Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months
Insider Ransomware Negotiators Colluded with BlackCat/ALPHV (TL-2026-1294), also tracked as DigitalMint insider ransomware scheme, is a high-severity ransomware operation, first published 2026-07-14. It is attributed to BlackCat with high confidence, affects DigitalMint Ransomware negotiation / incident-response services, maps to 27 MITRE ATT&CK techniques (T1005, T1018, T1033), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-1294
- Threat ID
- TL-2026-1294
- Also known as
- DigitalMint insider ransomware scheme, BlackCat double-agent negotiator case
- Severity
- HIGH
- Status
- RESOLVED
- Category
- RANSOMWARE
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution
- BlackCat
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- hospitality, nonprofit, financial services, retail, health, legal services, education, incident response ransom negotiation vendors
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Insider Ransomware Negotiators Colluded with BlackCat/ALPHV
Malware and tooling: BlackCat (Windows), BlackCat - S1068, Brute Ratel C4 - S1063, Cobalt Strike, metasploit
Ransomware negotiator Angelo Martino (DigitalMint), with co-conspirators Kevin Martin (DigitalMint) and Ryan Goldberg (Sygnia incident-response manager), secretly fed confidential client negotiation data to BlackCat/ALPHV starting April 2023, then became BlackCat affiliates deploying attacks themselves. Five DigitalMint clients paid a combined $75.3 million; the trio also directly deployed BlackCat against additional victims, splitting roughly $1.3 million from a medical-sector ransom. Martino was sentenced to 70 months on July 3, 2026; Martin and Goldberg each received 48-month sentences on May 1, 2026.
How Insider Ransomware Negotiators Colluded with BlackCat/ALPHV works
Between April and September 2023, Angelo John Martino III, a ransomware negotiator employed by Chicago-based incident-response and ransom-negotiation firm DigitalMint, operated as a covert double agent inside five separate ransomware-response engagements. While formally representing victim organizations in negotiations with the BlackCat/ALPHV ransomware-as-a-service (RaaS) operation, Martino used a hidden communication channel to relay confidential client data directly to BlackCat operators — including victims' cyber-insurance policy limits, internal negotiation strategy, and authorized payment ceilings. In at least one documented instance, Martino told the attackers a victim would pay $2 million more than the victim's actual stated offer, allowing BlackCat to extract inflated ransom payments by negotiating against a script Martino himself was feeding them. The five affected DigitalMint clients — spanning nonprofit, financial services, hospitality, and other sectors — ultimately paid ransoms ranging from $213,000 to $26.8 million, for a combined total of $75.3 million.
Martino's conduct escalated in May 2023 when he registered as a BlackCat/ALPHV affiliate in his own right, paying the ransomware operators roughly 20% of proceeds for access to the BlackCat locker and RaaS infrastructure. He recruited Kevin Tyler Martin, a fellow DigitalMint negotiator hired in 2022 after the conspiracy had already begun, and Ryan Clifford Goldberg, an incident-response manager at the separate IR firm Sygnia, to jointly deploy BlackCat ransomware against additional victims between April and November 2023, independent of the DigitalMint negotiation engagements. This direct-deployment track included an attack on a medical-sector organization that yielded roughly $1.2–1.3 million in ransom, split three ways among the conspirators. The scheme thus combined two distinct insider-abuse vectors against the same trust relationship: (1) betraying the negotiator/incident-responder role to feed an active adversary intelligence that maximized extortion outcomes against the negotiator's own clients, and (2) using that same insider knowledge and RaaS access to directly operate as ransomware affiliates.
BlackCat/ALPHV itself was, at the time, one of the most prolific RaaS operations globally, responsible for over $300 million in ransom proceeds from more than 1,000 victims through September 2023 before its data-leak-site infrastructure was seized by law enforcement in December 2023 (with the FBI subsequently releasing a decryption tool). BlackCat affiliates typically gained initial access via social engineering — including impersonating IT/helpdesk personnel — then used legitimate remote-access tooling and frameworks such as Cobalt Strike and Brute Ratel for command-and-control, Metasploit for defense evasion, and cloud services such as Mega.nz and Dropbox for data exfiltration ahead of double-extortion encryption. The malware itself, written in Rust, is capable of encrypting Windows, Linux, and VMware ESXi environments.
Martino, who had prior cybersecurity roles at Booz Allen Hamilton, Tracepoint, and TRM Labs dating to 2015, pleaded guilty to conspiracy to interfere with interstate commerce by extortion (Hobbs Act extortion conspiracy) and was sentenced on July 3, 2026 to 70 months (approximately 5.8 years) in federal prison — above the low end of federal sentencing guidelines (72–87 months range was reported as the guideline calculation) reflecting the court's characterization of his conduct as 'maximizing the harm to his clients.' Martin and Goldberg pleaded guilty in December 2024 and were each sentenced to 48 months on May 1, 2026. Law enforcement seized roughly $10 million in assets tied to Martino, including a $1.68 million waterfront home, a $396,000 single-family home, cryptocurrency wallets, vehicles, a food truck, and a luxury fishing boat. A restitution hearing for Martino was scheduled for September 17, 2026. DigitalMint stated it had no knowledge of Martino's conduct and that he 'deliberately concealed' his activities from standard industry controls; the firm declined to disclose whether it refunded affected clients. Sygnia did not issue a public statement in reporting reviewed.
The case is a significant supply-chain / third-party-trust risk exemplar for the incident-response and ransom-negotiation industry: it demonstrates that the confidentiality and independence assumptions underlying third-party IR/negotiation engagements can be subverted from within, materially worsening ransomware outcomes for victims who believed they were being represented in good faith against the adversary.
MITRE ATT&CK techniques used in TL-2026-1294
Collection
Discovery
T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1135 Network Share Discovery
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter
Defense Evasion
T1070 Indicator Removal; T1134 Access Token Manipulation
defense-impairment
T1112 Modify Registry; T1222 File and Directory Permissions Modification
Initial Access
T1199 Trusted Relationship; T1566 Phishing
Command and Control
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement; T1657 Financial Theft
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Exfiltration
T1567 Exfiltration Over Web Service
Lateral Movement
Resource Development
Affected products and versions in Insider Ransomware Negotiators Colluded with BlackCat/ALPHV
- DigitalMint — Ransomware negotiation / incident-response services
Vulnerable versions: 2022-2023 engagements involving Angelo Martino and Kevin Martin - Sygnia — Incident response services
Vulnerable versions: 2022-2023 engagements involving Ryan Goldberg
Remediation for Insider Ransomware Negotiators Colluded with BlackCat/ALPHV
Immediate actions
- Audit all active and historical ransomware negotiation/IR engagements for unauthorized communication channels between vendor personnel and threat actors
- Require dual-custody or witnessed negotiation sessions for all ransom communications with threat actors
- Mandate that cyber-insurance policy limits and internal authorized-payment ceilings never be disclosed to negotiators beyond the minimum needed for a single negotiation round
- Rotate any negotiation/incident-response vendor relationships where personnel had unsupervised solo access to victim financial and insurance data
- Review DigitalMint- and Sygnia-brokered engagements from 2022-2023 for signs of inflated settlements or anomalous negotiation patterns
Workarounds
- Engage a second, independent IR/negotiation firm to shadow-review high-value ransom negotiations
- Withhold precise insurance policy limits from negotiators; provide only an authorized negotiation ceiling on a need-to-know, per-round basis
Longer-term hardening
- Contractually require IR/negotiation vendors to disclose all personnel with prior ransomware-adjacent employment history or financial ties to threat-actor ecosystems
- Implement independent, real-time oversight (e.g., recorded/logged negotiation chat channels reviewed by a separate compliance function) for all ransom negotiations
- Establish a vendor-risk program specifically for incident-response and ransom-negotiation firms, treating them as high-trust, high-risk third parties
- Deploy behavioral monitoring/DLP on negotiator workstations and communication tools to detect exfiltration of client insurance/negotiation data
- Build in-house or co-sourced negotiation capability to reduce single-vendor dependency for high-value ransomware incidents
Timeline of Insider Ransomware Negotiators Colluded with BlackCat/ALPHV
- Angelo Martino is hired as a ransomware negotiator at DigitalMint while already engaged in undisclosed criminal collusion activity; Kevin Martin is later hired as a fellow DigitalMint negotiator in 2022 after the conspiracy had begun.
- Martino begins secretly relaying confidential client negotiation data — including cyber-insurance policy limits and internal negotiation strategy — to BlackCat/ALPHV operators via a hidden communication channel, across five DigitalMint client engagements.
- Martino registers as a BlackCat/ALPHV ransomware affiliate, paying operators roughly 20% of proceeds for locker and RaaS infrastructure access, and shares this access with Kevin Martin and Ryan Goldberg.
- Five DigitalMint clients across nonprofit, financial services, and hospitality sectors have paid a combined $75.3 million in ransoms (individual payments ranging $213,000 to $26.8 million) as a direct result of the compromised negotiations.
- Martino, Martin, and Goldberg conclude their direct BlackCat ransomware deployment campaign against additional victims (outside the DigitalMint negotiation channel), including a medical-sector target yielding roughly $1.2-1.3 million split among the three.
- Law enforcement disrupts BlackCat/ALPHV, seizing its data-leak-site infrastructure; the FBI subsequently releases a decryption tool for victims.
- Kevin Martin and Ryan Goldberg plead guilty to their roles in the conspiracy.
- Angelo Martino pleads guilty to conspiracy to interfere with interstate commerce by extortion (Hobbs Act extortion conspiracy).
- Kevin Martin and Ryan Goldberg are each sentenced to 48 months in federal prison for their roles deploying BlackCat ransomware.
- Angelo Martino is sentenced to 70 months in federal prison; the court characterizes his conduct as deliberately 'maximizing the harm to his clients.'
- DOJ sentencing announcement is widely covered by security and mainstream media (Malwarebytes, BleepingComputer, The Hacker News, CyberScoop, Help Net Security, and others), surfacing the case as a landmark insider-threat/vendor-risk precedent for the IR and ransom-negotiation industry.
- Martino is scheduled to return to federal court for a restitution determination hearing covering the $75.3 million in victim losses.
Sources cited for Insider Ransomware Negotiators Colluded with BlackCat/ALPHV
- The inside job that cost ransomware victims millions
- Ransomware negotiator who betrayed clients sentenced to 70 months in prison
- Florida Ransomware Negotiator Who Extorted and Attacked Multiple U.S. Victims Sentenced to Prison
- US ransomware negotiator gets 4 years in prison for BlackCat attacks
- Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
- Ransomware negotiator who ran BlackCat 'double agent' scheme against DigitalMint clients gets nearly six years
- Ex-ransomware negotiator gets 70 months for betraying clients to hackers
- Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
- Ex-Chicago ransomware negotiator gets nearly 6 years in prison for aiding hackers
- A ransomware negotiator who colluded with attackers to scam victims was sentenced to 70 months in prison
- #StopRansomware: ALPHV Blackcat
- BlackCat, Software S1068
- Response to the Revised CISA Advisory (AA23-353A) - Emulating ALPHV/BlackCat
Threats related to Insider Ransomware Negotiators Colluded with BlackCat/ALPHV
- Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme
- DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Insider Extortion Conspiracy
- Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims
- Everest Ransomware: Triple Extortion via Encryption, Access Brokering, and Insider Recruitment
- The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go Encryptor
- Everest Ransomware Group Demands $12.3M from Stadler Rail via Third-Party Supplier Breach
Detection coverage for TL-2026-1294
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1294 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.