# Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Insider Collusion with BlackCat/ALPHV Affiliates Ryan Goldberg and Kevin Martin

> Angelo John Martino III, a former ransomware negotiator at DigitalMint, was sentenced to 70 months in federal prison for conspiring with ALPHV/BlackCat ransomware affiliates Ryan Goldberg (ex-Sygnia incident-response manager) and Kevin Martin (ex-DigitalMint negotiator) to extort at least ten U.S. companies for a combined $75.3+ million between April and December 2023. Martino abused his negotiator access to leak victims' confidential negotiating positions and insurance policy limits to the attackers in exchange for a cut of the ransom.

- **Published:** 2026-07-10T00:00:00Z
- **Last reviewed:** 2026-07-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1174
- **ID:** TL-2026-1174
- **Severity:** MEDIUM
- **Category:** CYBERCRIME
- **Status:** RESOLVED
- **Actor:** ALPHV
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Between April and December 2023, three former cybersecurity professionals — Angelo John Martino III (a ransomware negotiator employed by incident-response/negotiation firm DigitalMint), Kevin Tyler Martin (also a DigitalMint negotiator), and Ryan Clifford Goldberg (an incident-response manager at Sygnia) — conspired to deploy ALPHV/BlackCat ransomware against and extort at least ten U.S. companies. Martino used his trusted position as a professional ransomware negotiator, hired by victim organizations specifically to resolve ransomware incidents, to secretly act as a 'double agent': he passed BlackCat operators confidential information about his own clients' negotiating strategy, financial capacity, and cyber-insurance policy limits, allowing the attackers to calibrate ransom demands for maximum extraction. In return, Martino and his co-conspirators received a share of the ransom proceeds paid to ALPHV/BlackCat administrators (the RaaS operators reportedly retained roughly a 20% affiliate cut of ransom payments under the group's ransomware-as-a-service model). Separately, Martin and Goldberg directly deployed BlackCat ransomware against additional victims, netting further payments including approximately $1.2 million in Bitcoin from one target and roughly $1.3 million from a medical firm. Overall, prosecutors identified at least five negotiated-victim companies extorted for a combined $75.3 million (a nonprofit paid $26.8M, a financial services firm paid $25.7M, a hospitality company paid $16.5M, and two others paid $6.1M and $213,000, respectively) tied to Martino's insider leaks, plus additional deployment-based extortion attributed to Martin and Goldberg. The group laundered cryptocurrency ransom proceeds through split wallets and converted funds into real estate, vehicles, a food truck, and a luxury fishing boat. The FBI's Miami Field Office, with U.S. Secret Service support, investigated the case under 'Operation Riptide'; when Goldberg attempted to flee the country, the FBI tracked him across ten nations before his arrest. Goldberg and Martin each pleaded guilty in December 2025 to conspiracy to obstruct commerce through extortion and were sentenced in May 2026 to four years each. Martino pleaded guilty in April 2026 to the same charge and was sentenced in July 2026 to 70 months (nearly six years) — the statutory maximum was 20 years. Law enforcement seized approximately $10 million in assets from Martino alone, including two residences (a $1.68 million Bayfront home and a $396,000 second residence), cryptocurrency wallets, vehicles, a food truck, and a 29-foot fishing boat. A restitution hearing was scheduled for September 17, 2026. The case underscores a novel insider-threat vector distinct from a typical technical intrusion: it did not require the attackers to breach the negotiator firm's systems — it relied entirely on trusted-insider betrayal of the incident-response/negotiation trust relationship, a role explicitly created to protect ransomware victims. ALPHV/BlackCat itself is a Rust-based, cross-platform (Windows, Linux, VMware ESXi) ransomware-as-a-service operation first identified in November 2021, notorious for triple-extortion tactics (encryption, data-leak-site threats, and DDoS/harassment of victims), extensive use of Cobalt Strike beacons for C2, Evilginx2 adversary-in-the-middle phishing kits to steal MFA/session cookies, and Mega.nz/Dropbox/FileZilla/WinSCP for data exfiltration prior to encryption. The FBI disrupted ALPHV/BlackCat's infrastructure in December 2023, releasing a decryption tool that helped hundreds of victims and reportedly prevented roughly $1 million in further ransom payments before the group later resurfaced amid the high-profile Change Healthcare 'exit scam.'

## MITRE ATT&CK

- T1199 Trusted Relationship
- T1566 Phishing
- T1078 Valid Accounts
- T1557 Adversary-in-the-Middle
- T1539 Steal Web Session Cookie
- T1105 Ingress Tool Transfer
- T1071 Application Layer Protocol
- T1055 Process Injection
- T1070 Indicator Removal
- T1047 Windows Management Instrumentation
- T1112 Modify Registry
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1657 Financial Theft
- T1213 Data from Information Repositories
- T1585 Establish Accounts

## Sources

- [Ransomware Negotiator Sentenced](https://cybersecuritynews.com/ransomware-negotiator-sentenced/)
- [Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison](https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced)
- [Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims](https://www.justice.gov/opa/pr/florida-man-working-ransomware-negotiator-pleads-guilty-conspiracy-deploy-ransomware-and)
- [Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail](https://cyberscoop.com/digitalmint-ransomware-negotiator-angelo-martino-sentenced/)
- [Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks](https://thehackernews.com/2026/07/ransomware-negotiator-gets-70-months-in.html)
- [Two cybersecurity pros get prison time for helping ransomware gang](https://www.helpnetsecurity.com/2026/05/04/cybersecurity-experts-alphv-blackcat-ransomware-sentenced/)
- [American Cybersecurity Professionals Given Jail Terms for BlackCat Ransomware Attacks](https://www.hipaajournal.com/u-s-nationals-indicted-blackcat-ransomware-attacks/)
- [Ransomware Negotiator Pleads Guilty to Working For BlackCat Cyber Gang](https://www.infosecurity-magazine.com/news/former-ransomware-negotiator/)
- [Ransomware negotiator admits role in attacks he was hired to resolve](https://www.helpnetsecurity.com/2026/04/21/ransomware-negotiator-blackcat-alphv-group/)
- [Four Years in Prison for Cybersecurity Pros Turned Ransomware Attackers](https://www.bitdefender.com/en-us/blog/hotforsecurity/four-years-in-prison-for-cybersecurity-pros-turned-ransomware-attackers)
- [#StopRansomware: ALPHV Blackcat (AA23-353A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a)
- [Response to the Revised CISA Advisory (AA23-353A): ALPHV BlackCat](https://www.attackiq.com/2024/03/07/emulating-alphv-blackcat/)
- [The Anatomy of a BlackCat Ransomware (ALPHV) Attack](https://www.sygnia.co/blog/blackcat-ransomware/)
- [ALPHV's Downfall? The 2023 Crackdown on BlackCat Ransomware](https://flashpoint.io/blog/alphvs-downfall-crackdown-blackcat-ransomware/)
- [FBI Releases IOCs Associated with BlackCat/ALPHV Ransomware](https://www.cisa.gov/news-events/alerts/2022/04/22/fbi-releases-iocs-associated-blackcatalphv-ransomware)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1174
