Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims
Former Ransomware Negotiator Angelo Martino Sentenced to 70 (TL-2026-1264), also tracked as DigitalMint insider extortion case, is a medium-severity tracked threat-actor profile, first published 2026-07-13. It is attributed to BlackCat with high confidence, affects DigitalMint Ransomware negotiation / incident response services, maps to 16 MITRE ATT&CK techniques (T1003, T1046, T1071), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1264
- Threat ID
- TL-2026-1264
- Also known as
- DigitalMint insider extortion case
- Severity
- MEDIUM
- Status
- RESOLVED
- Category
- THREAT_ACTOR
- First published
- 2026-07-13
- Last reviewed
- 2026-07-13
- Attribution
- BlackCat
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- financial services, nonprofit, hospitality, health, education, legal services, incident response cybersecurity services
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Former Ransomware Negotiator Angelo Martino Sentenced to 70
Malware and tooling: BlackCat (Windows), BlackCat - S1068, BlackCat data leak site
Angelo Martino, a former ransomware negotiator at DigitalMint, was sentenced to 70 months in federal prison for conspiring with BlackCat/ALPHV ransomware operators between April and November 2023, leaking confidential client negotiating positions and insurance limits from five victim organizations to maximize extortion demands totaling $75.3 million. Co-conspirators Kevin Martin (DigitalMint) and Ryan Goldberg (Sygnia) were each sentenced to 48 months for helping deploy BlackCat ransomware against additional victims.
How Former Ransomware Negotiator Angelo Martino Sentenced to 70 works
Angelo John Martino III, 41, of Land O'Lakes, Florida, worked as a ransomware negotiator at Chicago-based incident response firm DigitalMint, where he was hired by victim organizations to negotiate down ransom demands from ransomware operators, including affiliates of the BlackCat/ALPHV Ransomware-as-a-Service (RaaS) operation. Beginning in April 2023, Martino covertly acted as a double agent: while publicly representing his employer's clients in negotiations, he secretly fed BlackCat affiliates confidential information obtained through his negotiator role, including victims' internal negotiating positions and strategy, cyber-insurance policy limits, and internal risk assessments. This intelligence let the ransomware operators calibrate demands to extract the maximum amount each victim could plausibly pay, rather than the amount victims disclosed during negotiation. Martino was paid by the BlackCat actors for this information.
Across five identified victim organizations targeted between April and September 2023 -- a nonprofit organization (~$26.8M paid), a financial services company (~$25.7M paid), a hospitality company (~$16.5M paid), and two additional companies ($6.1M and $213,000 paid) -- Martino's conduct enabled combined extortion payments/demands of approximately $75.3 million. He also received roughly $1.2 million in Bitcoin directly tied to one case and split a $1.3 million ransom from a medical company with co-conspirators.
Martino separately conspired with Kevin Tyler Martin, 36, a fellow DigitalMint ransomware negotiator hired after the scheme began, and Ryan Clifford Goldberg, 33/41 (sources vary), an incident response manager at cybersecurity firm Sygnia, to actively help deploy BlackCat ransomware against at least four additional U.S. victim organizations between April 2023 and November 2023 -- including a financial services firm, a nonprofit, school districts, medical facilities, and law firms. The three received a 20% cut of ransom proceeds paid to BlackCat administrators in exchange for providing initial access, targeting intelligence, and negotiation intelligence. The group threatened to leak stolen data before encrypting victim systems, consistent with BlackCat/ALPHV's standard double-extortion model.
BlackCat/ALPHV, a Rust-based Ransomware-as-a-Service operation first identified in November 2021, is estimated by the FBI and CISA to have collected at least $300 million in ransom payments from over 1,000 victims worldwide before affiliates, including this insider group, continued operations after a partial law-enforcement disruption of BlackCat's infrastructure in December 2023 (a takedown the group publicly claimed was an 'exit scam').
Martino pleaded guilty on April 14, 2026, to a one-count criminal information charging conspiracy to interfere with interstate commerce by extortion (the Hobbs Act), and was sentenced on July 10, 2026 to 70 months in prison by Judge K. Michael Moore in the U.S. District Court for the Southern District of Florida. Martin and Goldberg pleaded guilty in December 2025 to the same charge and were each sentenced on May 1, 2026 to 48 months. Law enforcement (FBI, working with DOJ Criminal Division) seized more than $10 million in assets from Martino tied to the scheme, including a bayfront home (~$1.68M), a second residence (~$396K), luxury vehicles, a food truck, a 29-foot fishing boat, and cryptocurrency wallets. A restitution hearing for Martino is scheduled for September 17, 2026.
DigitalMint stated publicly that Martino's actions were deliberately concealed from the company and violated its values, ethics standards, and the law; it suspended Martino's access in April 2025 upon DOJ notification and said it used industry-standard background-check controls. The case is a significant insider-threat and trust-boundary failure within the incident-response/ransomware-negotiation industry: organizations that hire IR firms to negotiate with ransomware operators on their behalf implicitly trust those firms with highly sensitive financial and strategic data (insurance limits, board risk tolerance, negotiation floors/ceilings), and this case demonstrates that data can be monetized by a corrupted insider working in direct collusion with the same threat actor group the firm was ostensibly hired to counter.
MITRE ATT&CK techniques used in TL-2026-1264
Credential Access
Discovery
T1046 Network Service Discovery
Command and Control
T1071 Application Layer Protocol
Collection
T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1078 Valid Accounts; T1566 Phishing
Persistence
Privilege Escalation
T1484 Domain or Tenant Policy Modification
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1657 Financial Theft
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Reconnaissance
T1591 Gather Victim Org Information
defense-impairment
Affected products and versions in Former Ransomware Negotiator Angelo Martino Sentenced to 70
- DigitalMint — Ransomware negotiation / incident response services
Vulnerable versions: service delivery process, April 2023 - November 2023
Fixed in: N/A - personnel terminated April 2025 - Sygnia — Incident response services
Vulnerable versions: service delivery process, April 2023 - November 2023
Fixed in: N/A - personnel prosecuted
Remediation for Former Ransomware Negotiator Angelo Martino Sentenced to 70
Immediate actions
- Audit incident-response/ransomware-negotiation vendor contracts for confidentiality, data-handling, and insider-threat controls
- Restrict internal circulation of insurance policy limits and negotiating-position strategy to the minimum necessary personnel
- Require IR/negotiation vendors to disclose personnel background-check and access-control practices before engagement
- Review historical ransomware negotiations for anomalous demand escalation patterns that may indicate leaked negotiating positions
Workarounds
- Use segmented communication channels so a single negotiator does not have full visibility into both insurance limits and internal risk tolerance simultaneously
Longer-term hardening
- Implement need-to-know compartmentalization for ransom negotiation data between internal stakeholders and external negotiators
- Require dual-vendor or independent oversight for high-value ransomware negotiations
- Establish contractual audit rights and insider-threat monitoring clauses with third-party IR/negotiation firms
- Maintain cyber-insurance policy limit confidentiality separate from negotiation vendor disclosures where feasible
Timeline of Former Ransomware Negotiator Angelo Martino Sentenced to 70
- BlackCat/ALPHV Ransomware-as-a-Service operation first identified, a Rust-based RaaS estimated to have breached at least 60 entities worldwide by March 2022.
- Martino, Kevin Martin (DigitalMint), and Ryan Goldberg (Sygnia) begin a separate conspiracy to actively help deploy BlackCat ransomware against additional U.S. victim organizations, receiving a 20% cut of ransom proceeds.
- Angelo Martino, a ransomware negotiator at DigitalMint, begins conspiring with BlackCat/ALPHV affiliates, feeding them confidential client negotiating positions and insurance policy limits in exchange for payment.
- The five primary victims exploited via leaked negotiating data are targeted between April and September 2023, resulting in a combined $75.3 million in ransom demands/payments.
- Court documents reference a specific BlackCat deployment attack against 'Victim 9' by the conspirators.
- The active BlackCat deployment conspiracy involving Martino, Martin, and Goldberg against additional victims concludes.
- FBI and international law enforcement partners disrupt BlackCat/ALPHV infrastructure, seizing the group's data leak site; CISA and FBI jointly publish advisory AA23-353A detailing BlackCat TTPs and IOCs.
- DigitalMint suspends Angelo Martino's access to company systems after being notified by the Department of Justice of his conduct.
- Kevin Martin and Ryan Goldberg plead guilty to conspiracy to obstruct commerce by extortion for the ransomware deployment conspiracy.
- Angelo Martino pleads guilty to a one-count criminal information charging conspiracy to interfere with interstate commerce through extortion (Hobbs Act).
- Kevin Martin and Ryan Goldberg are each sentenced to 48 months in prison by Judge K. Michael Moore, U.S. District Court, Southern District of Florida.
- Angelo Martino is sentenced to 70 months in prison for his role in the extortion conspiracy; DOJ and FBI officials issue public statements condemning the insider betrayal.
- Case coverage aggregated and reported by Help Net Security and other outlets, highlighting the incident-response/negotiation industry trust-boundary implications.
- A hearing to determine the restitution amount owed by Angelo Martino to victims is scheduled.
Sources cited for Former Ransomware Negotiator Angelo Martino Sentenced to 70
- Former ransomware negotiator sentenced to prison for conspiring with BlackCat gang
- Florida Ransomware Negotiator Who Extorted and Attacked Multiple U.S. Victims Sentenced to Prison
- Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims
- Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
- Former DigitalMint ransomware negotiator pleads guilty to extortion scheme
- Ex-Chicago ransomware negotiator gets nearly 6 years in prison for aiding hackers
- Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
- Former ransomware negotiator sentenced to 70 months for extorting $75.3 million
- Former ransomware negotiator gets 4 years for BlackCat attacks
- Ransomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prison
- Florida ransomware negotiator convicted for helping ransomware gang extort US companies
- Former Ransomware Negotiator Sentenced to 70 Months in Prison for Secretly Helping BlackCat Gang
- Ransomware Negotiator Gets 6 Years in Prison for Assisting Scammers
- #StopRansomware: ALPHV Blackcat (AA23-353A)
Threats related to Former Ransomware Negotiator Angelo Martino Sentenced to 70
- DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Insider Extortion Conspiracy
- Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months
- Azure Blob Storage Ransomware: Four Storage-Encryption Abuse Methods (BlackCat/ALPHV, STORM-0501)
- Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme
- Fake Interpol Investigation Emails Deliver Custom Ransomware to Small Businesses
- DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker
Detection coverage for TL-2026-1264
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1264 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.