Former DigitalMint Negotiator Jailed for Aiding BlackCat Ransomware Extortion

Two other former ransomware negotiators, Kevin Tyler Martin and Ryan Clifford Goldberg, collaborated with Martino and pleaded guilty to conspiracy to obstruct commerce by extortion; both were sentenced to four years in prison.
The operation included a 20% share arrangement with BlackCat admins for access to the extortion portal, meaning the trio profited directly from ransom proceeds.
Victim impact included a financial services firm paying about $25.66 million and a nonprofit paying about $26.793 million, with multiple other victims including school districts and medical facilities.
Martino began collaborating with BlackCat in April 2023, sharing confidential information such as victims’ insurance policy limits and negotiation positions to help attackers maximize ransom demands.
The BlackCat (ALPHV) operation was linked to more than 60 breaches between November 2021 and March 2022, with over 1,000 victims and at least $300 million in ransom payments by September 2023.
A former ransomware negotiator has been sentenced to 70 months in federal prison for secretly helping the BlackCat/ALPHV ransomware gang extort the very clients he was hired to protect, according to BleepingComputer. Angelo Martino, 41, of Land O'Lakes, Florida, worked for DigitalMint, a cybersecurity incident response firm, while feeding confidential victim data directly to criminals.
Two colleagues — Kevin Tyler Martin and Ryan Clifford Goldberg — pleaded guilty to the same conspiracy and each received four years in prison, Security Affairs reported. Together, the three men turned a trusted crisis-response role into a criminal operation that extracted tens of millions of dollars from victims.
Martino began working with BlackCat admins in April 2023. His job was to help victims negotiate lower ransom payments. Instead, he shared their insurance policy limits and negotiation positions with the hackers, according to Security Affairs. That gave attackers the upper hand. They knew exactly how much victims could pay — and pushed for every dollar.
The arrangement was structured like a business deal. Martino and his co-conspirators received a 20% cut of ransom proceeds in exchange for access to BlackCat's extortion portal, BleepingComputer reported. The trio did not just pass along tips. They actively participated in the attacks.
The financial damage was severe. One financial services firm paid roughly $25.66 million in ransom. A nonprofit paid about $26.79 million. Other victims included school districts and medical facilities, according to IT Pro. The insiders' knowledge of victim finances helped drive payments far above what attackers might otherwise have demanded.
Healthcare organizations were among the hardest hit. HEAL Security noted that Martino's actions directly aided attacks on hospitals and nonprofits already under strain. The insider access made each attack more precise and more damaging than a typical ransomware strike.
BlackCat, also known as ALPHV, was already one of the most prolific ransomware groups before Martino joined their operation. The FBI linked them to more than 60 breaches between November 2021 and March 2022 alone. By September 2023, the gang had hit over 1,000 victims and collected at least $300 million in ransom payments, according to Security Affairs.
The group operated a professional extortion portal — a tool that made it easy for insiders like Martino to plug directly into their criminal infrastructure. Law enforcement eventually disrupted BlackCat, but the insider threat angle revealed by this case adds a new layer to the group's known tactics.
This case exposes a gap in how organizations think about cybersecurity. Companies spend heavily to stop outside hackers. But Martino sat inside the crisis response process. He had access to victim insurance details, negotiation strategies, and direct communication lines — everything an attacker needs, IT Pro reported.
Experts say the risk calls for stronger vetting and monitoring of incident response professionals. These workers handle some of the most sensitive data that exists — during the worst moments a company faces. Without controls on that access, even the people hired to help can become the threat.
Publishers
17
Articles
4
Reach
21