Double Agent: Florida Ransomware Negotiator Sentenced to 70 Months for BlackCat/ALPHV Attacks

Share
A deceptive handshake between a human hand and a purple cyber claw on a slate blue background.

A third cybersecurity "expert" has been sentenced to 70 months in federal prison for operating as an inside man for one of the world's most prolific ransomware cartels, using his position to facilitate extortions instead of preventing them.

Angelo Martino, 41, of Land O'Lakes, Florida, a professional ransomware negotiator at Chicago-based DigitalMint, has been sentenced to 70 months in federal prison. The case was charged and sentenced in the U.S. District Court for the Southern District of Florida, which prosecuted Martino even though Land O'Lakes sits in the Tampa area. He pleaded guilty in April 2026 to conspiring to commit extortion, admitting he had acted as a "double agent" for the notorious BlackCat (ALPHV) ransomware-as-a-service (RaaS) group, making him the third cybersecurity professional to fall in a sprawling federal investigation into Western collaborators aiding the Russian-linked gang.

Update (August 26, 2026): The sentence was imposed on July 9, 2026: 70 months — five years and 10 months — in federal prison. A restitution hearing is set for September 17, 2026. Ryan Goldberg and Kevin Martin, the two other cybersecurity professionals who pleaded guilty in December 2025, were each sentenced to 48 months at the end of April 2026.

The case has sent shockwaves through the incident response (IR) community, exposing a dark reality where the individuals hired to mitigate cyberattacks are sometimes the ones ensuring their success.

The Triple-Threat: U.S. Collaborators Plead Guilty

Defendant Primary Charge & Role
Angelo Martino Conspiracy to Extort: Ransomware negotiator at DigitalMint who funneled victim insurance data to BlackCat.
Kevin Martin Conspiracy to Extort: Ransomware negotiator at DigitalMint; pleaded guilty December 2025.
Ryan Goldberg Computer Fraud: Incident response manager at Sygnia who used his position to deploy BlackCat payloads on client hosts.

The "Inside Out" Extortion Strategy

Martino’s role was uniquely insidious. Working as a third-party negotiator for victimized companies, he was tasked with lowering ransom demands. Instead, according to court documents and The Register, Martino used his "behind-the-scenes" access to victim networks to feed sensitive information back to the BlackCat operators.

By revealing a victim's insurance limits, financial liquidity, and critical data locations to the hackers, Martino ensured that BlackCat could maintain maximum pressure. In several instances, he allegedly coached the attackers on how to respond to his own "negotiation" tactics to justify a higher final payout — of which he took a significant commission.

A Pattern of Professional Betrayal

Martino is not an isolated case. His plea follows those of two other U.S.-based cybersecurity professionals — Ryan Goldberg, of Georgia, an incident response manager at Sygnia Cybersecurity Services, and Kevin Martin, 36, of Texas, a ransomware negotiator at DigitalMint — who both pleaded guilty in December 2025 in the Southern District of Florida.

  • Access Brokerage: The trio admitted to helping identify high-value U.S. targets in the healthcare and critical infrastructure sectors.
  • Credential Sharing: In some cases, the "professionals" used their authorized access to install backdoors that the ransomware gang would later use to deploy encryption payloads.
  • Financial Laundering: The Justice Department says law enforcement has seized $10 million in assets from Martino to date — digital currency, vehicles, a food truck and a luxury fishing boat.

The CyberSignal Analysis

Signal 01 — The Professional "Vetting" Crisis

This incident is a definitive "Signal" for third-party risk. If your incident response firm is compromised, your entire recovery strategy is a liability. For B2B leaders, this case highlights a desperate need for negotiator vetting. It is no longer enough to hire a firm based on a brochure; you must require transparency regarding their internal audits and background checks. This is the ultimate "Shadow Supply Chain" risk — where the risk is the human in the loop.

Signal 02 — The Identity of the "Insider" has Changed

This is a critical "Signal" for Threat Actors. Traditionally, "insider threats" were disgruntled employees. In 2026, the "insider" is a third-party contractor with high-level permissions. This case reinforces the necessity of zero trust security — specifically the principle of "Trust but Verify" for external IR teams. Even the people saving your network must be monitored by automated audit logs that they cannot delete or modify.


Sources

Type Source
Official Dept DOJ: Florida Negotiator Pleads Guilty
Technical News BleepingComputer: Former Negotiator Guilty
Industry Alert SecurityWeek: Third Expert Admits Aiding Gang
Incident Context The Record: BlackCat Incident Responder Indicted
Official Dept DOJ: Florida Ransomware Negotiator Sentenced to Prison
Official Dept DOJ: Two Americans Who Attacked U.S. Victims Using ALPHV/BlackCat Sentenced