# Ransomware Negotiator Sentenced to 70 Months for Betraying Extortion Victims and Aiding BlackCat Attacks


A federal court has handed down a significant prison sentence to Angelo Martino, a former ransomware negotiator who exploited his trusted position to secretly work alongside BlackCat ransomware operators. On July 10, 2026, the 41-year-old Florida resident received 70 months (5 years and 10 months) in prison for conspiring with cybercriminals to extort the very clients he was hired to defend. The case represents a stark reminder of how insider threats can compound ransomware attacks and underscores law enforcement's growing commitment to pursuing corruption within incident response and cybersecurity firms.


## The Betrayal: How a Negotiator Became a Double Agent


Angelo Martino's role should have been straightforward: represent five ransomware victims by negotiating with attackers to reduce ransom demands and find pathways to recovery. Instead, Martino operated as what federal prosecutors called "a double agent working to maximize the harm to his clients and the financial gain to cybercriminals who paid him a part of the ransom."


The mechanics of his betrayal were chillingly effective. While negotiating on behalf of victims, Martino provided BlackCat operators with confidential information about:


  • Insurance policy limits — revealing how much coverage victims could access for ransom payments
  • Internal negotiating strategies — detailing the victims' bottom-line positions and fallback offers
  • Real-time negotiation positions — allowing attackers to calculate maximum extortion amounts based on actual victim resources

  • By leaking this sensitive data, Martino gave BlackCat attackers an overwhelming advantage. The victims were bargaining in the dark while their supposed representatives armed the criminals with strategic intelligence. The result was predictable: attackers demanded higher ransoms, knowing exactly how high victims could pay.


    According to prosecutors, Martino not only profited from the increased ransoms but actively colluded with BlackCat operators to maximize their take. He pleaded guilty to one count of conspiracy to interfere with interstate commerce through extortion in April 2026.


    ## A Criminal Conspiracy Within Cybersecurity Firms


    Martino's crimes were not isolated. Federal investigators uncovered a coordinated conspiracy involving two other cybersecurity professionals who attacked multiple U.S. victims between April and November 2023:


    Ryan Goldberg, 41, of Georgia — An incident response manager at Sygnia, a prominent cybersecurity firm. Goldberg was sentenced to four years in prison in May 2026 after pleading guilty to his role in deploying BlackCat ransomware.


    Kevin Martin, 36, of Texas — An employee at DigitalMint (a cryptocurrency-related firm) who also received a four-year sentence in May 2026 for his participation in the attacks.


    Together, this trio successfully deployed BlackCat ransomware against multiple victims across the United States. The coordination between insiders at different organizations and the actual ransomware operators represents a sophisticated criminal operation. Goldberg's position at Sygnia — a respected incident response and cybersecurity consultancy — would have provided valuable intelligence about victim networks, vulnerabilities, and incident response strategies.


    ## BlackCat: A Ransomware Operation With Reach and Resources


    BlackCat, also known as ALPHV, has been one of the most destructive ransomware operations in recent years. The gang operates on a ransomware-as-a-service (RaaS) model, offering its encryption and extortion toolkit to affiliated criminal groups in exchange for a cut of ransom payments. BlackCat's victims have included hospitals, local governments, manufacturing plants, and Fortune 500 companies, with reported losses totaling hundreds of millions of dollars.


    The involvement of insiders like Martino, Goldberg, and Martin expanded BlackCat's reach beyond technical exploitation. By recruiting or compromising individuals within incident response firms and security companies, the gang gained:


  • Advance warning of security improvements victims might implement
  • Detailed victim intelligence before, during, and after attacks
  • Negotiation leverage through real-time information about ransom negotiations
  • Profit maximization through insider knowledge of each victim's financial capacity

  • ## The Financial Exploitation and Asset Seizure


    Martino did not simply pass information for ideological reasons — he was paid by BlackCat operators for his betrayal. Law enforcement's investigation tracked his enrichment through illicit proceeds:


    Federal authorities have seized approximately $10 million in assets from Martino to date, including:


    | Asset Type | Details |

    |---|---|

    | Digital Currency | Cryptocurrency holdings accumulated from ransom payments |

    | Vehicles | High-value automobiles purchased with criminal proceeds |

    | Luxury Boat | A high-end fishing vessel financed by extortion gains |

    | Food Truck | A commercial vehicle asset |


    These seizures reflect the substantial compensation Martino received for his treachery. A restitution hearing is scheduled for September 17, 2026, where a federal judge will determine the full amount Martino must repay to his victims.


    ## Implications for Victim Organizations and Incident Response


    This case exposes a critical vulnerability in the incident response and cybersecurity industry: the potential for insiders to weaponize the trust placed in them during crises.


    For ransomware victims: The case illustrates that hiring an incident response firm or negotiator does not guarantee trustworthiness. Victims must:


  • Verify incident response firm credentials and background check their staff
  • Request written agreements that prohibit sharing negotiation strategies or policy information
  • Use formal contracts with clear confidentiality and fiduciary duty clauses
  • Consider hiring multiple independent advisors rather than relying on a single point of contact

  • For incident response and cybersecurity firms: The prosecutions of Goldberg and Martin send a direct message about corporate accountability. Firms must:


  • Conduct thorough background checks on all employees with client access
  • Implement rigorous internal controls separating access to victim data
  • Monitor suspicious activity among staff members (unusual financial behavior, unexplained absences during major incidents)
  • Establish compliance programs that screen for criminal associations
  • Train employees on legal obligations and reporting requirements

  • For law enforcement: The three convictions demonstrate sustained federal commitment to pursuing insider threats in cybersecurity. The FBI Cyber Division and Department of Justice have made ransomware conspiracy a prosecutorial priority, with agents actively investigating corruption within security firms.


    ## Legal Statements and Official Response


    Assistant U.S. Attorney Jason A. Reding Quiñones for the Southern District of Florida emphasized the gravity of Martino's betrayal: "He was hired to help victims in a moment of crisis. Instead, Martino betrayed them, fed their confidential negotiating positions to ransomware criminals, and helped squeeze them for more money. This case sends a clear message: we will pursue the hackers who deploy ransomware, the insiders who enable them, and the money they steal from American victims."


    Assistant Attorney General A. Tysen Duva of the Criminal Division added that "Angelo Martino's victims shared heartbreaking accounts of how their businesses were nearly destroyed, while the people they hired to help them instead betrayed them to ransomware gangs."


    FBI Assistant Director Brett Leatherman of the Cyber Division characterized the case plainly: "Angelo Martino sold out the very victims he was hired to represent, handing their confidential negotiating positions to BlackCat actors to drive up ransoms and enrich himself."


    ## HackWire Analysis


    What makes this case noteworthy beyond the headline is the sophisticated intersection of insider threats with ransomware operations. For years, security teams have focused on external attackers — and rightly so. But Martino, Goldberg, and Martin represent a harder problem: corruption within the trusted responders themselves.


    This pattern should concern every organization that experiences a ransomware incident. When you hire incident response, you're necessarily exposing your negotiating position, insurance details, and vulnerability data. Traditionally, this was assumed to be a controlled risk — incident responders are vetted professionals bound by contracts and ethics. The Martino case shatters that assumption.


    More broadly, the case exposes BlackCat's operational sophistication. A ransomware gang that can successfully recruit or corrupt insiders at Sygnia (a firm trusted by major organizations) has moved beyond script-kiddie opportunism into genuine enterprise-level threat operations. This is extortion as a service, supported by a criminal supply chain.


    For defenders, the tactical lesson is uncomfortable: assume your negotiators might be compromised. Use multiple independent advisors. Share sensitive negotiation data on a need-to-know basis. Verify that incident response firms have genuine separation of duties and oversight.


    For prosecutors, this is a blueprint for dismantling ransomware operations at scale — pursue not just the code-deployers but the information brokers and insiders who amplify their success. The FBI has clearly adopted this strategy, and it's yielding convictions.


    — *HackWire Editorial*


    ## Recommendations for Organizations


  • Verify incident response firms before engagement; request background checks on assigned staff
  • Compartmentalize information — never share complete negotiation strategies with a single advisor
  • Document all communications with incident response teams for compliance and audit purposes
  • Use written contracts that explicitly prohibit disclosure of negotiation positions or insurance details
  • Monitor your own staff for suspicious financial activity or unauthorized access to ransomware victim data
  • Report suspected insider threats immediately to FBI Cyber Division (tips.fbi.gov or local FBI field office)

  • ---


    ## Related Coverage


  • Read more in our [Ransomware](https://www.hackwire.news/category/ransomware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)