Angelo Martino, a 41-year-old ransomware negotiator from Land O’Lakes, Florida, has been convicted of secretly aiding BlackCat ransomware attackers while representing their victims in ransom negotiations. Rather than protecting his clients’ interests, Martino acted as a double agent—passing confidential negotiation strategies, insurance policy limits, and internal negotiating positions directly to the attackers to help them maximize their ransom demands. This betrayal allowed BlackCat to extract over $75 million from four companies and one nonprofit organization that had trusted Martino to defend them against extortion.
Martino’s case represents a profound breach of trust in an already vulnerable part of the cyber threat landscape. His guilty plea in April 2026 and subsequent 70-month federal prison sentence expose how ransomware gangs can exploit the very professionals hired to combat their schemes. The scheme operated between April 2023 and November 2023, during which Martino funneled critical intelligence to attackers while simultaneously billing victims for his supposed advocacy on their behalf.
Table of Contents
- How Did a Ransomware Negotiator Become a Criminal Collaborator?
- The Scale of Martino’s Damage to Victims
- What Specific Information Did Martino Provide to BlackCat?
- How Was Martino Discovered and Prosecuted?
- Sentencing, Asset Seizure, and Co-Conspirator Involvement
- The Vulnerability This Exposes in Ransomware Negotiations
- Martino as the Third Security Expert Imprisoned for Aiding Ransomware Gangs
How Did a Ransomware Negotiator Become a Criminal Collaborator?
Martino’s shift from negotiator to co-conspirator appears to have been motivated by financial incentives from the attackers. Federal prosecutors characterized him as a “double agent working to maximize the harm to his clients and the financial gain to cybercriminals who paid him a part of the ransom.” Rather than advising victims to hold firm on ransom amounts or challenging attackers’ demands, Martino used his professional access to provide BlackCat with information that allowed them to craft more effective extortion tactics. The betrayal was systematic and calculated.
When negotiating with BlackCat on behalf of his clients, Martino had access to sensitive information about each victim’s financial constraints, insurance coverage, and negotiating red lines. Instead of keeping this information confidential, he transmitted it to the attackers he was supposedly negotiating against. This created an asymmetrical negotiation environment where BlackCat knew exactly how much each victim could pay before giving up, while the victims believed they had an advocate working in their corner.
The Scale of Martino’s Damage to Victims
The financial scope of Martino’s crimes demonstrates the severity of his betrayal. Over $75 million was extorted from his clients—four companies and one nonprofit organization—across attacks he facilitated. This figure reflects not just ransomware payments but the compounded damage of extortionate demands that were calibrated using confidential information only Martino possessed. Victims who might have negotiated attackers down to 30% or 50% of initial demands instead faced adversaries who knew their exact breaking points.
The nonprofit organization included in this figure represents an especially egregious aspect of the scheme. Charities and nonprofits typically have limited budgets and fewer resources than corporations to absorb ransom payments. By providing BlackCat with negotiation intelligence against these organizations, Martino directly contributed to diverting funds from charitable work to criminal enterprises. The impact extended beyond the direct victims to the communities these organizations serve.
What Specific Information Did Martino Provide to BlackCat?
Court documents and reporting reveal the granular nature of Martino’s intelligence sharing. He provided BlackCat with his clients’ negotiation strategies—the approaches, opening positions, and tactical sequences victims planned to use when communicating with attackers. He disclosed insurance policy limits, allowing BlackCat to understand exactly how much insurance would cover and therefore how high they could push demands before victims would refuse to pay. Most critically, he shared internal negotiating positions, essentially giving the attackers a real-time view of victims’ decision-making processes and financial thresholds.
This type of intelligence represents the most valuable information a negotiator could provide to attackers. Ransomware negotiations are inherently asymmetrical—attackers have leverage through encrypted data and operational knowledge, but they often lack precise understanding of a victim’s actual financial capacity. By closing this information gap for BlackCat, Martino transformed the negotiation dynamic from one where victims had some leverage through uncertainty into one where attackers could apply precise pressure to extract maximum payments. The attackers didn’t need to guess or make educated estimates; they had insider confirmation of victim capabilities and constraints.
How Was Martino Discovered and Prosecuted?
The investigation into Martino’s activities led to his guilty plea in April 2026, when he admitted to conspiring to interfere with interstate commerce through extortion. The evidence linking Martino to BlackCat’s scheme was apparently substantial enough to make continued denial impractical.
His guilty plea to a conspiracy charge indicates federal prosecutors had documented communications, financial records, or informant testimony establishing his direct coordination with BlackCat leadership. The prosecution’s case extended beyond Martino to include co-conspirators Ryan Goldberg and Kevin Martin, both of whom were sentenced to four years in federal prison in May 2026 for their roles in the BlackCat attacks. The fact that multiple individuals were coordinating these activities suggests this was not a solo criminal venture but rather an organized operation with distinct roles—attackers, negotiators, and intelligence providers working in concert.
Sentencing, Asset Seizure, and Co-Conspirator Involvement
Martino received a 70-month federal prison sentence—five years and ten months—reflecting the severity of his betrayal and the scale of financial harm. Beyond incarceration, federal authorities seized approximately $20 million in assets directly tied to Martino’s criminal proceeds. This included $10 million in Florida real estate properties, along with $10 million in other seized assets including vehicles, a luxury fishing boat, a food truck, and cryptocurrency holdings.
The asset seizure demonstrates that Martino profited substantially from his role in the extortion scheme, accumulating wealth through ransom payments BlackCat distributed to him. His co-conspirators’ four-year sentences, imposed two months before Martino’s sentencing, may have influenced prosecutorial recommendations in his case. The staggered sentencing also allowed federal authorities to build additional evidence from earlier convictions before proceeding to trial or guilty plea with Martino. The involvement of multiple perpetrators across different roles—attackers, negotiators, and intelligence operatives—reflects how modern ransomware operations have professionalized into specialized criminal networks rather than small-scale hacking operations.
The Vulnerability This Exposes in Ransomware Negotiations
Martino’s case reveals a critical vulnerability in how organizations approach ransomware response: the trustworthiness of third-party negotiators. Many ransomware consultants operate in gray markets with minimal oversight, background checking, or accountability mechanisms. Organizations under attack often engage negotiators quickly, under pressure, without conducting thorough due diligence.
Martino had apparently built enough credibility to be hired repeatedly by victims, yet he was simultaneously working against their interests. The existence of insider threats within the negotiation industry also raises questions about how victims can verify that their negotiators are actually advocating for them. Without direct observation of negotiations or communication audits, victims have limited visibility into what information is being shared and with whom. Organizations relying on external negotiators may not realize they are exposing sensitive business intelligence about insurance coverage, financial reserves, and decision-making processes—precisely the information that helps attackers optimize their extortion tactics.
Martino as the Third Security Expert Imprisoned for Aiding Ransomware Gangs
Martino’s conviction marks the third instance of a U.S. security expert being sentenced to federal prison for helping ransomware gangs. This pattern suggests the problem extends beyond isolated bad actors to represent a structural vulnerability in how ransomware operations recruit insiders. Security professionals possess exactly the knowledge, access, and credibility that makes them valuable to ransomware operations.
They understand victim networks, negotiation processes, and insurance frameworks. They can be approached by attackers with financial incentives and used to magnify the effectiveness of attacks that might otherwise be less profitable. The recurrence of these cases indicates that federal law enforcement is identifying and prosecuting these insider threats, but it also suggests that the initial incidents may not have deterred other security professionals from considering similar arrangements. Each conviction demonstrates that such activity is prosecutable and carries substantial prison time, yet the pattern continues. This suggests that either financial incentives from ransomware gangs remain compelling to some security professionals, or recruitment into these schemes occurs before individuals understand the legal consequences of their actions.
