# Cybersecurity Insider Sentenced to 70 Months for Aiding BlackCat Ransomware Gang


Angelo Martino becomes third US security expert imprisoned for supplying ransomware operators with victim negotiation data, exposing systemic insider threat vulnerabilities across the industry.


---


## The Threat


Angelo Martino, a 41-year-old Florida resident and former ransomware negotiator, was sentenced on Thursday to 70 months (5.8 years) in federal prison for his role as an inside operative for the BlackCat/Alphv ransomware organization. His case represents the third major prosecution of cybersecurity professionals who betrayed their employers and clients by directly aiding threat actors—a pattern that exposes a critical vulnerability within the cybersecurity industry itself.


Martino, who worked at cybersecurity firms where his official role was to negotiate ransom payments on behalf of victims, instead used his privileged position to provide confidential intelligence to the very attackers he was ostensibly working against. In doing so, he fundamentally compromised the negotiation process for at least five separate victim organizations and maximized losses for companies already in crisis.


---


## Background and Context


The Martino case is part of a coordinated federal prosecution involving three security professionals who collaborated with BlackCat ransomware operators in 2023. The other two defendants—Kevin Martin from Texas and Ryan Goldberg from Georgia—were each sentenced to 48 months in federal prison in late April 2026, roughly three months before Martino's sentencing.


All three men worked at cybersecurity firms where they held roles either directly involved in ransom negotiation or with access to sensitive victim information. Rather than using this access to protect clients, they weaponized it.


### BlackCat/Alphv: The Ransomware Organization


BlackCat (also known as Alphv) emerged as one of the most prolific ransomware operations in the criminal underground. Between 2021 and December 2023—when the organization was disrupted by law enforcement—the gang:


  • Targeted over 1,000 organizations across multiple sectors, including healthcare, finance, critical infrastructure, and manufacturing
  • Demanded ransoms ranging from hundreds of thousands to tens of millions of dollars
  • Operated as a ransomware-as-a-service (RaaS) platform, licensing their tools and infrastructure to affiliated threat actors
  • Maintained a dark web leak site where they published stolen data from non-compliant victims

  • Following its disruption, the organization attempted an exit scam, extracting a $22 million ransom from a final victim before disappearing from public view.


    ---


    ## Technical Details: How the Insider Threat Worked


    Martino's cooperation with BlackCat began in April 2023 and followed a straightforward but devastating operational model:


    ### The Scheme


    | Component | Details |

    |-----------|---------|

    | Martino's Role | Ransomware negotiator for cybersecurity firm clients |

    | Confidential Information Provided | Victim negotiating positions, settlement strategies, financial constraints, and resistance thresholds |

    | Compensation Model | Direct payments from BlackCat, plus profit-sharing from inflated ransom demands |

    | Victim Impact | At least 5 confirmed victim organizations subjected to tailored extortion |

    | Duration | April 2023 through at least early 2024 |


    According to Department of Justice filings, Martino received compensation from BlackCat to:


  • Disclose the negotiating position of his employer's clients in real time or near-real time
  • Reveal the cybersecurity strategy clients were employing to resist ransom demands
  • Identify financial thresholds and payment authority within victim organizations
  • Provide intelligence on law enforcement involvement in negotiations

  • This information allowed BlackCat operators to calibrate their extortion demands with surgical precision, bypassing negotiation tactics and targeting exact financial breaking points within victim organizations.


    ### The Cost of Compromise


    When law enforcement executed seizure warrants against Martino, they recovered approximately $10 million in illicit assets, including:


  • Cryptocurrency holdings
  • Luxury vehicles
  • A food truck
  • A fishing boat

  • The Martino case illustrates that insider threats within cybersecurity firms don't require sophisticated espionage tradecraft—they exploit the natural trust placed in professionals who already have legitimate access to sensitive information.


    ---


    ## Implications for the Cybersecurity Industry


    The Martino-Martin-Goldberg prosecutions expose a structural vulnerability in how cybersecurity firms operate and manage personnel:


    ### Systemic Risks


    1. Compromised Negotiation Integrity

    Ransomware negotiation is a critical control point where security professionals interface directly with victims during their most vulnerable moments. If negotiators are working for the attacker, the entire negotiation framework collapses.


    2. Access Control Failures

    All three defendants held roles that granted them access to confidential victim information, financial data, and strategic decision-making processes. Minimal monitoring or compartmentalization allowed them to extract and exfiltrate this data with relative ease.


    3. Insider Threat Blind Spots

    None of these individuals raised immediate red flags through traditional security monitoring. Their access was legitimate, their data requests appeared routine, and their positions provided plausible cover for information gathering.


    4. Low Barrier to Entry for Organized Crime

    The case demonstrates that ransomware gangs actively target and recruit cybersecurity professionals. The financial incentives (cryptocurrency payments, profit-sharing arrangements) are sufficient to corrupt individuals with legitimate employment.


    ### Industry-Wide Exposure


    With BlackCat alone having targeted over 1,000 organizations before its disruption, it is reasonable to assume that at least some portion of those attacks benefited from insider intelligence. The Martino-Martin-Goldberg network, if it represents 10-20% of insider compromises in the ransomware ecosystem, suggests hundreds of additional organizations may have faced extortion where negotiation strategies were already known to attackers.


    ---


    ## Legal and Sentencing Outcomes


    Martino pleaded guilty in April 2026, acknowledging his cooperation with BlackCat. His 70-month sentence is notably longer than those of Martin and Goldberg (48 months each), suggesting either:


  • A greater level of involvement or coordination with BlackCat
  • More victims directly harmed by his intelligence sharing
  • Additional criminal activity not publicly disclosed
  • Judicial assessment of specific aggravating factors

  • Restitution Determination: The court has scheduled a separate hearing in September 2026 to determine the amount Martino must pay in restitution to victims. Given the estimated impact of BlackCat operations and the direct connection between Martino's information and victim losses, this figure could reach into the millions.


    ---


    ## HackWire Analysis


    This case signals a fundamental shift in how ransomware gangs operate: they've moved beyond technical exploitation to systematic compromises of the humans who defend against them. The Martino-Martin-Goldberg prosecutions aren't anomalies—they represent a proven, scalable model for maximizing ransom extraction by eliminating the negotiation process entirely.


    Why now matters: The three prosecutions cluster in 2026, suggesting federal investigators identified and rolled up this network over the past 18-24 months. However, BlackCat operations continued through December 2023, meaning these insider compromises persisted for 7-8 months before resolution. Organizations that negotiated with BlackCat during April-December 2023 should assume their internal financial data, strategic resistance thresholds, and negotiation limits were known to attackers in advance.


    The pattern extends beyond BlackCat. Ransomware operators have systematized insider recruitment as a revenue optimization tactic. If security professionals can be flipped at scale, the entire cybersecurity industry's operational model—which depends on negotiators, incident responders, and forensic specialists having trusted access to sensitive victim data—becomes a liability rather than an asset.


    For defenders: Organizations should assume that any large ransomware negotiation involving external cybersecurity firms may be compromised at the negotiation layer. Segregation of negotiation strategy from operational details, real-time monitoring of external access to financial and strategic information, and insider threat programs specifically designed for security staff are no longer optional. The cost of assuming negotiators are trustworthy is now measured in tens of millions in inflated ransoms and extended extortion demands.


    HackWire Editorial


    ---


    ## Recommendations


    For Victim Organizations:

  • Audit all ransom negotiations conducted between April 2023 and December 2023 that involved the three identified defendants or their firms
  • Request forensic analysis of whether negotiation strategies were compromised
  • Review final settlement amounts against pre-attack financial capacity assessments
  • Report suspected over-payment or anomalies to law enforcement and insurance carriers

  • For Cybersecurity Firms:

  • Implement real-time access logging and alerting for sensitive victim information
  • Segregate negotiation roles from incident response and forensic roles
  • Conduct background investigations and financial vulnerability assessments for staff with high-privileged access
  • Establish insider threat monitoring programs specifically designed for security staff
  • Implement multi-person approval workflows for access to victim negotiation strategies and financial data

  • For Law Enforcement:

  • Expand insider threat investigations within the cybersecurity services industry
  • Coordinate with international law enforcement to identify additional compromised negotiators
  • Pursue financial asset recovery from cryptocurrency holdings and business assets
  • Establish FBI task forces within major cybersecurity firms to monitor for recruitment attempts by ransomware gangs

  • For Industry Regulators:

  • Mandate insider threat training and certification for employees with access to victim financial data
  • Require regular audits of access logs to sensitive information within security firms
  • Establish information-sharing protocols for suspected insider threats across firms

  • ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)