Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme
Former DigitalMint Ransomware Negotiator Angelo Martino (TL-2026-1166), also tracked as DigitalMint Insider Ransomware Negotiator Case, is a medium-severity ransomware operation, first published 2026-07-10. It is attributed to BlackCat with high confidence, affects DigitalMint Ransomware Negotiation / Incident Response Services, maps to 38 MITRE ATT&CK techniques (T1003, T1003.001, T1016), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-1166
- Threat ID
- TL-2026-1166
- Also known as
- DigitalMint Insider Ransomware Negotiator Case, Martino BlackCat Collusion Scheme
- Severity
- MEDIUM
- Status
- RESOLVED
- Category
- RANSOMWARE
- First published
- 2026-07-10
- Last reviewed
- 2026-07-10
- Attribution
- BlackCat
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- health, finance, nonprofit, hospitality, legal, education, pharmacy, manufacturing, professionalservices
- Target regions
- united states of america, North America
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Former DigitalMint Ransomware Negotiator Angelo Martino
Malware and tooling: BlackCat (Windows), BlackCat - S1068
Angelo John Martino III, a former DigitalMint ransomware negotiator, was sentenced to 70 months in federal prison for colluding with BlackCat (ALPHV) ransomware affiliates while representing victim companies during negotiations, sharing confidential insurance-policy limits and negotiating positions to maximize extortion payouts across five U.S. organizations totaling $75.3 million. Co-conspirators Kevin Tyler Martin (also a DigitalMint negotiator) and Ryan Clifford Goldberg (a former Sygnia incident-response manager) were each sentenced to 4 years in April 2026 for a related, separate spree of BlackCat/ALPHV attacks against five additional companies.
How Former DigitalMint Ransomware Negotiator Angelo Martino works
Between April 2023 and November 2023, Angelo John Martino III (41, South Florida), while employed by incident-response and ransomware-negotiation firm DigitalMint, abused his trusted position as the assigned negotiator for at least five U.S. victim organizations to secretly collude with BlackCat/ALPHV ransomware affiliates. Martino shared confidential client information obtained through his negotiator role — including cyber-insurance policy limits and the victims' authorized negotiating ceilings — with ransomware operators via backchannels, enabling the affiliates (and Martino himself, who received a cut of the proceeds) to extract the maximum possible ransom payment from each victim. In effect, Martino negotiated against himself: representing the victim on one side of the table while feeding the attacker actionable intelligence on the other. He also provided affiliate account access and, per prosecutors, instructed accomplices to deny settlement offers and withhold payment ceilings from victims to inflate demands. The five victims he colluded against paid a combined $75.3 million, with individual payments including $26.79 million (a nonprofit), $25.66 million (a financial-services firm), $16.5 million (a hospitality company), $6.1 million, and $213,000. A separate but related conspiracy tied to the same case involved Martino, Kevin Tyler Martin (a fellow DigitalMint negotiator), and Ryan Clifford Goldberg (a former manager of incident response at Sygnia), who together attempted to deploy BlackCat/ALPHV ransomware directly against five additional U.S. companies (a Florida medical company, a Maryland pharmaceutical company, a California doctor's office, a Virginia drone manufacturer, and a California engineering company) between April and December 2023. Only one of those five attacks succeeded — the Florida medical company paid roughly $1.2-1.3 million — while patient photos stolen from the California doctor's office were published on BlackCat's leak site as pressure despite no ransom being paid. In all schemes, 20% of ransom proceeds were remitted to BlackCat/ALPHV RaaS administrators per the group's affiliate revenue-share model. Martino pleaded guilty in April 2026 to conspiracy to obstruct commerce by extortion and was sentenced July 9, 2026 to 70 months in prison; Martin and Goldberg pleaded guilty in December 2025 and were sentenced in April 2025/2026 to 4 years each. Authorities seized roughly $10 million in assets tied to Martino, including a $1.68 million home, a $396,000 property, a food truck, a 29-foot luxury fishing boat, vehicles, and cryptocurrency; two Florida properties remain subject to forfeiture, with a restitution hearing scheduled for September 17, 2026. This is a legal/enforcement outcome rather than an active technical threat — no new CVE, malware sample, or network IOC was disclosed in the reporting — but it is directly relevant to SOC/threat-intel tracking of BlackCat/ALPHV affiliate TTPs (per CISA #StopRansomware Advisory AA23-353A) and to insider-collusion risk within incident-response and ransomware-negotiation workflows, which sit inside the trusted response chain of victim organizations.
MITRE ATT&CK techniques used in TL-2026-1166
Credential Access
T1003 OS Credential Dumping; T1003.001 LSASS Memory
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1069.001 Local Groups; T1069.002 Domain Groups; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1087.002 Domain Account; T1135 Network Share Discovery; T1680 Local Storage Discovery
Lateral Movement
T1021.001 Remote Desktop Protocol; T1570 Lateral Tool Transfer
Exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1047 Windows Management Instrumentation
Defense Evasion
Execution
T1059.003 Windows Command Shell; T1106 Native API
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Command and Control
defense-impairment
T1112 Modify Registry; T1222.001 Windows Permissions; T1685.005 Clear Windows Event Logs
Privilege Escalation
T1134 Access Token Manipulation; T1548.002 Bypass User Account Control
stealth
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491.001 Internal Defacement; T1561.001 Disk Content Wipe
Resource Development
Reconnaissance
Affected products and versions in Former DigitalMint Ransomware Negotiator Angelo Martino
- DigitalMint — Ransomware Negotiation / Incident Response Services
Vulnerable versions: N/A - insider threat, not a software product
Fixed in: N/A - Sygnia — Incident Response Services
Vulnerable versions: N/A - insider threat, not a software product
Fixed in: N/A
Remediation for Former DigitalMint Ransomware Negotiator Angelo Martino
Immediate actions
- Audit third-party incident-response and ransomware-negotiation vendor contracts for conflict-of-interest and information-sharing controls
- Restrict negotiator/vendor access to cyber-insurance policy limits and authorized payment ceilings on a strict need-to-know basis
- Require dual-control/witnessed communications for all ransomware negotiation sessions with external parties
- Review historical ransomware negotiations handled by third-party firms for anomalous settlement patterns or maximum-limit payments
Workarounds
- Engage a second, independent negotiator or legal advisor to cross-check settlement recommendations from primary IR vendor staff
Longer-term hardening
- Implement vendor background-check and bonding requirements for personnel with access to breach negotiation and insurance data
- Deploy independent, firm-internal oversight (legal counsel, separate negotiation review board) for high-value ransomware negotiations
- Adopt CISA #StopRansomware Advisory AA23-353A detection and hardening guidance against BlackCat/ALPHV affiliate TTPs
- Establish contractual clawback and audit-rights provisions with incident-response/negotiation vendors
Timeline of Former DigitalMint Ransomware Negotiator Angelo Martino
- BlackCat/ALPHV Ransomware-as-a-Service first identified, later attributed to over 1,000 victims and $300M+ in ransom collected through September 2023 per FBI/CISA reporting.
- Angelo Martino, Kevin Tyler Martin, and Ryan Clifford Goldberg begin colluding with BlackCat/ALPHV affiliates, targeting victim companies for extortion and direct ransomware deployment.
- A Florida medical company pays approximately $1.2-1.3 million after a successful BlackCat/ALPHV attack tied to the Martin/Goldberg conspiracy.
- Ryan Clifford Goldberg and his wife purchase one-way flights to Paris roughly ten days after an FBI interview, later cited by prosecutors as evidence of consciousness of guilt.
- FBI/CISA reporting on BlackCat/ALPHV places cumulative campaign impact at 1,000+ victims and $300M+ in ransom payments through this date.
- Martino's insider-collusion scheme against DigitalMint's five negotiation clients concludes, having extracted a combined $75.3 million.
- The related Martin/Goldberg BlackCat/ALPHV deployment conspiracy against five additional companies concludes.
- CISA/FBI/HHS revise joint #StopRansomware Advisory AA23-353A on ALPHV BlackCat, adding IOCs and TTPs identified through February 2024 investigations.
- DOJ indicts Ryan Clifford Goldberg and Kevin Tyler Martin in the U.S. District Court for the Southern District of Florida for hacking and extortion tied to BlackCat/ALPHV attacks.
- Goldberg and Martin plead guilty to conspiracy to obstruct commerce by extortion, reducing their maximum exposure from 50 to 20 years.
- Angelo Martino is released on a $500,000 bond following his surrender in the case.
- Reporting details a separate DOJ case against Angelo Martino for colluding with BlackCat affiliates to extort $75 million from five DigitalMint negotiation clients.
- Angelo Martino pleads guilty to conspiracy to obstruct commerce by extortion in connection with the DigitalMint insider-collusion scheme.
- Kevin Tyler Martin and Ryan Clifford Goldberg are each sentenced to 4 years (48 months) in federal prison.
- Angelo John Martino III is sentenced to 70 months (5 years, 10 months) in federal prison for the insider-collusion extortion scheme.
- BleepingComputer, CyberScoop, and other outlets report on Martino's sentencing and the broader DigitalMint/Sygnia insider ransomware-negotiator case.
- A restitution hearing in Martino's case is scheduled, to determine final victim compensation and asset forfeiture outcomes.
Sources cited for Former DigitalMint Ransomware Negotiator Angelo Martino
- US ransomware negotiator gets 4 years in prison for BlackCat attacks
- Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
- Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims
- Former DigitalMint ransomware negotiator pleads guilty to extortion scheme
- Feds say another DigitalMint negotiator ran ransomware attacks and helped extort $75 million
- Chicago cybersecurity firm employee brokered $75M in ransom after orchestrating hacks, feds say
- Former incident responders plead guilty to ransomware attack spree
- Ransomware responders plead guilty to using ALPHV in attacks on US organizations
- Rogue employee of Chicago cybersecurity firm pleads guilty to $1.3 million ransomware hack
- Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says
- DOJ accuses US ransomware negotiators of launching their own ransomware attacks
- Two US cybersecurity experts sentenced in ransomware case, third awaits July ruling
- Third ransomware pro pleads guilty to cybercrime U-turn
- #StopRansomware: ALPHV Blackcat
- BlackCat, Software S1068
Threats related to Former DigitalMint Ransomware Negotiator Angelo Martino
- Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage
- DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Insider Extortion Conspiracy
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US Production
- FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware Operations
Detection coverage for TL-2026-1166
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1166 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.