Threat reportCybercrimeTL-2026-1174
Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Insider Collusion with BlackCat/ALPHV Affiliates Ryan Goldberg and Kevin Martin
Former Ransomware Negotiator Angelo Martino Sentenced to 70 (TL-2026-1174), also tracked as Ransomware Negotiator Insider Case, is a medium-severity cybercrime threat, first published 2026-07-10. It is attributed to ALPHV with high confidence, affects N/A Ransomware incident-response / negotiation trust relationship, maps to 18 MITRE ATT&CK techniques (T1041, T1047, T1055), and is covered by 9 detection rules and 17 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 3ALPHV
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-1174
- Threat ID
- TL-2026-1174
- Also known as
- Ransomware Negotiator Insider Case, DigitalMint Insider Collusion Case, Operation Riptide
- Severity
- MEDIUM
- Status
- RESOLVED
- Category
- CYBERCRIME
- First published
- Last reviewed
- Attribution
- ALPHV, BlackCat, Ryan Goldberg
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- nonprofit, financial services, hospitality, health, professional services, incident response negotiation firms
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in Former Ransomware Negotiator Angelo Martino Sentenced to 70
Malware and tooling: ALPHV/BlackCat, BlackCat (Windows), Cobalt Strike, FileZilla, WinSCP, evilginx2 - S9003
How Former Ransomware Negotiator Angelo Martino Sentenced to 70 works
Angelo John Martino III, a former ransomware negotiator at DigitalMint, was sentenced to 70 months in federal prison for conspiring with ALPHV/BlackCat ransomware affiliates Ryan Goldberg (ex-Sygnia incident-response manager) and Kevin Martin (ex-DigitalMint negotiator) to extort at least ten U.S. companies for a combined $75.3+ million between April and December 2023. Martino abused his negotiator access to leak victims' confidential negotiating positions and insurance policy limits to the attackers in exchange for a cut of the ransom.
Between April and December 2023, three former cybersecurity professionals — Angelo John Martino III (a ransomware negotiator employed by incident-response/negotiation firm DigitalMint), Kevin Tyler Martin (also a DigitalMint negotiator), and Ryan Clifford Goldberg (an incident-response manager at Sygnia) — conspired to deploy ALPHV/BlackCat ransomware against and extort at least ten U.S. companies. Martino used his trusted position as a professional ransomware negotiator, hired by victim organizations specifically to resolve ransomware incidents, to secretly act as a 'double agent': he passed BlackCat operators confidential information about his own clients' negotiating strategy, financial capacity, and cyber-insurance policy limits, allowing the attackers to calibrate ransom demands for maximum extraction. In return, Martino and his co-conspirators received a share of the ransom proceeds paid to ALPHV/BlackCat administrators (the RaaS operators reportedly retained roughly a 20% affiliate cut of ransom payments under the group's ransomware-as-a-service model). Separately, Martin and Goldberg directly deployed BlackCat ransomware against additional victims, netting further payments including approximately $1.2 million in Bitcoin from one target and roughly $1.3 million from a medical firm. Overall, prosecutors identified at least five negotiated-victim companies extorted for a combined $75.3 million (a nonprofit paid $26.8M, a financial services firm paid $25.7M, a hospitality company paid $16.5M, and two others paid $6.1M and $213,000, respectively) tied to Martino's insider leaks, plus additional deployment-based extortion attributed to Martin and Goldberg. The group laundered cryptocurrency ransom proceeds through split wallets and converted funds into real estate, vehicles, a food truck, and a luxury fishing boat. The FBI's Miami Field Office, with U.S. Secret Service support, investigated the case under 'Operation Riptide'; when Goldberg attempted to flee the country, the FBI tracked him across ten nations before his arrest. Goldberg and Martin each pleaded guilty in December 2025 to conspiracy to obstruct commerce through extortion and were sentenced in May 2026 to four years each. Martino pleaded guilty in April 2026 to the same charge and was sentenced in July 2026 to 70 months (nearly six years) — the statutory maximum was 20 years. Law enforcement seized approximately $10 million in assets from Martino alone, including two residences (a $1.68 million Bayfront home and a $396,000 second residence), cryptocurrency wallets, vehicles, a food truck, and a 29-foot fishing boat. A restitution hearing was scheduled for September 17, 2026. The case underscores a novel insider-threat vector distinct from a typical technical intrusion: it did not require the attackers to breach the negotiator firm's systems — it relied entirely on trusted-insider betrayal of the incident-response/negotiation trust relationship, a role explicitly created to protect ransomware victims. ALPHV/BlackCat itself is a Rust-based, cross-platform (Windows, Linux, VMware ESXi) ransomware-as-a-service operation first identified in November 2021, notorious for triple-extortion tactics (encryption, data-leak-site threats, and DDoS/harassment of victims), extensive use of Cobalt Strike beacons for C2, Evilginx2 adversary-in-the-middle phishing kits to steal MFA/session cookies, and Mega.nz/Dropbox/FileZilla/WinSCP for data exfiltration prior to encryption. The FBI disrupted ALPHV/BlackCat's infrastructure in December 2023, releasing a decryption tool that helped hundreds of victims and reportedly prevented roughly $1 million in further ransom payments before the group later resurfaced amid the high-profile Change Healthcare 'exit scam.'
MITRE ATT&CK techniques used in TL-2026-1174
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1047 Windows Management Instrumentation
Defense Evasion
T1055 Process Injection; T1070 Indicator Removal
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing
Persistence
Collection
T1213 Data from Information Repositories
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1657 Financial Theft
Credential Access
T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Resource Development
Affected products and versions in Former Ransomware Negotiator Angelo Martino Sentenced to 70
- N/A — Ransomware incident-response / negotiation trust relationship
Vulnerable versions: Third-party ransomware negotiator access model
Remediation for Former Ransomware Negotiator Angelo Martino Sentenced to 70
Immediate actions
- Audit and restrict incident-response/negotiator third-party access to victim negotiation data, insurance policy limits, and financial capacity information
- Require dual-control or need-to-know compartmentalization for any external negotiator or IR consultant handling active ransomware cases
- Rotate credentials and revoke third-party consultant access immediately upon incident closure
- Review cyber-insurance policy disclosure practices to limit which parties can view full coverage limits during active negotiations
Workarounds
- Engage multiple independent negotiation/legal advisors for high-value ransomware incidents to reduce single-point-of-trust risk
- Require law-enforcement (FBI) notification and involvement before authorizing large ransom payments
Longer-term hardening
- Establish contractual insider-threat monitoring and background-vetting requirements for third-party incident-response and ransomware-negotiation vendors
- Implement segregation of duties so no single negotiator has unilateral, unmonitored access to both attacker communications and internal financial/insurance data
- Deploy behavioral analytics/DLP on IR vendor communications channels to detect anomalous data exfiltration to attacker-controlled contacts
- Adopt CISA #StopRansomware AA23-353A mitigations for ALPHV/BlackCat: phishing-resistant MFA, network segmentation, offline immutable backups, and monitoring for Cobalt Strike/Evilginx2 activity
Timeline of Former Ransomware Negotiator Angelo Martino Sentenced to 70
- ALPHV/BlackCat ransomware-as-a-service operation is first identified, offering affiliates a Rust-based, cross-platform encryptor and roughly an 80/20 profit split favoring affiliates.
- Between April and September 2023, five companies whose negotiations Martino compromised pay a combined $75.3 million in ransom (nonprofit $26.8M, financial services firm $25.7M, hospitality company $16.5M, plus $6.1M and $213,000 from two others).
- Angelo Martino, a ransomware negotiator at DigitalMint, begins secretly sharing confidential client negotiating positions and insurance policy limits with ALPHV/BlackCat operators; Kevin Martin and Ryan Goldberg begin directly deploying BlackCat ransomware against additional victims.
- Martin and Goldberg's direct BlackCat deployment campaign against additional U.S. victims, including a medical firm extorted for roughly $1.3 million, concludes.
- FBI disrupts ALPHV/BlackCat infrastructure and releases a decryption tool, aiding hundreds of victims and preventing an estimated $1 million in further ransom payments.
- CISA, FBI, and HHS publish updated joint #StopRansomware advisory AA23-353A detailing ALPHV/BlackCat TTPs and IOCs current as of December 6, 2023.
- Ryan Goldberg and Kevin Martin plead guilty to conspiracy to obstruct commerce through extortion.
- Angelo Martino pleads guilty to conspiracy to interfere with interstate commerce through extortion.
- Ryan Goldberg and Kevin Martin are each sentenced to four years in federal prison.
- Angelo Martino is sentenced to 70 months in federal prison; law enforcement has seized roughly $10 million in his assets, including two residences, cryptocurrency, vehicles, a food truck, and a fishing boat.
- Restitution hearing scheduled to determine victim compensation.
Sources cited for Former Ransomware Negotiator Angelo Martino Sentenced to 70
- Ransomware Negotiator Sentenced
- Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison
- Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims
- Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
- Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
- Two cybersecurity pros get prison time for helping ransomware gang
- American Cybersecurity Professionals Given Jail Terms for BlackCat Ransomware Attacks
- Ransomware Negotiator Pleads Guilty to Working For BlackCat Cyber Gang
- Ransomware negotiator admits role in attacks he was hired to resolve
- Four Years in Prison for Cybersecurity Pros Turned Ransomware Attackers
- #StopRansomware: ALPHV Blackcat (AA23-353A)
- Response to the Revised CISA Advisory (AA23-353A): ALPHV BlackCat
- The Anatomy of a BlackCat Ransomware (ALPHV) Attack
- ALPHV's Downfall? The 2023 Crackdown on BlackCat Ransomware
- FBI Releases IOCs Associated with BlackCat/ALPHV Ransomware
Detection coverage for TL-2026-1174
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1174 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.