Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme

Former DigitalMint Ransomware Negotiator Angelo Martino (TL-2026-1166), also tracked as DigitalMint Insider Ransomware Negotiator Case, is a medium-severity ransomware operation, first published 2026-07-10. It is attributed to BlackCat with high confidence, affects DigitalMint Ransomware Negotiation / Incident Response Services, maps to 38 MITRE ATT&CK techniques (T1003, T1003.001, T1016), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-1166

Threat ID
TL-2026-1166
Also known as
DigitalMint Insider Ransomware Negotiator Case, Martino BlackCat Collusion Scheme
Severity
MEDIUM
Status
RESOLVED
Category
RANSOMWARE
First published
2026-07-10
Last reviewed
2026-07-10
Attribution
BlackCat
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
health, finance, nonprofit, hospitality, legal, education, pharmacy, manufacturing, professionalservices
Target regions
united states of america, North America
Detection rules
9
Indicators of compromise
16

Malware and tooling in Former DigitalMint Ransomware Negotiator Angelo Martino

Malware and tooling: BlackCat (Windows), BlackCat - S1068

Angelo John Martino III, a former DigitalMint ransomware negotiator, was sentenced to 70 months in federal prison for colluding with BlackCat (ALPHV) ransomware affiliates while representing victim companies during negotiations, sharing confidential insurance-policy limits and negotiating positions to maximize extortion payouts across five U.S. organizations totaling $75.3 million. Co-conspirators Kevin Tyler Martin (also a DigitalMint negotiator) and Ryan Clifford Goldberg (a former Sygnia incident-response manager) were each sentenced to 4 years in April 2026 for a related, separate spree of BlackCat/ALPHV attacks against five additional companies.

How Former DigitalMint Ransomware Negotiator Angelo Martino works

Between April 2023 and November 2023, Angelo John Martino III (41, South Florida), while employed by incident-response and ransomware-negotiation firm DigitalMint, abused his trusted position as the assigned negotiator for at least five U.S. victim organizations to secretly collude with BlackCat/ALPHV ransomware affiliates. Martino shared confidential client information obtained through his negotiator role — including cyber-insurance policy limits and the victims' authorized negotiating ceilings — with ransomware operators via backchannels, enabling the affiliates (and Martino himself, who received a cut of the proceeds) to extract the maximum possible ransom payment from each victim. In effect, Martino negotiated against himself: representing the victim on one side of the table while feeding the attacker actionable intelligence on the other. He also provided affiliate account access and, per prosecutors, instructed accomplices to deny settlement offers and withhold payment ceilings from victims to inflate demands. The five victims he colluded against paid a combined $75.3 million, with individual payments including $26.79 million (a nonprofit), $25.66 million (a financial-services firm), $16.5 million (a hospitality company), $6.1 million, and $213,000. A separate but related conspiracy tied to the same case involved Martino, Kevin Tyler Martin (a fellow DigitalMint negotiator), and Ryan Clifford Goldberg (a former manager of incident response at Sygnia), who together attempted to deploy BlackCat/ALPHV ransomware directly against five additional U.S. companies (a Florida medical company, a Maryland pharmaceutical company, a California doctor's office, a Virginia drone manufacturer, and a California engineering company) between April and December 2023. Only one of those five attacks succeeded — the Florida medical company paid roughly $1.2-1.3 million — while patient photos stolen from the California doctor's office were published on BlackCat's leak site as pressure despite no ransom being paid. In all schemes, 20% of ransom proceeds were remitted to BlackCat/ALPHV RaaS administrators per the group's affiliate revenue-share model. Martino pleaded guilty in April 2026 to conspiracy to obstruct commerce by extortion and was sentenced July 9, 2026 to 70 months in prison; Martin and Goldberg pleaded guilty in December 2025 and were sentenced in April 2025/2026 to 4 years each. Authorities seized roughly $10 million in assets tied to Martino, including a $1.68 million home, a $396,000 property, a food truck, a 29-foot luxury fishing boat, vehicles, and cryptocurrency; two Florida properties remain subject to forfeiture, with a restitution hearing scheduled for September 17, 2026. This is a legal/enforcement outcome rather than an active technical threat — no new CVE, malware sample, or network IOC was disclosed in the reporting — but it is directly relevant to SOC/threat-intel tracking of BlackCat/ALPHV affiliate TTPs (per CISA #StopRansomware Advisory AA23-353A) and to insider-collusion risk within incident-response and ransomware-negotiation workflows, which sit inside the trusted response chain of victim organizations.

MITRE ATT&CK techniques used in TL-2026-1166

Credential Access

T1003 OS Credential Dumping; T1003.001 LSASS Memory

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1049 System Network Connections Discovery; T1057 Process Discovery; T1069.001 Local Groups; T1069.002 Domain Groups; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1087.002 Domain Account; T1135 Network Share Discovery; T1680 Local Storage Discovery

Lateral Movement

T1021.001 Remote Desktop Protocol; T1570 Lateral Tool Transfer

Exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1047 Windows Management Instrumentation

Defense Evasion

T1055 Process Injection

Execution

T1059.003 Windows Command Shell; T1106 Native API

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Command and Control

T1105 Ingress Tool Transfer

defense-impairment

T1112 Modify Registry; T1222.001 Windows Permissions; T1685.005 Clear Windows Event Logs

Privilege Escalation

T1134 Access Token Manipulation; T1548.002 Bypass User Account Control

stealth

T1197 BITS Jobs

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491.001 Internal Defacement; T1561.001 Disk Content Wipe

Resource Development

T1586 Compromise Accounts

Reconnaissance

T1598 Phishing for Information

Affected products and versions in Former DigitalMint Ransomware Negotiator Angelo Martino

  • DigitalMint — Ransomware Negotiation / Incident Response Services
    Vulnerable versions: N/A - insider threat, not a software product
    Fixed in: N/A
  • Sygnia — Incident Response Services
    Vulnerable versions: N/A - insider threat, not a software product
    Fixed in: N/A

Remediation for Former DigitalMint Ransomware Negotiator Angelo Martino

Immediate actions

  • Audit third-party incident-response and ransomware-negotiation vendor contracts for conflict-of-interest and information-sharing controls
  • Restrict negotiator/vendor access to cyber-insurance policy limits and authorized payment ceilings on a strict need-to-know basis
  • Require dual-control/witnessed communications for all ransomware negotiation sessions with external parties
  • Review historical ransomware negotiations handled by third-party firms for anomalous settlement patterns or maximum-limit payments

Workarounds

  • Engage a second, independent negotiator or legal advisor to cross-check settlement recommendations from primary IR vendor staff

Longer-term hardening

  • Implement vendor background-check and bonding requirements for personnel with access to breach negotiation and insurance data
  • Deploy independent, firm-internal oversight (legal counsel, separate negotiation review board) for high-value ransomware negotiations
  • Adopt CISA #StopRansomware Advisory AA23-353A detection and hardening guidance against BlackCat/ALPHV affiliate TTPs
  • Establish contractual clawback and audit-rights provisions with incident-response/negotiation vendors

Timeline of Former DigitalMint Ransomware Negotiator Angelo Martino

  • BlackCat/ALPHV Ransomware-as-a-Service first identified, later attributed to over 1,000 victims and $300M+ in ransom collected through September 2023 per FBI/CISA reporting.
  • Angelo Martino, Kevin Tyler Martin, and Ryan Clifford Goldberg begin colluding with BlackCat/ALPHV affiliates, targeting victim companies for extortion and direct ransomware deployment.
  • A Florida medical company pays approximately $1.2-1.3 million after a successful BlackCat/ALPHV attack tied to the Martin/Goldberg conspiracy.
  • Ryan Clifford Goldberg and his wife purchase one-way flights to Paris roughly ten days after an FBI interview, later cited by prosecutors as evidence of consciousness of guilt.
  • FBI/CISA reporting on BlackCat/ALPHV places cumulative campaign impact at 1,000+ victims and $300M+ in ransom payments through this date.
  • Martino's insider-collusion scheme against DigitalMint's five negotiation clients concludes, having extracted a combined $75.3 million.
  • The related Martin/Goldberg BlackCat/ALPHV deployment conspiracy against five additional companies concludes.
  • CISA/FBI/HHS revise joint #StopRansomware Advisory AA23-353A on ALPHV BlackCat, adding IOCs and TTPs identified through February 2024 investigations.
  • DOJ indicts Ryan Clifford Goldberg and Kevin Tyler Martin in the U.S. District Court for the Southern District of Florida for hacking and extortion tied to BlackCat/ALPHV attacks.
  • Goldberg and Martin plead guilty to conspiracy to obstruct commerce by extortion, reducing their maximum exposure from 50 to 20 years.
  • Angelo Martino is released on a $500,000 bond following his surrender in the case.
  • Reporting details a separate DOJ case against Angelo Martino for colluding with BlackCat affiliates to extort $75 million from five DigitalMint negotiation clients.
  • Angelo Martino pleads guilty to conspiracy to obstruct commerce by extortion in connection with the DigitalMint insider-collusion scheme.
  • Kevin Tyler Martin and Ryan Clifford Goldberg are each sentenced to 4 years (48 months) in federal prison.
  • Angelo John Martino III is sentenced to 70 months (5 years, 10 months) in federal prison for the insider-collusion extortion scheme.
  • BleepingComputer, CyberScoop, and other outlets report on Martino's sentencing and the broader DigitalMint/Sygnia insider ransomware-negotiator case.
  • A restitution hearing in Martino's case is scheduled, to determine final victim compensation and asset forfeiture outcomes.

Sources cited for Former DigitalMint Ransomware Negotiator Angelo Martino

Threats related to Former DigitalMint Ransomware Negotiator Angelo Martino

Detection coverage for TL-2026-1166

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1166 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats