Ransomware Negotiator Angelo Martino Gets 70 Months for Helping BlackCat

Former ransomware negotiator Angelo Martino received 70 months in prison after secretly sharing clients' confidential information with BlackCat attackers and participating in additional ransomware attacks.

Oct 9, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A Florida ransomware negotiator who secretly helped the hackers targeting his own clients has been sentenced to 70 months in federal prison. Angelo Martino, 41, of Land O'Lakes, Florida, supplied confidential information to the BlackCat ransomware group, allowing attackers to increase their ransom demands against companies that had hired him for help.

The July 9, 2026, sentencing followed Martino's guilty plea to conspiring to interfere with interstate commerce through extortion. He also admitted working with two other cybersecurity professionals to launch ransomware attacks against additional US victims. Authorities have seized approximately $10 million in assets connected to his crimes.

According to the Justice Department's sentencing announcement, Martino began collaborating with BlackCat operators in April 2023 while employed at a US cyber incident-response company.

The case exposes a serious risk for organizations recovering from ransomware attacks: a trusted negotiator can have access to insurance limits, payment discussions, and sensitive recovery decisions that become valuable to the attackers if that trust is abused.

How Angelo Martino helped BlackCat extort ransomware victims

Martino worked as a ransomware negotiator for five victims while secretly cooperating with the BlackCat group, also known as ALPHV.

Instead of protecting his clients' negotiating positions, he disclosed their insurance policy limits and internal strategies to the attackers. The information helped BlackCat maximize ransom payments, and the group paid Martino for providing it.

The Justice Department's plea announcement confirms that his employer and clients were unaware of the arrangement.

Martino also conspired with Kevin Martin of Texas and Ryan Goldberg of Georgia, both former cybersecurity professionals, to deploy BlackCat ransomware against additional US organizations between April and November 2023.

Martin joined Martino's incident-response company after the conspiracy began, while Goldberg worked at a separate firm.

BlackCat operated as a ransomware-as-a-service group, providing malware and extortion infrastructure to affiliates who conducted attacks and shared proceeds with the operators.

In one attack, the three conspirators extorted approximately $1.2 million in Bitcoin from a victim. They divided their share of the ransom and laundered the proceeds through multiple channels.

Advertisement

The scheme demonstrates how insider access can compound the damage caused by ransomware. Victims were not simply negotiating with criminals; they were unknowingly sharing sensitive information with someone assisting those same attackers.

Similar insider risks have appeared in other security incidents, including a Coinbase data breach involving insiders who allegedly helped expose customer information.

Prison sentences, seized assets, and restitution

Martino pleaded guilty April 14 to one count of conspiracy to interfere with interstate commerce through extortion, an offense carrying a maximum sentence of 20 years.

US District Judge K. Michael Moore sentenced him to 70 months in prison on July 9.

His co-conspirators, Martin and Goldberg, each received 48-month prison sentences on May 1, according to the Justice Department.

Federal investigators also seized approximately $10 million in assets linked to Martino, including cryptocurrency, vehicles, a food truck, and a luxury fishing boat purchased or acquired through the scheme.

The government scheduled a restitution hearing for Sept. 17 to determine how much Martino would owe victims. No subsequent restitution amount has been confirmed in the publicly available DOJ announcements.

The investigation was led by the FBI's Miami Field Office, with assistance from the US Secret Service.

Martino's prosecution followed earlier federal efforts against BlackCat. In December 2023, the FBI disrupted the group's infrastructure, seized several websites, and released a decryption tool that helped hundreds of ransomware victims recover systems.

The Justice Department estimated that the tool prevented approximately $99 million in ransom payments.

The prosecution also demonstrates that criminal liability extends beyond the operators deploying ransomware. Individuals who knowingly facilitate extortion through privileged access can face substantial prison sentences and asset seizures.

How organizations can reduce ransomware negotiation risks

Martino's case raises concerns about the oversight of outside incident-response providers and the sensitive information shared during ransomware negotiations.

Organizations often engage external specialists during an attack because internal teams lack the expertise or capacity to manage negotiations, restoration, and legal obligations simultaneously.

Advertisement

Those specialists may need access to insurance information, business recovery priorities, and confidential communications. Compromising that trust can give attackers leverage that ordinary network access would not provide.

Security leaders should consider four safeguards when engaging external ransomware negotiators:

  1. Verify provider personnel. Confirm who will handle negotiations, review relevant qualifications, and establish clear responsibility for sensitive decisions.
  2. Limit access to confidential information. Share insurance limits, financial details, and internal negotiating strategies only when necessary for the engagement.
  3. Maintain independent oversight. Require documented approval for significant negotiation decisions, payment recommendations, and communications with attackers.
  4. Preserve negotiation records. Retain relevant communications and transaction documentation to support investigations, insurance claims, and potential legal proceedings.

These measures cannot eliminate insider threats, but they can reduce the opportunities for a single compromised individual to influence recovery decisions without detection.

Organizations should also consider broader insider-threat controls when granting external responders privileged access during security incidents. Network segmentation can further limit ransomware damage, with zero-trust ransomware testing demonstrating how restricting access between systems can help contain attacks.

BlackCat's ransomware operations have faced sustained law-enforcement disruption, but the Martino case illustrates a separate problem: criminals can exploit the trust placed in the people hired to negotiate with them.

For businesses facing ransomware, protecting negotiation information and maintaining independent oversight are essential parts of incident response.

Also read: Understanding how ransomware uses encryption can help security teams prepare recovery procedures before an attack forces difficult payment decisions.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.