 adversary-in-the-middle framework to steal MFA tokens and session cookies, and Metasploit to evade allowlisting controls, before deploying the BlackCat/ALPHV Rust-based locker for double-extortion (encrypt + leak-site publication) impact.
MITRE ATT&CK techniques used in TL-2026-1155
Credential Access
T1003 OS Credential Dumping; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Lateral Movement
Defense Evasion
Discovery
T1046 Network Service Discovery; T1087 Account Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1219 Remote Access Tools
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing
Privilege Escalation
Collection
T1119 Automated Collection; T1213 Data from Information Repositories; T1560 Archive Collected Data
Persistence
T1133 External Remote Services
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft
Resource Development
defense-impairment
Affected products and versions in DigitalMint Ransomware Negotiator Angelo Martino Sentenced
- DigitalMint — Ransomware Negotiation / Incident Response Services
Vulnerable versions: Negotiation engagements 2022-2025 involving Angelo Martino
Fixed in: N/A - personnel terminated April 2025 - Sygnia — Incident Response Services
Vulnerable versions: Engagements involving Ryan Clifford Goldberg, 2023
Fixed in: N/A - personnel terminated
Remediation for DigitalMint Ransomware Negotiator Angelo Martino Sentenced
Immediate actions
- Audit and re-vet all third-party ransomware negotiation and incident-response (IR) vendors for insider-conflict-of-interest controls
- Enforce strict need-to-know compartmentalization of negotiating position, walk-away threshold, and insurance policy limit data during active ransomware negotiations
- Require dual-control / two-person review for any external party sharing victim financial ceiling data with negotiators
- Contractually require IR/negotiation vendors to disclose any prior or concurrent affiliate relationships with ransomware operators
- Rotate and restrict access to cyber-insurance policy documents during active incidents to a minimal need-to-know group
Workarounds
- Engage outside/independent counsel to hold sensitive insurance-limit and negotiating-position data separate from the assigned negotiator
- Use multiple, competitively-sourced negotiators or advisors for high-value incidents to reduce single-point-of-trust exposure
Longer-term hardening
- Build insider-threat monitoring into vendor management programs covering IR and ransomware-negotiation firms
- Establish independent, siloed communication channels between counsel/insurer and negotiator that cannot be unilaterally bypassed by a single negotiator
- Deploy anomaly detection on negotiator communications channels (email, chat, negotiation portal logs) for unauthorized data transfer
- Require background checks and periodic re-vetting of personnel with access to ransom negotiation intelligence
- Diversify and independently verify ransomware-negotiation vendor selection rather than relying on a single trusted firm across the incident lifecycle
Weaknesses (CWE) in DigitalMint Ransomware Negotiator Angelo Martino Sentenced
CWE-284, CWE-668, CWE-862
Timeline of DigitalMint Ransomware Negotiator Angelo Martino Sentenced
- Angelo Martino is hired as a ransomware negotiator at incident-response firm DigitalMint.
- BlackCat/ALPHV affiliate campaign begins; Martino starts leaking client negotiating positions and insurance limits to affiliates while representing victims in negotiations; Goldberg/Martin/co-conspirator begin directly attacking victim networks with ALPHV/BlackCat.
- A Florida medical company pays approximately $1.3 million ransom to the Goldberg/Martin/co-conspirator BlackCat cell; 20% of proceeds sent to ALPHV administrators.
- Five primary victims represented by Martino via DigitalMint pay a combined $75.3 million in ransoms (nonprofit $26.8M, financial services $25.7M, hospitality $16.5M, retail/hospitality $6.1M, medical $213K) after Martino leaked their negotiating leverage and insurance limits to BlackCat affiliates.
- An additional five organizations are targeted by the conspiracy between April and November 2023, with outcomes not publicly disclosed.
- FBI-led international law enforcement operation disrupts ALPHV/BlackCat ransomware infrastructure and releases a decryption tool credited with saving victims an estimated $99 million; CISA/FBI/HHS publish joint advisory AA23-353A.
- Ryan Clifford Goldberg (Sygnia) and Kevin Tyler Martin (DigitalMint) plead guilty in the Southern District of Florida to conspiracy to obstruct commerce by extortion for directly deploying ALPHV/BlackCat ransomware against victim networks.
- DigitalMint terminates Angelo Martino after the DOJ investigation surfaces his role leaking client data to BlackCat affiliates.
- Angelo Martino surrenders to federal authorities and is released on a $500,000 bond.
- Goldberg and Martin are each sentenced to four years in prison for their BlackCat ransomware attacks.
- Martino pleads guilty to one count of conspiracy to obstruct, delay, or affect commerce by extortion under the Hobbs Act.
- Martino is sentenced to 70 months in federal prison; DOJ seizes roughly $10 million in assets including two Florida properties, cryptocurrency, vehicles, a food truck, and a 29-foot fishing boat.
- A restitution hearing for victims is scheduled in the Southern District of Florida.
Sources cited for DigitalMint Ransomware Negotiator Angelo Martino Sentenced
- DigitalMint ransomware negotiator Angelo Martino sentenced
- Former DigitalMint ransomware negotiator pleads guilty to extortion scheme
- Ransomware responders plead guilty to using ALPHV in attacks on US organizations
- Ransomware Insider Betrayal: Guilty Plea In BlackCat Cybercrime Scheme
- American Cybersecurity Professionals Given Jail Terms for BlackCat Ransomware Attacks
- Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023
- US ransomware negotiators get 4 years in prison over BlackCat attacks
- Former incident responders plead guilty to ransomware attack spree
- 2 Cyber Pros Admit to Being BlackCat Ransomware Affiliates
- #StopRansomware: ALPHV Blackcat (AA23-353A)
- BlackCat, Software S1068
- Ryan Goldberg of Sygnia and Kevin Martin of DigitalMint Get 4 Years for BlackCat Ransomware
Threats related to DigitalMint Ransomware Negotiator Angelo Martino Sentenced
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims
- Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months
- Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme
Detection coverage for TL-2026-1155
As of 2026-07-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1155 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.