DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Insider Extortion Conspiracy — Threadlinqs Intelligence
As of 2026-07-09, DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Insider Extortion Conspiracy is a high-severity threat intel threat attributed to BlackCat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1155 · Severity: HIGH · Status: RESOLVED · Category: THREAT_INTEL
Attribution: BlackCat · FINANCIAL
Angelo John Martino III, a former ransomware negotiator at incident-response firm DigitalMint, was sentenced to 70 months in federal prison for conspiring with BlackCat/ALPHV ransomware affiliates.
On July 9, 2026, a U.S. District Court in the Southern District of Florida sentenced Angelo John Martino III, 41, of South Florida, to 70 months in prison for conspiracy to obstruct, delay, or affect commerce by extortion, in violation of the Hobbs Act (18 U.S.C. § 1951). Martino was employed by DigitalMint, a third-party ransomware negotiation and incident-response firm, from 2022 until his termination in April 2025 after the scheme surfaced. In his role, Martino was trusted by victim organizations to negotiate ransom payments on their behalf with BlackCat (also known as ALPHV) ransomware affiliates. Instead of acting in his clients' interest, Martino covertly funneled confidential negotiation intelligence -- including victims' internal negotiating positions, walk-away thresholds, and cyber-insurance policy coverage limits -- directly to the BlackCat threat actors he was ostensibly negotiating against. This intelligence allowed the affiliates to calibrate ransom demands to the maximum amount each victim could plausibly pay, rather than guessing blind. Between April and September 2023, this scheme extorted a combined $75.3 million from five victim organizations: a nonprofit ($26.8M), a financial-services company ($25.7M), a hospitality company ($16.5M), a second hospitality/retail victim ($6.1M), and a medical-industry victim ($213,000). An additional five organizations were targeted between April and November 2023 with undisclosed outcomes. Martino received a cut of the illicit proceeds for his participation. The scheme came to light through a parallel DOJ investigation into two other cybersecurity-industry insiders operating the same trusted-insider playbook: Kevin Tyler Martin, a fellow DigitalMint negotiator, and Ryan Clifford Goldberg, an incident-response manager at rival firm Sygnia. Martin and Goldberg, along with an unnamed third co-conspirator, directly attacked and encrypted victim networks using ALPHV/BlackCat ransomware between April and December 2023, targeting a Florida medical company, a Maryland pharmaceutical company, a California doctor's office (whose patient photos were later published on the ALPHV leak site), a Virginia drone manufacturer, and a California engineering firm, netting roughly $1.3 million from the medical company alone and paying BlackCat administrators a 20% affiliate cut for access to the ransomware and leak-site infrastructure. Martin and Goldberg pleaded guilty in December 2024 and were each sentenced to four years in prison in April 2026. Martino was indicted and surrendered in March 2026, released on a $500,000 bond, pleaded guilty in April 2026, and was sentenced July 9, 2026. The DOJ seized roughly $10 million in assets from Martino, including two Florida properties (a Bayfront home worth $1.68 million and a second home worth $396,000), cryptocurrency wallets, multiple vehicles, a food truck, and a 29-foot luxury fishing boat. A restitution hearing is scheduled for September 17, 2026. The case represents a novel insider-threat vector for the incident-response and ransomware-negotiation industry: threat actors co-opting a trusted third-party crisis-response vendor -- normally a defender-side asset -- to leak the exact information (negotiating leverage, insurance limits, walk-away points) that ransomware affiliates need to maximize extortion payouts. BlackCat/ALPHV itself was one of the most prolific ransomware-as-a-service operations, victimizing nearly 70 organizations by leak-site count in a single quarter before being disrupted by an FBI-led operation in December 2023 that seized infrastructure and released a decryption tool credited with saving victims an estimated $99 million; the brand nonetheless continued affiliate activity into 2024 with high-profile hits on MGM Resorts, Fidelity National Financial, and UnitedHealth/Change Healthcare. ALPHV Blackcat affiliates' standard technical playbook -- documented in CISA/FBI/HHS joint advisory AA23-353A -- uses Cobalt Strike and Brute R
Weaknesses (CWE)
CWE-284, CWE-668, CWE-862
Target sectors: nonprofit, financial services, hospitality, retail, health, pharmacy, manufacturing drone, engineering, cybersecurity incident-response
Target regions: united states of america, Florida, Maryland, California, Virginia, Texas, georgia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1585, T1199, T1078, T1566, T1059, T1133, T1078, T1562, T1036, T1557