A federal judge sentenced Angelo Martino, a 41-year-old former ransomware negotiator at Chicago-based DigitalMint, to nearly 6 years in prison for a stunning betrayal: while hired to negotiate ransom payments on behalf of victims, Martino secretly provided BlackCat ransomware attackers with confidential negotiating strategies and sensitive victim information to help them maximize their demands. Sentenced on July 10, 2026, Martino pleaded guilty to the charges in April 2026 after orchestrating a scheme that extracted over $75 million in ransom payments from five victims spanning the hospitality, retail, medical services, and financial sectors. His co-conspirators, Kevin Martin and Ryan Goldberg, each received 4-year prison sentences in May 2026 after pleading guilty in December 2025.
The case represents one of the most egregious betrayals of trust in the cybersecurity industry—a hired professional whose job was to protect victims instead weaponizing his position to aid criminals. Federal authorities seized approximately $20 million in assets from Martino, including $10 million in Florida properties and $10 million in other holdings including vehicles, a luxury fishing boat, a food truck, and cryptocurrency. The prosecution revealed how a single insider with access to sensitive negotiations could exponentially increase the damage inflicted by ransomware gangs, turning a position of trust into a criminal advantage.
Table of Contents
- How Did a Ransomware Negotiator Become a Criminal Conspirator?
- The Inside Information That Made Extortion More Efficient
- The BlackCat Partnership and Coordinated Extortion
- How Ransomware Victims Face Compounded Risks Through Insider Betrayal
- The Financial Scale and Asset Seizure Operation
- Co-Conspirators and the Organized Nature of the Crime
- What the Martino Case Reveals About Insider Threats in Cybersecurity
How Did a Ransomware Negotiator Become a Criminal Conspirator?
Martino’s role at DigitalMint was supposed to be defensive: when companies and nonprofits were hit with ransomware attacks, his job was to negotiate ransom payments at the lowest possible price, protecting organizations from paying inflated demands. Instead, Martino inverted this role entirely. By providing BlackCat attackers with the confidential strategies he was using on behalf of victims—and by sharing sensitive information about the targets themselves—Martino essentially switched sides mid-negotiation. This was not passive wrongdoing; it was active collaboration designed to sabotage his own clients while enriching the criminals he was supposed to be working against.
The mechanics of the scheme relied on information asymmetry. During ransom negotiations, Martino would learn critical details: the victim’s financial capacity, their timeline pressures, their willingness to pay certain amounts, their defensive capabilities, and their decision-making processes. He also knew which organizations were most vulnerable and which had already paid ransom to BlackCat or other gangs. By funneling this intelligence to BlackCat operators, Martino transformed them from guessing attackers into precision extortionists who could demand exactly what each victim could bear. This fundamentally altered the negotiation dynamic, shifting power entirely to the criminals and making it nearly impossible for victims to meaningfully bargain down their ransoms.
The Inside Information That Made Extortion More Efficient
The scheme operated with a cold efficiency. When a victim organization was breached and Martino was brought in to negotiate, he served dual purposes. On the surface, he appeared to be advocating for the victim’s interests, but simultaneously he was feeding the attackers detailed intelligence about how much the victim would likely pay, what arguments might persuade them, and what their actual tolerance for ransom was. In some cases, this inside information allowed BlackCat operators to refine their extortion tactics mid-negotiation, adjusting their demands based on precise knowledge of the victim’s financial and operational constraints.
This arrangement was particularly damaging because Martino held what the security industry calls “negotiator privilege”—access to highly sensitive financial and operational details that only a trusted advisor would see. Victims disclosed information to Martino about their cash positions, their insurance coverage, their board-level tolerance for paying ransom, and their competitive vulnerabilities, all under the assumption that this information would be used to protect them. Instead, it was weaponized against them. The five victims targeted by this conspiracy ranged from small nonprofits to mid-sized companies, meaning the $75 million total extracted represented a catastrophic financial blow to organizations that could least afford it.
The BlackCat Partnership and Coordinated Extortion
BlackCat, also known as ALPHV, is a professionally-run ransomware operation known for sophisticated targeting and high-value extortion demands. The partnership between Martino and BlackCat operators reflected a level of deliberation and organization that distinguishes this case from opportunistic criminal activity. This was planned collaboration: Martino was not coerced or blackmailed into helping; he chose to provide intelligence in exchange for financial benefit. The arrangement allowed BlackCat to shift from general extortion to targeted, personalized ransomware attacks—hitting specific organizations and crafting demands calibrated to what negotiation data suggested they would pay.
The scope of the conspiracy extended across multiple victims and multiple months, indicating sustained coordination rather than a single bad decision. Federal prosecutors documented that Martino, Martin, and Goldberg worked together to execute the scheme, with each conspirator playing defined roles in the extortion pipeline. The timeline from Martino’s guilty plea in April 2026 to his sentencing in July 2026 was relatively compressed, suggesting that the evidence against him was substantial and the case was straightforward. Martino’s cooperation with prosecutors during sentencing (if any occurred) might have been limited, as federal judges typically recognize guilty pleas and cooperation in their sentencing decisions, and his 70-month sentence reflects a serious penalty even with potential cooperation credit.
How Ransomware Victims Face Compounded Risks Through Insider Betrayal
Organizations hiring ransomware negotiators already operate from a position of weakness—they have been breached, their data has been stolen or encrypted, and they face either paying substantial money or enduring operational paralysis. What Martino’s case demonstrates is that this weakness is compounded when the hired professional becomes part of the attack. Victims cannot effectively negotiate against an adversary who knows their bottom line, their alternatives, their financial capacity, and their operational timeline. It is like entering a poker game where the other player has been shown your hole cards before the hand begins.
For companies considering whether to hire a ransomware negotiator, this case presents a fundamental problem: vetting. How do you determine whether a negotiator is trustworthy? Martino’s employment at an established Chicago cybersecurity firm provided superficial credibility, but his willingness to betray clients suggests that credentials and corporate affiliations alone are insufficient. Organizations must now consider whether they should split negotiations across multiple advisors to prevent any single negotiator from accumulating comprehensive knowledge, or whether they should negotiate directly without third-party intermediaries. Each approach carries tradeoffs: multiple advisors increase complexity and cost but reduce single-point-of-failure risk, while direct negotiation avoids the insider problem but requires organizational expertise the company may not possess.
The Financial Scale and Asset Seizure Operation
The $75 million extracted from five victims over the course of the conspiracy represents the volume of damage that can be inflicted when insider access meets organized ransomware operations. Federal authorities calculated that across a nonprofit organization and four companies spanning different industries, Martino and his conspirators orchestrated ransom demands that totaled approximately $75 million in actual payments. This was not speculative damage; these were ransom payments actually made by victimized organizations to recover from attacks or restore data. The nonprofit victim is particularly notable, as nonprofits typically operate on constrained budgets and cannot easily absorb massive extortion payments without cutting core programs.
The federal asset seizure of approximately $20 million provides a window into the proceeds Martino accumulated. The $10 million in Florida properties and $10 million in additional assets (vehicles, a luxury fishing boat, a food truck, and cryptocurrency) paint a picture of conspicuous spending inconsistent with a legitimate negotiator salary. This visible wealth accumulation—luxury boats and multiple properties—likely contributed to investigative leads, as federal authorities often track suspicious financial activity, unexplained wealth, and sudden asset acquisitions. However, $20 million seized from an estimated $75 million in victim ransoms suggests that $55 million in proceeds remains unaccounted for, either hidden in accounts not yet recovered, distributed to co-conspirators, or already spent or converted into assets law enforcement has not yet identified.
Co-Conspirators and the Organized Nature of the Crime
Kevin Martin and Ryan Goldberg were not minor participants; their equal 4-year sentences alongside Martino’s 70-month term indicate they held substantial roles in the conspiracy. Both pleaded guilty in December 2025, several months before Martino’s April 2026 guilty plea. The sequencing of guilty pleas often reflects prosecutorial strategy, with earlier pleas sometimes indicating cooperation agreements or guilty pleas by lower-level participants before charges against the primary defendant proceed.
Martino’s later guilty plea and longer sentence suggest he may have been the central organizer or the negotiator with direct access to victim information, while Martin and Goldberg supported the scheme. The parallel sentencing dates for Martin and Goldberg in May 2026, followed by Martino’s sentencing in July 2026, create a temporal pattern that suggests coordinated federal prosecution across multiple defendants. Federal judges typically sentence co-conspirators around the same period to reinforce consistent sentencing philosophy across cases. The conspiracy’s organized nature—coordinated intelligence sharing, defined roles, and direct communication with a ransomware gang—elevates this from individual wrongdoing to an organized criminal enterprise.
What the Martino Case Reveals About Insider Threats in Cybersecurity
The prosecution of Angelo Martino and his co-conspirators is the kind of case that should serve as a wake-up call for the entire ransomware negotiation industry, but often does not. Insider threats in cybersecurity have historically focused on IT administrators selling access, security researchers sharing vulnerabilities, or former employees retaliating against their companies. The idea that a professional hired specifically to *defend* against extortion would become an active participant in extortion is a category inversion that many organizations have not adequately prepared for. Vetting negotiators for criminal intent before and during an engagement remains difficult; background checks catch criminal history but not future criminal intent. Organizations cannot reasonably demand that negotiators undergo lie detector tests or financial forensics, yet those are the instruments that might have flagged Martino’s undisclosed arrangements with criminal gangs.
The five organizations victimized in this conspiracy—ranging from hospitality to medical services to financial sectors—were already in crisis when they hired Martino’s services. Federal investigators recovered evidence of the conspiracy, built cases against three conspirators, secured guilty pleas, and imposed substantial prison sentences totaling approximately 18.3 years combined. However, the victims themselves bore the permanent loss of the $75 million in ransom payments. Federal asset seizure recovered a fraction of that amount, and none of the seized assets will be returned directly to the victims in the form of restitution; seized assets typically enter the federal crime victim fund or remain under government control. The Martino case demonstrates that insider betrayal in cybersecurity can operate at scale and remain hidden until federal investigations uncover coordinated communications or suspicious financial activity.
