Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims

Former Ransomware Negotiator Angelo Martino Sentenced to 70 (TL-2026-1264), also tracked as DigitalMint insider extortion case, is a medium-severity tracked threat-actor profile, first published 2026-07-13. It is attributed to BlackCat with high confidence, affects DigitalMint Ransomware negotiation / incident response services, maps to 16 MITRE ATT&CK techniques (T1003, T1046, T1071), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1264

Threat ID
TL-2026-1264
Also known as
DigitalMint insider extortion case
Severity
MEDIUM
Status
RESOLVED
Category
THREAT_ACTOR
First published
2026-07-13
Last reviewed
2026-07-13
Attribution
BlackCat
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
financial services, nonprofit, hospitality, health, education, legal services, incident response cybersecurity services
Target regions
united states of america
Detection rules
9
Indicators of compromise
20

Malware and tooling in Former Ransomware Negotiator Angelo Martino Sentenced to 70

Malware and tooling: BlackCat (Windows), BlackCat - S1068, BlackCat data leak site

Angelo Martino, a former ransomware negotiator at DigitalMint, was sentenced to 70 months in federal prison for conspiring with BlackCat/ALPHV ransomware operators between April and November 2023, leaking confidential client negotiating positions and insurance limits from five victim organizations to maximize extortion demands totaling $75.3 million. Co-conspirators Kevin Martin (DigitalMint) and Ryan Goldberg (Sygnia) were each sentenced to 48 months for helping deploy BlackCat ransomware against additional victims.

How Former Ransomware Negotiator Angelo Martino Sentenced to 70 works

Angelo John Martino III, 41, of Land O'Lakes, Florida, worked as a ransomware negotiator at Chicago-based incident response firm DigitalMint, where he was hired by victim organizations to negotiate down ransom demands from ransomware operators, including affiliates of the BlackCat/ALPHV Ransomware-as-a-Service (RaaS) operation. Beginning in April 2023, Martino covertly acted as a double agent: while publicly representing his employer's clients in negotiations, he secretly fed BlackCat affiliates confidential information obtained through his negotiator role, including victims' internal negotiating positions and strategy, cyber-insurance policy limits, and internal risk assessments. This intelligence let the ransomware operators calibrate demands to extract the maximum amount each victim could plausibly pay, rather than the amount victims disclosed during negotiation. Martino was paid by the BlackCat actors for this information.

Across five identified victim organizations targeted between April and September 2023 -- a nonprofit organization (~$26.8M paid), a financial services company (~$25.7M paid), a hospitality company (~$16.5M paid), and two additional companies ($6.1M and $213,000 paid) -- Martino's conduct enabled combined extortion payments/demands of approximately $75.3 million. He also received roughly $1.2 million in Bitcoin directly tied to one case and split a $1.3 million ransom from a medical company with co-conspirators.

Martino separately conspired with Kevin Tyler Martin, 36, a fellow DigitalMint ransomware negotiator hired after the scheme began, and Ryan Clifford Goldberg, 33/41 (sources vary), an incident response manager at cybersecurity firm Sygnia, to actively help deploy BlackCat ransomware against at least four additional U.S. victim organizations between April 2023 and November 2023 -- including a financial services firm, a nonprofit, school districts, medical facilities, and law firms. The three received a 20% cut of ransom proceeds paid to BlackCat administrators in exchange for providing initial access, targeting intelligence, and negotiation intelligence. The group threatened to leak stolen data before encrypting victim systems, consistent with BlackCat/ALPHV's standard double-extortion model.

BlackCat/ALPHV, a Rust-based Ransomware-as-a-Service operation first identified in November 2021, is estimated by the FBI and CISA to have collected at least $300 million in ransom payments from over 1,000 victims worldwide before affiliates, including this insider group, continued operations after a partial law-enforcement disruption of BlackCat's infrastructure in December 2023 (a takedown the group publicly claimed was an 'exit scam').

Martino pleaded guilty on April 14, 2026, to a one-count criminal information charging conspiracy to interfere with interstate commerce by extortion (the Hobbs Act), and was sentenced on July 10, 2026 to 70 months in prison by Judge K. Michael Moore in the U.S. District Court for the Southern District of Florida. Martin and Goldberg pleaded guilty in December 2025 to the same charge and were each sentenced on May 1, 2026 to 48 months. Law enforcement (FBI, working with DOJ Criminal Division) seized more than $10 million in assets from Martino tied to the scheme, including a bayfront home (~$1.68M), a second residence (~$396K), luxury vehicles, a food truck, a 29-foot fishing boat, and cryptocurrency wallets. A restitution hearing for Martino is scheduled for September 17, 2026.

DigitalMint stated publicly that Martino's actions were deliberately concealed from the company and violated its values, ethics standards, and the law; it suspended Martino's access in April 2025 upon DOJ notification and said it used industry-standard background-check controls. The case is a significant insider-threat and trust-boundary failure within the incident-response/ransomware-negotiation industry: organizations that hire IR firms to negotiate with ransomware operators on their behalf implicitly trust those firms with highly sensitive financial and strategic data (insurance limits, board risk tolerance, negotiation floors/ceilings), and this case demonstrates that data can be monetized by a corrupted insider working in direct collusion with the same threat actor group the firm was ostensibly hired to counter.

MITRE ATT&CK techniques used in TL-2026-1264

Credential Access

T1003 OS Credential Dumping

Discovery

T1046 Network Service Discovery

Command and Control

T1071 Application Layer Protocol

Collection

T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories

Initial Access

T1078 Valid Accounts; T1566 Phishing

Persistence

T1078 Valid Accounts

Privilege Escalation

T1484 Domain or Tenant Policy Modification

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1585 Establish Accounts

Reconnaissance

T1591 Gather Victim Org Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Former Ransomware Negotiator Angelo Martino Sentenced to 70

  • DigitalMint — Ransomware negotiation / incident response services
    Vulnerable versions: service delivery process, April 2023 - November 2023
    Fixed in: N/A - personnel terminated April 2025
  • Sygnia — Incident response services
    Vulnerable versions: service delivery process, April 2023 - November 2023
    Fixed in: N/A - personnel prosecuted

Remediation for Former Ransomware Negotiator Angelo Martino Sentenced to 70

Immediate actions

  • Audit incident-response/ransomware-negotiation vendor contracts for confidentiality, data-handling, and insider-threat controls
  • Restrict internal circulation of insurance policy limits and negotiating-position strategy to the minimum necessary personnel
  • Require IR/negotiation vendors to disclose personnel background-check and access-control practices before engagement
  • Review historical ransomware negotiations for anomalous demand escalation patterns that may indicate leaked negotiating positions

Workarounds

  • Use segmented communication channels so a single negotiator does not have full visibility into both insurance limits and internal risk tolerance simultaneously

Longer-term hardening

  • Implement need-to-know compartmentalization for ransom negotiation data between internal stakeholders and external negotiators
  • Require dual-vendor or independent oversight for high-value ransomware negotiations
  • Establish contractual audit rights and insider-threat monitoring clauses with third-party IR/negotiation firms
  • Maintain cyber-insurance policy limit confidentiality separate from negotiation vendor disclosures where feasible

Timeline of Former Ransomware Negotiator Angelo Martino Sentenced to 70

  • BlackCat/ALPHV Ransomware-as-a-Service operation first identified, a Rust-based RaaS estimated to have breached at least 60 entities worldwide by March 2022.
  • Martino, Kevin Martin (DigitalMint), and Ryan Goldberg (Sygnia) begin a separate conspiracy to actively help deploy BlackCat ransomware against additional U.S. victim organizations, receiving a 20% cut of ransom proceeds.
  • Angelo Martino, a ransomware negotiator at DigitalMint, begins conspiring with BlackCat/ALPHV affiliates, feeding them confidential client negotiating positions and insurance policy limits in exchange for payment.
  • The five primary victims exploited via leaked negotiating data are targeted between April and September 2023, resulting in a combined $75.3 million in ransom demands/payments.
  • Court documents reference a specific BlackCat deployment attack against 'Victim 9' by the conspirators.
  • The active BlackCat deployment conspiracy involving Martino, Martin, and Goldberg against additional victims concludes.
  • FBI and international law enforcement partners disrupt BlackCat/ALPHV infrastructure, seizing the group's data leak site; CISA and FBI jointly publish advisory AA23-353A detailing BlackCat TTPs and IOCs.
  • DigitalMint suspends Angelo Martino's access to company systems after being notified by the Department of Justice of his conduct.
  • Kevin Martin and Ryan Goldberg plead guilty to conspiracy to obstruct commerce by extortion for the ransomware deployment conspiracy.
  • Angelo Martino pleads guilty to a one-count criminal information charging conspiracy to interfere with interstate commerce through extortion (Hobbs Act).
  • Kevin Martin and Ryan Goldberg are each sentenced to 48 months in prison by Judge K. Michael Moore, U.S. District Court, Southern District of Florida.
  • Angelo Martino is sentenced to 70 months in prison for his role in the extortion conspiracy; DOJ and FBI officials issue public statements condemning the insider betrayal.
  • Case coverage aggregated and reported by Help Net Security and other outlets, highlighting the incident-response/negotiation industry trust-boundary implications.
  • A hearing to determine the restitution amount owed by Angelo Martino to victims is scheduled.

Sources cited for Former Ransomware Negotiator Angelo Martino Sentenced to 70

Threats related to Former Ransomware Negotiator Angelo Martino Sentenced to 70

Detection coverage for TL-2026-1264

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1264 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats