SYS::ONLINE
Wasteland.
Briefs2284
Issues25
SinceFeb 2026
LIVE
█ Ransomware RANSOMWARE-NEGOTIA 2026-08-27

DigitalMint Clients: BlackCat Insider Extortion Conspiracy

"A former ransomware negotiator at Chicago incident response firm DigitalMint has been sentenced to 70 months in federal prison for secretly feeding his own clients' negotiating positions and cyber insurance limits to…"

A former ransomware negotiator at Chicago incident response firm DigitalMint has been sentenced to 70 months in federal prison for secretly feeding his own clients' negotiating positions and cyber insurance limits to the BlackCat/ALPHV ransomware group in exchange for a cut of the ransoms. Angelo John Martino III, 41, of Land O'Lakes, Florida, pleaded guilty on April 14, 2026 to a one-count information charging conspiracy to interfere with interstate commerce by extortion. Five organizations he was retained to represent paid a combined total reported as "more than $75 million" (Malwarebytes) and $75.3 million (HaystackID/JDSupra, citing CyberScoop's review of court records). Investigators have seized more than $10 million in cryptocurrency and assets traced to Martino personally. A caveat on sourcing: no victim organization, regulator filing, or national CERT advisory is among the available material. Every account below traces back to Justice Department statements, the signed factual proffer, and court records as reported by security press, and the reporting is not uniform.

What Happened

Beginning in April 2023, Martino used his seat at DigitalMint to run two negotiations simultaneously. In the official BlackCat negotiation chat, visible to his employer and the client, he played the role of the hard-bargaining intermediary arguing his client could not meet the demand. In a separate intermediary channel his employer could not see, described by Bitdefender as a hidden tab inside the same BlackCat negotiation panel he used for legitimate work, he told the attackers exactly what the victim and its insurer would actually pay.

Prosecutors described him in a sentencing memorandum, quoted by CyberScoop, as a "double agent working to maximize the harm to his clients and the financial gain to cybercriminals who paid him a part of the ransom," adding that "this was not a crime of opportunity or momentary weakness; it was a sustained abuse of a fiduciary-like relationship driven by a single purpose: greed."

The proffer language is blunt. DataBreach.com quotes Martino telling a BlackCat actor: "Keep denying our offers and I will let you know once I find out the max they want to pay." Bitdefender reports the operator side of the same dynamic surfacing in the client-facing chat: "We know how much you can pay. Contact your insurance. We know about them also." Malwarebytes reports a case where Martino told DigitalMint he was relaying a client's offer while privately informing the gang the client would go $2 million higher. The client paid the extra $2 million.

The scheme did not stop at intelligence leaking. In May 2023, Martino signed on as a BlackCat affiliate himself and, with two other cybersecurity professionals, deployed ransomware against additional US organizations between April and November 2023. His co-conspirators were Kevin Martin, 36, of Texas, hired as Martino's DigitalMint coworker after the conspiracy began, and Ryan Goldberg, 41, of Georgia, an incident response manager at Sygnia Cybersecurity Services. One of those attacks netted roughly $1.2 million in Bitcoin, which the three split and laundered through cryptocurrency transactions designed to obscure its origin.

What Was Taken

The stolen asset in the core scheme was not data. It was the victim's hand: cyber insurance policy limits, board-level internal assessments, negotiating floors and ceilings, and real-time financial circumstances. This is precisely the material a victim has no choice but to disclose to a negotiator, and precisely the material that determines the price of an extortion.

The financial toll is reported with some variation. Malwarebytes puts the five ransoms in a range from $213,000 to $26.8 million paid between April and September 2023, totaling more than $75 million, with victims identified as a hospitality company, a nonprofit, a financial services company, a retail company, and a medical company. HaystackID, citing CyberScoop's review of court records, gives a per-victim breakdown reaching $75.3 million: a nonprofit at nearly $26.8 million, a financial services company at nearly $25.7 million, a hospitality company at almost $16.5 million, and the remaining two victims at $6.1 million and $213,000.

The separate affiliate attacks produced the roughly $1.2 million Bitcoin ransom split three ways. Readers should note that viagradix.com, the weakest source in this set, describes that $1.2 million as having been paid by "a medical device company"; no other source attributes that figure to a named victim sector, and the Justice Department framing in Help Net Security and ISSSource treats it as proceeds from the affiliate conspiracy rather than from one of the five negotiation victims. Treat that detail as unconfirmed.

Forfeited property linked to Martino exceeds $10 million and includes cryptocurrency, luxury vehicles, a fishing boat, and a food truck. DataBreach.com additionally lists houses among the seized assets. Prosecutors have been explicit that the $10 million represents traced criminal proceeds, not the total victim loss.

Accounts Differ

Two points in the record do not line up cleanly.

The sentencing date is reported inconsistently. ISSSource, DataBreach.com, and HaystackID all place it on Thursday, July 9, 2026, in federal court in Miami. Malwarebytes reports July 3. Three independent accounts against one favors July 9, but the discrepancy is worth noting rather than papering over.

Titles attached to DOJ quotes also vary. ISSSource attributes its statement to "Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division," while Help Net Security quotes US Attorney Jason A. Reding Quiñones for the Southern District of Florida. Both quotes are reported as official; the attribution of role should be verified against the DOJ release before reuse.

Sentence length framing differs cosmetically as well: ISSSource headlines "5 years" against a 70-month term, which is just over five years and eight months. The underlying number, 70 months, is consistent across all sources, along with three years of supervised release and a restitution hearing set for September 17.

Why It Matters

Ransomware defense has spent a decade hardening the perimeter, the endpoint, and the backup. This case attacks a layer nobody instrumented: the trusted advisor retained during the worst week of an organization's life. Galactic Advisors frames the negotiator as the person who "ends up holding the most in that room," the one to whom a terrified leadership team hands its real financial ceiling, its insurance coverage, its hourly bleed rate, and the true state of its backups. That disclosure is not optional. It is the job.

Three of the people charged worked in the cybersecurity industry, two of them at the same incident response firm and one at a different one. That is not a rogue-employee story; it is a demonstration that adversary recruitment now reaches into the responder bench. FBI Cyber Division assistant director Brett Leatherman's summary, reported by viagradix.com, is that Martino "sold out" the people he was hired to protect. ISSSource quotes DOJ describing "heartbreaking accounts of how their businesses were nearly destroyed."

The practical consequence for defenders: the negotiation table is now an attack surface with a documented exploitation history, and the compromise leaves almost no technical artifact. Nothing in the victims' telemetry would have shown a negotiator opening a second chat tab.

The Attack Technique

There is no intrusion vector to report on the insider side, because there was no intrusion. The technique was authorized access abused end to end.

The mechanics, as described across Malwarebytes, Bitdefender, and DataBreach.com, break down as follows. Martino held legitimate credentials to BlackCat's victim negotiation portal as part of his day job. Within that same portal he operated an intermediary or hidden channel invisible to DigitalMint and to the client, giving him an out-of-band path to the threat actor that never left his employer's monitored workflow. He then arbitraged the information asymmetry, presenting one posture in the supervised chat and selling the true reserve price in the private one. Payment came as a share of the resulting ransom, laundered through cryptocurrency.

The escalation phase used conventional BlackCat affiliate tradecraft: Martino joined the affiliate program in May 2023 and, with Martin and Goldberg, deployed the ransomware directly against additional US targets through November 2023. Detection of the insider conduct depended on the criminal investigation, not on any control at DigitalMint or its clients.

What Organizations Should Do

  1. Treat negotiation channels as monitored systems, not advisor workspaces. Require that all threat actor communications route through infrastructure the victim or its counsel can log and review, and treat any actor-controlled portal, including any sub-channel within it, as untrusted. The hidden tab in this case lived inside the attacker's own platform.

  2. Compartmentalize insurance limits and reserve pricing. The negotiator does not need the policy limit and the board's true ceiling as raw numbers on day one. Route those through breach counsel, disclose them in tranches tied to negotiation milestones, and log every disclosure. A leak of a staged number is worth less to the adversary than a leak of the whole hand.

  3. Demand dual control on the negotiation seat. No single individual should be the sole channel to the extortionist. Pair negotiators, or place counsel or an internal owner on every session, so that the supervised chat and the private chat cannot diverge unobserved. Martino's scheme required exactly one unwatched person.

  4. Vet the responder like a privileged insider, because they are one. Background screening, conflict-of-interest attestation, and contractual audit rights over communications should be table stakes in the retainer. Martin was hired into DigitalMint after the conspiracy was already underway.

  5. Watch for negotiation behavior that contradicts your position. An adversary who references your insurer, holds firm against every concession, or prices to a number suspiciously close to your undisclosed ceiling is a signal. The BlackCat operator line quoted by Bitdefender, telling a victim to contact its insurance and noting "we know about them also," was visible in the official chat.

  6. Preserve the full negotiation record and press for restitution. Retain complete transcripts, payment records, and advisor communications. The restitution hearing in this matter is scheduled for September 17, and forfeited assets exceeding $10 million are in play. Organizations that suspect advisor compromise in a 2023 BlackCat engagement should engage counsel and contact the FBI.

Sources: Ransomware Negotiator's Shocking Scam: Stealing $75 Million from Vi... | Ransomware negotiator who betrayed clients sentenced to ... | The inside job that cost ransomware victims millions | Ransomware negotiator stole at least $10M while selling ... | The ransomware negotiator who was working for the other ... | Negotiator Hired to Help Ransomware Victims Gets 5 Years - ISSSource | insider who betrayed ransomware victims gets 70 months | The Ransomware Negotiator Who Sold Out His Clients and Bought a Boa...