Ransomware negotiator hired to represent victims was working for the attackers

Ars Technica News

Summary

A ransomware negotiator hired to represent victims was secretly working for the BlackCat attackers, sharing confidential client information to maximize ransom payments, leading to a 6-year prison sentence.

<p>A former ransomware negotiator was <a href="https://storage.courtlistener.com/recap/gov.uscourts.flsd.708190/gov.uscourts.flsd.708190.46.0.pdf">sentenced</a> to 70 months in prison yesterday after colluding with BlackCat scammers to extort the victims he was hired to protect.</p> <p>As a ransomware negotiator for the <a href="https://digitalmint.io/services/ransomware-cryptocurrency-settlement/">company DigitalMint</a>, Florida resident Angelo Martino's job was "to negotiate with cybercriminals to mitigate the ransoms paid by [DigitalMint's] clients," the US government said in a <a href="https://storage.courtlistener.com/recap/gov.uscourts.flsd.708190/gov.uscourts.flsd.708190.40.0.pdf">sentencing memorandum</a> on Tuesday. "Instead, Martino provided the cybercriminals with confidential negotiation information to maximize the ransoms in exchange for a portion of the ransom payments. Five of the victims whom Martino was supposed to help paid over $75 million to ransomware affiliates, including likely millions of dollars in ransom demands inflated as a result of the confidential information provided by Martino."</p> <p>Martino, 41, pleaded guilty and <a href="https://storage.courtlistener.com/recap/gov.uscourts.flsd.708190/gov.uscourts.flsd.708190.37.0.pdf">asked for a 24-month sentence</a>, noting that he "provided substantial assistance that contributed to the indictment and conviction of two co-defendants." As described in <a href="https://arstechnica.com/security/2025/11/fbi-arrests-ransomware-clean-up-experts-for-planting-ransomware/">this November 2025 article</a>, the co-defendants were Texas resident Kevin Martin, a ransomware negotiator for DigitalMint, and Georgia resident Ryan Goldberg, an incident manager at security firm Sygnia.</p><p><a href="https://arstechnica.com/tech-policy/2026/07/ransomware-negotiator-helped-attackers-extort-his-own-clients-gets-6-year-sentence/">Read full article</a></p> <p><a href="https://arstechnica.com/tech-policy/2026/07/ransomware-negotiator-helped-attackers-extort-his-own-clients-gets-6-year-sentence/#comments">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 07/10/26, 09:11 PM

# Ransomware negotiator hired to represent victims was working for the attackers Source: [https://arstechnica.com/tech-policy/2026/07/ransomware-negotiator-helped-attackers-extort-his-own-clients-gets-6-year-sentence/](https://arstechnica.com/tech-policy/2026/07/ransomware-negotiator-helped-attackers-extort-his-own-clients-gets-6-year-sentence/) “As part of his duties, the defendant was provided with details regarding the attack and information regarding the ransom demand and typically the victim’s applicable insurance coverage and negotiating strategy,” the factual proffer said\. Martino used BlackCat’s live chat system to negotiate ransom payments\. Starting in April 2023, he “began communicating with BlackCat actors through the messaging platform Tox and in a separate ‘intermediary chat’ tab of the BlackCat panel,” which “was only accessible to the defendant and the BlackCat negotiators and affiliates,” the factual proffer said\. Martino used the intermediary chat tab to provide confidential information about clients\. “The purpose of these intermediary chat communications was to maximize the ransom payments paid by those victims to the BlackCat actors,” the court document said\. “This information provided by the defendant without the victims’ knowledge included the victims’ insurance policy limits and internal negotiation positions\. In exchange for providing confidential information, the defendant received a portion of the ransomware payments in digital currency\.” In May 2023, Martino obtained affiliate access to the BlackCat panel, and he shared that access with the co\-conspirators\. “After the defendant obtained affiliate access, the defendant, Co\-conspirator 1, and Co\-Conspirator 2 agreed to, and did use the BlackCat ransomware and platform to attack and extort victims and share the ransom proceeds amongst themselves and with the BlackCat admin,” the factual proffer said\. ## DigitalMint “also an unknowing victim” In a statement provided to Ars today, DigitalMint said it had no knowledge of Martino’s criminal actions while he was employed there\. DigitalMint said it fired the employees involved in the conspiracy after learning of the allegations from the Department of Justice, “and fully cooperated with federal authorities throughout the investigation\.” “The actions of Martino and his co\-conspirators were deliberately concealed from DigitalMint and were in clear violation of the company’s values, ethical standards, and the law,” DigitalMint said\. “The government has now publicly made it clear that DigitalMint was also an unknowing victim of these crimes\.” DigitalMint said Martino evaded the company’s internal safeguards that attempt to prevent fraud\. “DigitalMint maintained controls consistent with industry standards, including background checks and compliance procedures, but Martino intentionally hid his conduct from the company, including through separate, unauthorized communication channels that the government’s filings describe as accessible only to Martino and the BlackCat negotiators and affiliates,” DigitalMint said\. “When federal authorities brought the allegations to the company’s attention, DigitalMint acted immediately\.” Sygnia[told CNN](https://www.cnn.com/2025/11/03/politics/cybersecurity-ransomeware-hacking)and other media outlets in November that it terminated Goldberg “immediately upon learning of the situation\.” Sygnia said the company itself was not a target of the investigation and that it was working closely with the FBI\.

Similar Articles

Who Runs the Ransomware Group ‘The Gentlemen?’

Krebs on Security

An investigation into the ransomware group 'The Gentlemen' reveals clues pointing to the real-life identity of its administrator, known as Hastalamuerte/Zeta88, an Izhevsk-based Russian speaker who recruits affiliates with a 90/10 ransom split.