Threat reportCybercrimeTL-2026-1174

Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Insider Collusion with BlackCat/ALPHV Affiliates Ryan Goldberg and Kevin Martin

mediumRESOLVED

Former Ransomware Negotiator Angelo Martino Sentenced to 70 (TL-2026-1174), also tracked as Ransomware Negotiator Insider Case, is a medium-severity cybercrime threat, first published 2026-07-10. It is attributed to ALPHV with high confidence, affects N/A Ransomware incident-response / negotiation trust relationship, maps to 18 MITRE ATT&CK techniques (T1041, T1047, T1055), and is covered by 9 detection rules and 17 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
3ALPHV
Detection rules
9SPL · KQL · Sigma
IOCs
17Indicators of compromise

Key facts for TL-2026-1174

Threat ID
TL-2026-1174
Also known as
Ransomware Negotiator Insider Case, DigitalMint Insider Collusion Case, Operation Riptide
Severity
MEDIUM
Status
RESOLVED
Category
CYBERCRIME
First published
Last reviewed
Attribution
ALPHV, BlackCat, Ryan Goldberg
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
nonprofit, financial services, hospitality, health, professional services, incident response negotiation firms
Target regions
united states of america
Detection rules
9
Indicators of compromise
17

Malware and tooling in Former Ransomware Negotiator Angelo Martino Sentenced to 70

Malware and tooling: ALPHV/BlackCat, BlackCat (Windows), Cobalt Strike, FileZilla, WinSCP, evilginx2 - S9003

How Former Ransomware Negotiator Angelo Martino Sentenced to 70 works

Angelo John Martino III, a former ransomware negotiator at DigitalMint, was sentenced to 70 months in federal prison for conspiring with ALPHV/BlackCat ransomware affiliates Ryan Goldberg (ex-Sygnia incident-response manager) and Kevin Martin (ex-DigitalMint negotiator) to extort at least ten U.S. companies for a combined $75.3+ million between April and December 2023. Martino abused his negotiator access to leak victims' confidential negotiating positions and insurance policy limits to the attackers in exchange for a cut of the ransom.

Between April and December 2023, three former cybersecurity professionals — Angelo John Martino III (a ransomware negotiator employed by incident-response/negotiation firm DigitalMint), Kevin Tyler Martin (also a DigitalMint negotiator), and Ryan Clifford Goldberg (an incident-response manager at Sygnia) — conspired to deploy ALPHV/BlackCat ransomware against and extort at least ten U.S. companies. Martino used his trusted position as a professional ransomware negotiator, hired by victim organizations specifically to resolve ransomware incidents, to secretly act as a 'double agent': he passed BlackCat operators confidential information about his own clients' negotiating strategy, financial capacity, and cyber-insurance policy limits, allowing the attackers to calibrate ransom demands for maximum extraction. In return, Martino and his co-conspirators received a share of the ransom proceeds paid to ALPHV/BlackCat administrators (the RaaS operators reportedly retained roughly a 20% affiliate cut of ransom payments under the group's ransomware-as-a-service model). Separately, Martin and Goldberg directly deployed BlackCat ransomware against additional victims, netting further payments including approximately $1.2 million in Bitcoin from one target and roughly $1.3 million from a medical firm. Overall, prosecutors identified at least five negotiated-victim companies extorted for a combined $75.3 million (a nonprofit paid $26.8M, a financial services firm paid $25.7M, a hospitality company paid $16.5M, and two others paid $6.1M and $213,000, respectively) tied to Martino's insider leaks, plus additional deployment-based extortion attributed to Martin and Goldberg. The group laundered cryptocurrency ransom proceeds through split wallets and converted funds into real estate, vehicles, a food truck, and a luxury fishing boat. The FBI's Miami Field Office, with U.S. Secret Service support, investigated the case under 'Operation Riptide'; when Goldberg attempted to flee the country, the FBI tracked him across ten nations before his arrest. Goldberg and Martin each pleaded guilty in December 2025 to conspiracy to obstruct commerce through extortion and were sentenced in May 2026 to four years each. Martino pleaded guilty in April 2026 to the same charge and was sentenced in July 2026 to 70 months (nearly six years) — the statutory maximum was 20 years. Law enforcement seized approximately $10 million in assets from Martino alone, including two residences (a $1.68 million Bayfront home and a $396,000 second residence), cryptocurrency wallets, vehicles, a food truck, and a 29-foot fishing boat. A restitution hearing was scheduled for September 17, 2026. The case underscores a novel insider-threat vector distinct from a typical technical intrusion: it did not require the attackers to breach the negotiator firm's systems — it relied entirely on trusted-insider betrayal of the incident-response/negotiation trust relationship, a role explicitly created to protect ransomware victims. ALPHV/BlackCat itself is a Rust-based, cross-platform (Windows, Linux, VMware ESXi) ransomware-as-a-service operation first identified in November 2021, notorious for triple-extortion tactics (encryption, data-leak-site threats, and DDoS/harassment of victims), extensive use of Cobalt Strike beacons for C2, Evilginx2 adversary-in-the-middle phishing kits to steal MFA/session cookies, and Mega.nz/Dropbox/FileZilla/WinSCP for data exfiltration prior to encryption. The FBI disrupted ALPHV/BlackCat's infrastructure in December 2023, releasing a decryption tool that helped hundreds of victims and reportedly prevented roughly $1 million in further ransom payments before the group later resurfaced amid the high-profile Change Healthcare 'exit scam.'

MITRE ATT&CK techniques used in TL-2026-1174

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

execution

T1047 Windows Management Instrumentation

Defense Evasion

T1055 Process Injection; T1070 Indicator Removal

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing

Persistence

T1112 Modify Registry

Collection

T1213 Data from Information Repositories

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1657 Financial Theft

Credential Access

T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Resource Development

T1585 Establish Accounts

Affected products and versions in Former Ransomware Negotiator Angelo Martino Sentenced to 70

  • N/A — Ransomware incident-response / negotiation trust relationship
    Vulnerable versions: Third-party ransomware negotiator access model

Remediation for Former Ransomware Negotiator Angelo Martino Sentenced to 70

Immediate actions

  • Audit and restrict incident-response/negotiator third-party access to victim negotiation data, insurance policy limits, and financial capacity information
  • Require dual-control or need-to-know compartmentalization for any external negotiator or IR consultant handling active ransomware cases
  • Rotate credentials and revoke third-party consultant access immediately upon incident closure
  • Review cyber-insurance policy disclosure practices to limit which parties can view full coverage limits during active negotiations

Workarounds

  • Engage multiple independent negotiation/legal advisors for high-value ransomware incidents to reduce single-point-of-trust risk
  • Require law-enforcement (FBI) notification and involvement before authorizing large ransom payments

Longer-term hardening

  • Establish contractual insider-threat monitoring and background-vetting requirements for third-party incident-response and ransomware-negotiation vendors
  • Implement segregation of duties so no single negotiator has unilateral, unmonitored access to both attacker communications and internal financial/insurance data
  • Deploy behavioral analytics/DLP on IR vendor communications channels to detect anomalous data exfiltration to attacker-controlled contacts
  • Adopt CISA #StopRansomware AA23-353A mitigations for ALPHV/BlackCat: phishing-resistant MFA, network segmentation, offline immutable backups, and monitoring for Cobalt Strike/Evilginx2 activity

Timeline of Former Ransomware Negotiator Angelo Martino Sentenced to 70

  • ALPHV/BlackCat ransomware-as-a-service operation is first identified, offering affiliates a Rust-based, cross-platform encryptor and roughly an 80/20 profit split favoring affiliates.
  • Between April and September 2023, five companies whose negotiations Martino compromised pay a combined $75.3 million in ransom (nonprofit $26.8M, financial services firm $25.7M, hospitality company $16.5M, plus $6.1M and $213,000 from two others).
  • Angelo Martino, a ransomware negotiator at DigitalMint, begins secretly sharing confidential client negotiating positions and insurance policy limits with ALPHV/BlackCat operators; Kevin Martin and Ryan Goldberg begin directly deploying BlackCat ransomware against additional victims.
  • Martin and Goldberg's direct BlackCat deployment campaign against additional U.S. victims, including a medical firm extorted for roughly $1.3 million, concludes.
  • FBI disrupts ALPHV/BlackCat infrastructure and releases a decryption tool, aiding hundreds of victims and preventing an estimated $1 million in further ransom payments.
  • CISA, FBI, and HHS publish updated joint #StopRansomware advisory AA23-353A detailing ALPHV/BlackCat TTPs and IOCs current as of December 6, 2023.
  • Ryan Goldberg and Kevin Martin plead guilty to conspiracy to obstruct commerce through extortion.
  • Angelo Martino pleads guilty to conspiracy to interfere with interstate commerce through extortion.
  • Ryan Goldberg and Kevin Martin are each sentenced to four years in federal prison.
  • Angelo Martino is sentenced to 70 months in federal prison; law enforcement has seized roughly $10 million in his assets, including two residences, cryptocurrency, vehicles, a food truck, and a fishing boat.
  • Restitution hearing scheduled to determine victim compensation.

Sources cited for Former Ransomware Negotiator Angelo Martino Sentenced to 70

Detection coverage for TL-2026-1174

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1174 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
17 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats