> ## Content Index
> Fetch the complete content index at: https://www.thecybersignal.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Double Agent: Florida Ransomware Negotiator Sentenced to 70 Months for BlackCat/ALPHV Attacks
- URL: https://www.thecybersignal.com/double-agent-florida-ransomware-negotiator-pleads-guilty-to-aiding-blackcat-alphv-attacks/
- Published: 2026-04-21T12:22:00.000Z
- Updated: 2026-08-27T21:52:20.000Z
- Author: Nicholas Robert
- Tags: Fraud, Threat Actors, Third Party Risk, United States, Trending

*A third cybersecurity "expert" has been sentenced to 70 months in federal prison for operating as an inside man for one of the world's most prolific ransomware cartels, using his position to facilitate extortions instead of preventing them.*

**Angelo Martino**, 41, of Land O'Lakes, Florida, a [professional ransomware negotiator](https://www.thecybersignal.com/the-new-hostage-negotiator-why-cybersecuritys-fastest-growing-role-has-nothing-to-do-with-firewalls/) at Chicago-based DigitalMint, has been sentenced to 70 months in federal prison. The case was charged and sentenced in the U.S. District Court for the Southern District of Florida, which prosecuted Martino even though Land O'Lakes sits in the Tampa area. He pleaded guilty in April 2026 to conspiring to commit extortion, admitting he had acted as a "double agent" for the notorious **BlackCat (ALPHV)** ransomware-as-a-service (RaaS) group, making him the third cybersecurity professional to fall in a sprawling federal investigation into Western collaborators aiding the Russian-linked gang.

**Update (August 26, 2026):** The sentence was imposed on July 9, 2026: 70 months — five years and 10 months — in federal prison. A restitution hearing is set for September 17, 2026\. Ryan Goldberg and Kevin Martin, the two other cybersecurity professionals who pleaded guilty in December 2025, were each sentenced to 48 months at the end of April 2026.

The case has sent shockwaves through the incident response (IR) community, exposing a dark reality where the individuals hired to mitigate cyberattacks are sometimes the ones ensuring their success.

### The Triple-Threat: U.S. Collaborators Plead Guilty

| Defendant      | Primary Charge & Role                                                                                                      |
| -------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Angelo Martino | **Conspiracy to Extort:** Ransomware negotiator at DigitalMint who funneled victim insurance data to BlackCat.             |
| Kevin Martin   | **Conspiracy to Extort:** Ransomware negotiator at DigitalMint; pleaded guilty December 2025.                              |
| Ryan Goldberg  | **Computer Fraud:** Incident response manager at Sygnia who used his position to deploy BlackCat payloads on client hosts. |

---

## The "Inside Out" Extortion Strategy

Martino’s role was uniquely insidious. Working as a third-party negotiator for victimized companies, he was tasked with lowering ransom demands. Instead, according to court documents and *The Register*, Martino used his "behind-the-scenes" access to victim networks to feed sensitive information back to the BlackCat operators.

By revealing a victim's insurance limits, financial liquidity, and critical data locations to the hackers, Martino ensured that BlackCat could maintain maximum pressure. In several instances, he allegedly coached the attackers on how to respond to his own "negotiation" tactics to justify a higher final payout — of which he took a significant commission.

## A Pattern of Professional Betrayal

Martino is not an isolated case. His plea follows those of two other U.S.-based cybersecurity professionals — **Ryan Goldberg**, of Georgia, an incident response manager at Sygnia Cybersecurity Services, and **Kevin Martin**, 36, of Texas, a ransomware negotiator at DigitalMint — who both pleaded guilty in December 2025 in the Southern District of Florida.

- **Access Brokerage:** The trio admitted to helping identify high-value U.S. targets in the healthcare and critical infrastructure sectors.
- **Credential Sharing:** In some cases, the "professionals" used their authorized access to install backdoors that the ransomware gang would later use to deploy encryption payloads.
- **Financial Laundering:** The Justice Department says law enforcement has seized **$10 million** in assets from Martino to date — digital currency, vehicles, a food truck and a luxury fishing boat.

---

## The CyberSignal Analysis

### Signal 01 — The Professional "Vetting" Crisis

This incident is a definitive "Signal" for [third-party risk](https://www.thecybersignal.com/tag/third-party-risk/). If your incident response firm is compromised, your entire recovery strategy is a liability. For B2B leaders, this case highlights a desperate need for **negotiator vetting**. It is no longer enough to hire a firm based on a brochure; you must require transparency regarding their internal audits and background checks. This is the ultimate "Shadow Supply Chain" risk — where the risk is the human in the loop.

### Signal 02 — The Identity of the "Insider" has Changed

This is a critical "Signal" for **Threat Actors**. Traditionally, "insider threats" were disgruntled employees. In 2026, the "insider" is a third-party contractor with high-level permissions. This case reinforces the necessity of [zero trust security](https://www.thecybersignal.com/what-is-zero-trust-security/)— specifically the principle of "Trust but Verify" for external IR teams. Even the people saving your network must be monitored by automated audit logs that they cannot delete or modify.

---

## Sources

| Type             | Source                                                                                                                                                                                                                        |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Official Dept    | [DOJ: Florida Negotiator Pleads Guilty](https://www.justice.gov/opa/pr/florida-man-working-ransomware-negotiator-pleads-guilty-conspiracy-deploy-ransomware-and?ref=thecybersignal.com)                                       |
| Technical News   | [BleepingComputer: Former Negotiator Guilty](https://www.bleepingcomputer.com/news/security/former-ransomware-negotiator-pleads-guilty-to-blackcat-attacks/?ref=thecybersignal.com)                                           |
| Industry Alert   | [SecurityWeek: Third Expert Admits Aiding Gang](https://www.securityweek.com/third-us-security-expert-admits-helping-ransomware-gang/?ref=thecybersignal.com)                                                                 |
| Incident Context | [The Record: BlackCat Incident Responder Indicted](https://therecord.media/ransomware-blackcat-doj-incident-responder?ref=thecybersignal.com)                                                                                 |
| Official Dept    | [DOJ: Florida Ransomware Negotiator Sentenced to Prison](https://www.justice.gov/opa/pr/florida-ransomware-negotiator-who-extorted-and-attacked-multiple-us-victims-sentenced-prison?ref=thecybersignal.com)                  |
| Official Dept    | [DOJ: Two Americans Who Attacked U.S. Victims Using ALPHV/BlackCat Sentenced](https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced?ref=thecybersignal.com) |