# Cybersecurity Insider Sentenced to 70 Months for Aiding BlackCat Ransomware Gang
Angelo Martino becomes third US security expert imprisoned for supplying ransomware operators with victim negotiation data, exposing systemic insider threat vulnerabilities across the industry.
---
## The Threat
Angelo Martino, a 41-year-old Florida resident and former ransomware negotiator, was sentenced on Thursday to 70 months (5.8 years) in federal prison for his role as an inside operative for the BlackCat/Alphv ransomware organization. His case represents the third major prosecution of cybersecurity professionals who betrayed their employers and clients by directly aiding threat actors—a pattern that exposes a critical vulnerability within the cybersecurity industry itself.
Martino, who worked at cybersecurity firms where his official role was to negotiate ransom payments on behalf of victims, instead used his privileged position to provide confidential intelligence to the very attackers he was ostensibly working against. In doing so, he fundamentally compromised the negotiation process for at least five separate victim organizations and maximized losses for companies already in crisis.
---
## Background and Context
The Martino case is part of a coordinated federal prosecution involving three security professionals who collaborated with BlackCat ransomware operators in 2023. The other two defendants—Kevin Martin from Texas and Ryan Goldberg from Georgia—were each sentenced to 48 months in federal prison in late April 2026, roughly three months before Martino's sentencing.
All three men worked at cybersecurity firms where they held roles either directly involved in ransom negotiation or with access to sensitive victim information. Rather than using this access to protect clients, they weaponized it.
### BlackCat/Alphv: The Ransomware Organization
BlackCat (also known as Alphv) emerged as one of the most prolific ransomware operations in the criminal underground. Between 2021 and December 2023—when the organization was disrupted by law enforcement—the gang:
Following its disruption, the organization attempted an exit scam, extracting a $22 million ransom from a final victim before disappearing from public view.
---
## Technical Details: How the Insider Threat Worked
Martino's cooperation with BlackCat began in April 2023 and followed a straightforward but devastating operational model:
### The Scheme
| Component | Details |
|-----------|---------|
| Martino's Role | Ransomware negotiator for cybersecurity firm clients |
| Confidential Information Provided | Victim negotiating positions, settlement strategies, financial constraints, and resistance thresholds |
| Compensation Model | Direct payments from BlackCat, plus profit-sharing from inflated ransom demands |
| Victim Impact | At least 5 confirmed victim organizations subjected to tailored extortion |
| Duration | April 2023 through at least early 2024 |
According to Department of Justice filings, Martino received compensation from BlackCat to:
This information allowed BlackCat operators to calibrate their extortion demands with surgical precision, bypassing negotiation tactics and targeting exact financial breaking points within victim organizations.
### The Cost of Compromise
When law enforcement executed seizure warrants against Martino, they recovered approximately $10 million in illicit assets, including:
The Martino case illustrates that insider threats within cybersecurity firms don't require sophisticated espionage tradecraft—they exploit the natural trust placed in professionals who already have legitimate access to sensitive information.
---
## Implications for the Cybersecurity Industry
The Martino-Martin-Goldberg prosecutions expose a structural vulnerability in how cybersecurity firms operate and manage personnel:
### Systemic Risks
1. Compromised Negotiation Integrity
Ransomware negotiation is a critical control point where security professionals interface directly with victims during their most vulnerable moments. If negotiators are working for the attacker, the entire negotiation framework collapses.
2. Access Control Failures
All three defendants held roles that granted them access to confidential victim information, financial data, and strategic decision-making processes. Minimal monitoring or compartmentalization allowed them to extract and exfiltrate this data with relative ease.
3. Insider Threat Blind Spots
None of these individuals raised immediate red flags through traditional security monitoring. Their access was legitimate, their data requests appeared routine, and their positions provided plausible cover for information gathering.
4. Low Barrier to Entry for Organized Crime
The case demonstrates that ransomware gangs actively target and recruit cybersecurity professionals. The financial incentives (cryptocurrency payments, profit-sharing arrangements) are sufficient to corrupt individuals with legitimate employment.
### Industry-Wide Exposure
With BlackCat alone having targeted over 1,000 organizations before its disruption, it is reasonable to assume that at least some portion of those attacks benefited from insider intelligence. The Martino-Martin-Goldberg network, if it represents 10-20% of insider compromises in the ransomware ecosystem, suggests hundreds of additional organizations may have faced extortion where negotiation strategies were already known to attackers.
---
## Legal and Sentencing Outcomes
Martino pleaded guilty in April 2026, acknowledging his cooperation with BlackCat. His 70-month sentence is notably longer than those of Martin and Goldberg (48 months each), suggesting either:
Restitution Determination: The court has scheduled a separate hearing in September 2026 to determine the amount Martino must pay in restitution to victims. Given the estimated impact of BlackCat operations and the direct connection between Martino's information and victim losses, this figure could reach into the millions.
---
## HackWire Analysis
This case signals a fundamental shift in how ransomware gangs operate: they've moved beyond technical exploitation to systematic compromises of the humans who defend against them. The Martino-Martin-Goldberg prosecutions aren't anomalies—they represent a proven, scalable model for maximizing ransom extraction by eliminating the negotiation process entirely.
Why now matters: The three prosecutions cluster in 2026, suggesting federal investigators identified and rolled up this network over the past 18-24 months. However, BlackCat operations continued through December 2023, meaning these insider compromises persisted for 7-8 months before resolution. Organizations that negotiated with BlackCat during April-December 2023 should assume their internal financial data, strategic resistance thresholds, and negotiation limits were known to attackers in advance.
The pattern extends beyond BlackCat. Ransomware operators have systematized insider recruitment as a revenue optimization tactic. If security professionals can be flipped at scale, the entire cybersecurity industry's operational model—which depends on negotiators, incident responders, and forensic specialists having trusted access to sensitive victim data—becomes a liability rather than an asset.
For defenders: Organizations should assume that any large ransomware negotiation involving external cybersecurity firms may be compromised at the negotiation layer. Segregation of negotiation strategy from operational details, real-time monitoring of external access to financial and strategic information, and insider threat programs specifically designed for security staff are no longer optional. The cost of assuming negotiators are trustworthy is now measured in tens of millions in inflated ransoms and extended extortion demands.
— HackWire Editorial
---
## Recommendations
For Victim Organizations:
For Cybersecurity Firms:
For Law Enforcement:
For Industry Regulators:
---
## Related Coverage