Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months — Threadlinqs Intelligence
As of 2026-07-14, Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months is a high-severity ransomware threat attributed to BlackCat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-1294 · Severity: HIGH · Status: RESOLVED · Category: RANSOMWARE
Attribution: BlackCat · FINANCIAL
Ransomware negotiator Angelo Martino (DigitalMint), with co-conspirators Kevin Martin (DigitalMint) and Ryan Goldberg (Sygnia incident-response manager), secretly fed confidential client negotiation
Between April and September 2023, Angelo John Martino III, a ransomware negotiator employed by Chicago-based incident-response and ransom-negotiation firm DigitalMint, operated as a covert double agent inside five separate ransomware-response engagements. While formally representing victim organizations in negotiations with the BlackCat/ALPHV ransomware-as-a-service (RaaS) operation, Martino used a hidden communication channel to relay confidential client data directly to BlackCat operators — including victims' cyber-insurance policy limits, internal negotiation strategy, and authorized payment ceilings. In at least one documented instance, Martino told the attackers a victim would pay $2 million more than the victim's actual stated offer, allowing BlackCat to extract inflated ransom payments by negotiating against a script Martino himself was feeding them. The five affected DigitalMint clients — spanning nonprofit, financial services, hospitality, and other sectors — ultimately paid ransoms ranging from $213,000 to $26.8 million, for a combined total of $75.3 million.
Martino's conduct escalated in May 2023 when he registered as a BlackCat/ALPHV affiliate in his own right, paying the ransomware operators roughly 20% of proceeds for access to the BlackCat locker and RaaS infrastructure. He recruited Kevin Tyler Martin, a fellow DigitalMint negotiator hired in 2022 after the conspiracy had already begun, and Ryan Clifford Goldberg, an incident-response manager at the separate IR firm Sygnia, to jointly deploy BlackCat ransomware against additional victims between April and November 2023, independent of the DigitalMint negotiation engagements. This direct-deployment track included an attack on a medical-sector organization that yielded roughly $1.2–1.3 million in ransom, split three ways among the conspirators. The scheme thus combined two distinct insider-abuse vectors against the same trust relationship: (1) betraying the negotiator/incident-responder role to feed an active adversary intelligence that maximized extortion outcomes against the negotiator's own clients, and (2) using that same insider knowledge and RaaS access to directly operate as ransomware affiliates.
BlackCat/ALPHV itself was, at the time, one of the most prolific RaaS operations globally, responsible for over $300 million in ransom proceeds from more than 1,000 victims through September 2023 before its data-leak-site infrastructure was seized by law enforcement in December 2023 (with the FBI subsequently releasing a decryption tool). BlackCat affiliates typically gained initial access via social engineering — including impersonating IT/helpdesk personnel — then used legitimate remote-access tooling and frameworks such as Cobalt Strike and Brute Ratel for command-and-control, Metasploit for defense evasion, and cloud services such as Mega.nz and Dropbox for data exfiltration ahead of double-extortion encryption. The malware itself, written in Rust, is capable of encrypting Windows, Linux, and VMware ESXi environments.
Martino, who had prior cybersecurity roles at Booz Allen Hamilton, Tracepoint, and TRM Labs dating to 2015, pleaded guilty to conspiracy to interfere with interstate commerce by extortion (Hobbs Act extortion conspiracy) and was sentenced on July 3, 2026 to 70 months (approximately 5.8 years) in federal prison — above the low end of federal sentencing guidelines (72–87 months range was reported as the guideline calculation) reflecting the court's characterization of his conduct as 'maximizing the harm to his clients.' Martin and Goldberg pleaded guilty in December 2024 and were each sentenced to 48 months on May 1, 2026. Law enforcement seized roughly $10 million in assets tied to Martino, including a $1.68 million waterfront home, a $396,000 single-family home, cryptocurrency wallets, vehicles, a food truck, and a luxury fishing boat. A restitution hearing for Martino was scheduled for September 17, 2026. DigitalMint stated it had no knowle
Target sectors: hospitality, nonprofit, financial services, retail, health, legal services, education, incident response ransom negotiation vendors
Target regions: united states of america
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1585, T1199, T1566, T1059, T1047, T1548, T1134, T1070, T1222, T1112