Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims — Threadlinqs Intelligence
As of 2026-07-13, Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims is a medium-severity threat actor threat attributed to BlackCat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1264 · Severity: MEDIUM · Status: RESOLVED · Category: THREAT_ACTOR
Attribution: BlackCat · FINANCIAL
Angelo Martino, a former ransomware negotiator at DigitalMint, was sentenced to 70 months in federal prison for conspiring with BlackCat/ALPHV ransomware operators between April and November 2023,
Angelo John Martino III, 41, of Land O'Lakes, Florida, worked as a ransomware negotiator at Chicago-based incident response firm DigitalMint, where he was hired by victim organizations to negotiate down ransom demands from ransomware operators, including affiliates of the BlackCat/ALPHV Ransomware-as-a-Service (RaaS) operation. Beginning in April 2023, Martino covertly acted as a double agent: while publicly representing his employer's clients in negotiations, he secretly fed BlackCat affiliates confidential information obtained through his negotiator role, including victims' internal negotiating positions and strategy, cyber-insurance policy limits, and internal risk assessments. This intelligence let the ransomware operators calibrate demands to extract the maximum amount each victim could plausibly pay, rather than the amount victims disclosed during negotiation. Martino was paid by the BlackCat actors for this information.
Across five identified victim organizations targeted between April and September 2023 -- a nonprofit organization (~$26.8M paid), a financial services company (~$25.7M paid), a hospitality company (~$16.5M paid), and two additional companies ($6.1M and $213,000 paid) -- Martino's conduct enabled combined extortion payments/demands of approximately $75.3 million. He also received roughly $1.2 million in Bitcoin directly tied to one case and split a $1.3 million ransom from a medical company with co-conspirators.
Martino separately conspired with Kevin Tyler Martin, 36, a fellow DigitalMint ransomware negotiator hired after the scheme began, and Ryan Clifford Goldberg, 33/41 (sources vary), an incident response manager at cybersecurity firm Sygnia, to actively help deploy BlackCat ransomware against at least four additional U.S. victim organizations between April 2023 and November 2023 -- including a financial services firm, a nonprofit, school districts, medical facilities, and law firms. The three received a 20% cut of ransom proceeds paid to BlackCat administrators in exchange for providing initial access, targeting intelligence, and negotiation intelligence. The group threatened to leak stolen data before encrypting victim systems, consistent with BlackCat/ALPHV's standard double-extortion model.
BlackCat/ALPHV, a Rust-based Ransomware-as-a-Service operation first identified in November 2021, is estimated by the FBI and CISA to have collected at least $300 million in ransom payments from over 1,000 victims worldwide before affiliates, including this insider group, continued operations after a partial law-enforcement disruption of BlackCat's infrastructure in December 2023 (a takedown the group publicly claimed was an 'exit scam').
Martino pleaded guilty on April 14, 2026, to a one-count criminal information charging conspiracy to interfere with interstate commerce by extortion (the Hobbs Act), and was sentenced on July 10, 2026 to 70 months in prison by Judge K. Michael Moore in the U.S. District Court for the Southern District of Florida. Martin and Goldberg pleaded guilty in December 2025 to the same charge and were each sentenced on May 1, 2026 to 48 months. Law enforcement (FBI, working with DOJ Criminal Division) seized more than $10 million in assets from Martino tied to the scheme, including a bayfront home (~$1.68M), a second residence (~$396K), luxury vehicles, a food truck, a 29-foot fishing boat, and cryptocurrency wallets. A restitution hearing for Martino is scheduled for September 17, 2026.
DigitalMint stated publicly that Martino's actions were deliberately concealed from the company and violated its values, ethics standards, and the law; it suspended Martino's access in April 2025 upon DOJ notification and said it used industry-standard background-check controls. The case is a significant insider-threat and trust-boundary failure within the incident-response/ransomware-negotiation industry: organizations that hire IR firms to negotiate with ransomware operators on their behalf impl
Target sectors: financial services, nonprofit, hospitality, health, education, legal services, incident response cybersecurity services
Target regions: united states of america
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_ACTOR, MEDIUM, threat intelligence, cybersecurity, T1585, T1591, T1078, T1566, T1078, T1484, T1562, T1003, T1046, T1213