Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Insider Collusion with BlackCat/ALPHV Affiliates Ryan Goldberg and Kevin Martin — Threadlinqs Intelligence
As of 2026-07-10, Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Insider Collusion with BlackCat/ALPHV Affiliates Ryan Goldberg and Kevin Martin is a medium-severity cybercrime threat attributed to ALPHV, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1174 · Severity: MEDIUM · Status: RESOLVED · Category: CYBERCRIME
Attribution: ALPHV · FINANCIAL
Angelo John Martino III, a former ransomware negotiator at DigitalMint, was sentenced to 70 months in federal prison for conspiring with ALPHV/BlackCat ransomware affiliates Ryan Goldberg (ex-Sygnia
Between April and December 2023, three former cybersecurity professionals — Angelo John Martino III (a ransomware negotiator employed by incident-response/negotiation firm DigitalMint), Kevin Tyler Martin (also a DigitalMint negotiator), and Ryan Clifford Goldberg (an incident-response manager at Sygnia) — conspired to deploy ALPHV/BlackCat ransomware against and extort at least ten U.S. companies. Martino used his trusted position as a professional ransomware negotiator, hired by victim organizations specifically to resolve ransomware incidents, to secretly act as a 'double agent': he passed BlackCat operators confidential information about his own clients' negotiating strategy, financial capacity, and cyber-insurance policy limits, allowing the attackers to calibrate ransom demands for maximum extraction. In return, Martino and his co-conspirators received a share of the ransom proceeds paid to ALPHV/BlackCat administrators (the RaaS operators reportedly retained roughly a 20% affiliate cut of ransom payments under the group's ransomware-as-a-service model). Separately, Martin and Goldberg directly deployed BlackCat ransomware against additional victims, netting further payments including approximately $1.2 million in Bitcoin from one target and roughly $1.3 million from a medical firm. Overall, prosecutors identified at least five negotiated-victim companies extorted for a combined $75.3 million (a nonprofit paid $26.8M, a financial services firm paid $25.7M, a hospitality company paid $16.5M, and two others paid $6.1M and $213,000, respectively) tied to Martino's insider leaks, plus additional deployment-based extortion attributed to Martin and Goldberg. The group laundered cryptocurrency ransom proceeds through split wallets and converted funds into real estate, vehicles, a food truck, and a luxury fishing boat. The FBI's Miami Field Office, with U.S. Secret Service support, investigated the case under 'Operation Riptide'; when Goldberg attempted to flee the country, the FBI tracked him across ten nations before his arrest. Goldberg and Martin each pleaded guilty in December 2025 to conspiracy to obstruct commerce through extortion and were sentenced in May 2026 to four years each. Martino pleaded guilty in April 2026 to the same charge and was sentenced in July 2026 to 70 months (nearly six years) — the statutory maximum was 20 years. Law enforcement seized approximately $10 million in assets from Martino alone, including two residences (a $1.68 million Bayfront home and a $396,000 second residence), cryptocurrency wallets, vehicles, a food truck, and a 29-foot fishing boat. A restitution hearing was scheduled for September 17, 2026. The case underscores a novel insider-threat vector distinct from a typical technical intrusion: it did not require the attackers to breach the negotiator firm's systems — it relied entirely on trusted-insider betrayal of the incident-response/negotiation trust relationship, a role explicitly created to protect ransomware victims. ALPHV/BlackCat itself is a Rust-based, cross-platform (Windows, Linux, VMware ESXi) ransomware-as-a-service operation first identified in November 2021, notorious for triple-extortion tactics (encryption, data-leak-site threats, and DDoS/harassment of victims), extensive use of Cobalt Strike beacons for C2, Evilginx2 adversary-in-the-middle phishing kits to steal MFA/session cookies, and Mega.nz/Dropbox/FileZilla/WinSCP for data exfiltration prior to encryption. The FBI disrupted ALPHV/BlackCat's infrastructure in December 2023, releasing a decryption tool that helped hundreds of victims and reportedly prevented roughly $1 million in further ransom payments before the group later resurfaced amid the high-profile Change Healthcare 'exit scam.'
Target sectors: nonprofit, financial services, hospitality, health, professional services, incident response negotiation firms
Target regions: united states of america
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CYBERCRIME, MEDIUM, threat intelligence, cybersecurity, T1199, T1566, T1078, T1557, T1539, T1105, T1071, T1055, T1070, T1047