# Former Ransomware Negotiator Sentenced to Nearly 6 Years for BlackCat Extortion Attacks
A federal judge has handed down a significant conviction in what prosecutors describe as an unprecedented insider threat case: Angelo Martino, a 41-year-old former ransomware negotiator at cybersecurity firm DigitalMint, was sentenced to 70 months in federal prison for his role in orchestrating BlackCat (ALPHV) ransomware attacks against U.S. organizations between 2023 and 2025.
The sentencing marks a rare prosecution of insiders who abused their position within the incident response industry to maximize extortion payouts, revealing a dangerous vulnerability: threat negotiators with knowledge of victims' insurance policies and negotiation strategies can become force multipliers for criminal ransomware syndicates.
## The Conspiracy: Insiders Turn Against Their Clients
Martino was not acting alone. He coordinated with two other former cybersecurity employees: Kevin Tyler Martin (28) and Ryan Clifford Goldberg (33), both previously employed at Sygnia and DigitalMint. All three pleaded guilty to conspiracy to obstruct commerce by extortion.
Between April 2023 and April 2025, the three men worked as BlackCat affiliate operators, gaining access to the ransomware-as-a-service platform in exchange for paying the gang's administrators a 20% commission on all ransom proceeds they collected. This affiliate model allowed them to operate with relative independence while funneling a steady stream of revenue upward to the BlackCat leadership.
Their criminal enterprise was particularly brazen because they exploited their day jobs to gather intelligence:
The impact was devastating. Their victims included a financial services firm that paid $25.66 million and a nonprofit organization forced to pay $26.79 million in ransom. Additional targets encompassed school districts, medical facilities, law firms, and other financial services companies.
## Background: The BlackCat Threat
BlackCat (also tracked as ALPHV) emerged as one of the most prolific ransomware operations in the threat landscape. According to FBI analysis cited in the indictment:
The gang is known for:
The operation demonstrates a mature, business-like structure typical of top-tier ransomware-as-a-service platforms, where the gang leadership maintains the platform while affiliates conduct attacks and negotiate ransom payments.
## How the Insider Threat Was Discovered
Court documents unsealed in March 2026 revealed the full scope of the conspiracy. Martino was initially referred to only as "Co-Conspirator 1" in an October 2025 indictment, but court filings later identified him by name.
DigitalMint CEO Jonathan Solomon issued a statement condemning the actions: *"We strongly condemn these former employees' criminal behavior, which violated our values, ethical standards, and the law. When we learned about the conduct, we immediately terminated both individuals."*
The timing of the discovery—the three-year operation running from April 2023 through April 2025—suggests that investigators spent considerable time building the case before public charges emerged. The coordination required to link multiple incidents, identify the perpetrators, and gather evidence of their communications with BlackCat operators represents significant investigative work.
## Sentencing and Legal Consequences
On May 2026, Martin and Goldberg each received four-year sentences after pleading guilty in December 2025. Martino's sentence of 70 months (5 years 10 months) reflects the more serious charges and his leadership role in the conspiracy.
All three face additional consequences:
The sentencing guidelines for extortion conspiracy cases typically recommend longer sentences for cases involving larger financial damages and sophisticated coordination—factors all present here.
## Implications: The Insider Threat Crisis in Cybersecurity
This case exposes a critical vulnerability in the incident response industry: the asymmetric power dynamic between negotiators and victims.
Ransomware negotiators operate with highly sensitive information:
A negotiator with conflicting loyalties can weaponize this intelligence to dramatically increase extortion success rates. Rather than negotiating down ransom demands (their legitimate role), insiders can ensure demands perfectly match what victims can afford to pay.
This fundamentally changes the risk calculus for incident response firms:
## HackWire Analysis
The Martino case reveals a systemic weakness in how the incident response industry manages conflicts of interest. Unlike most cybercrime prosecutions—which pursue external threat actors—this case targets trusted insiders whose value came from their legitimacy and access.
The real story is not about three opportunistic criminals, but about an industry that normalized highly sensitive access without corresponding transparency or oversight. A ransomware negotiator reviewing victim insurance limits and negotiation positions is structurally different from a network security employee—they collect economically sensitive intelligence that directly determines extortion payouts.
What makes this particularly concerning is the scale. Between 2023 and 2025, these three individuals didn't just pocket bribes—they systematically optimized ransom demands across multiple victim organizations. A $26.79 million nonprofit payment doesn't happen without inside knowledge of exactly what that organization could bear to pay.
The industry response will be critical. Will incident response firms implement negotiation transparency measures? Will they separate ransomware negotiators from operational security staff? Will they establish third-party oversight of ransom decisions? The current model—where negotiators have access to victim financial intelligence with minimal external accountability—has proven vulnerable to insider exploitation.
Organizations should view this not as an anomaly but as a proof-of-concept. If three employees at major incident response firms attempted this, it means the opportunity exists elsewhere. Victims should demand transparency: Who sets ransom targets? What information do negotiators access? What oversight prevents self-dealing?
— HackWire Editorial
## Recommendations for Organizations
In light of this case, organizations should consider the following defensive measures:
For firms engaged in ransom negotiations:
For potential victims:
For law enforcement and regulators:
## Related Coverage