Double Agent: Florida Ransomware Negotiator Sentenced to 70 Months for BlackCat/ALPHV Attacks
A third cybersecurity "expert" has been sentenced to 70 months in federal prison for operating as an inside man for one of the world's most prolific ransomware cartels, using his position to facilitate extortions instead of preventing them.
Angelo Martino, 41, of Land O'Lakes, Florida, a professional ransomware negotiator at Chicago-based DigitalMint, has been sentenced to 70 months in federal prison. The case was charged and sentenced in the U.S. District Court for the Southern District of Florida, which prosecuted Martino even though Land O'Lakes sits in the Tampa area. He pleaded guilty in April 2026 to conspiring to commit extortion, admitting he had acted as a "double agent" for the notorious BlackCat (ALPHV) ransomware-as-a-service (RaaS) group, making him the third cybersecurity professional to fall in a sprawling federal investigation into Western collaborators aiding the Russian-linked gang.
Update (August 26, 2026): The sentence was imposed on July 9, 2026: 70 months — five years and 10 months — in federal prison. A restitution hearing is set for September 17, 2026. Ryan Goldberg and Kevin Martin, the two other cybersecurity professionals who pleaded guilty in December 2025, were each sentenced to 48 months at the end of April 2026.
The case has sent shockwaves through the incident response (IR) community, exposing a dark reality where the individuals hired to mitigate cyberattacks are sometimes the ones ensuring their success.
The Triple-Threat: U.S. Collaborators Plead Guilty
The "Inside Out" Extortion Strategy
Martino’s role was uniquely insidious. Working as a third-party negotiator for victimized companies, he was tasked with lowering ransom demands. Instead, according to court documents and The Register, Martino used his "behind-the-scenes" access to victim networks to feed sensitive information back to the BlackCat operators.
By revealing a victim's insurance limits, financial liquidity, and critical data locations to the hackers, Martino ensured that BlackCat could maintain maximum pressure. In several instances, he allegedly coached the attackers on how to respond to his own "negotiation" tactics to justify a higher final payout — of which he took a significant commission.
A Pattern of Professional Betrayal
Martino is not an isolated case. His plea follows those of two other U.S.-based cybersecurity professionals — Ryan Goldberg, of Georgia, an incident response manager at Sygnia Cybersecurity Services, and Kevin Martin, 36, of Texas, a ransomware negotiator at DigitalMint — who both pleaded guilty in December 2025 in the Southern District of Florida.
- Access Brokerage: The trio admitted to helping identify high-value U.S. targets in the healthcare and critical infrastructure sectors.
- Credential Sharing: In some cases, the "professionals" used their authorized access to install backdoors that the ransomware gang would later use to deploy encryption payloads.
- Financial Laundering: The Justice Department says law enforcement has seized $10 million in assets from Martino to date — digital currency, vehicles, a food truck and a luxury fishing boat.
The CyberSignal Analysis
Signal 01 — The Professional "Vetting" Crisis
This incident is a definitive "Signal" for third-party risk. If your incident response firm is compromised, your entire recovery strategy is a liability. For B2B leaders, this case highlights a desperate need for negotiator vetting. It is no longer enough to hire a firm based on a brochure; you must require transparency regarding their internal audits and background checks. This is the ultimate "Shadow Supply Chain" risk — where the risk is the human in the loop.
Signal 02 — The Identity of the "Insider" has Changed
This is a critical "Signal" for Threat Actors. Traditionally, "insider threats" were disgruntled employees. In 2026, the "insider" is a third-party contractor with high-level permissions. This case reinforces the necessity of zero trust security — specifically the principle of "Trust but Verify" for external IR teams. Even the people saving your network must be monitored by automated audit logs that they cannot delete or modify.