Former DigitalMint ransomware negotiator Angelo John Martino III was sentenced to 70 months in federal prison for conspiring with BlackCat/ALPHV affiliates and abusing confidential client information to drive up ransomware payments from U.S. victims. Prosecutors said Martino used sensitive details from at least five victim organizations—including negotiating positions, insurance limits, financial status, and planned responses—to help attackers increase pressure and extract larger payments, effectively working both sides of the negotiations. Authorities said the scheme contributed to extortion demands tied to roughly $75.3 million in victim losses.
Martino also admitted conspiring with former DigitalMint negotiator Kevin Tyler Martin and former Sygnia incident response manager Ryan Clifford Goldberg to deploy BlackCat ransomware against five additional U.S. companies, including a medical firm that paid nearly $1.3 million in Bitcoin. The case was investigated by the FBI Miami Field Office and the U.S. Secret Service as part of Operation Riptide, and authorities seized millions in assets linked to Martino, with reports citing between $7 million and $10 million. The sentencing highlights the insider risk facing ransomware victims that rely on outside negotiators and incident response firms during extortion events.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The Justice Department said a restitution hearing in the Angelo Martino case is scheduled for September 17, 2026, following his sentencing for conspiring with BlackCat affiliates. The hearing will address restitution related to the ransomware conspiracy.
During 2023, Angelo Martino secretly shared confidential DigitalMint client negotiation details, including cyber-insurance limits and internal positions, with BlackCat/ALPHV affiliates. Prosecutors said the leaks helped the ransomware gang demand and obtain higher ransom payments from affected clients.
The reference states that Martino's co-conspirators, former DigitalMint negotiator Kevin Martin and former Sygnia incident response manager Ryan Goldberg, were each sentenced to 48 months in prison for their roles in the BlackCat-linked scheme.
Authorities seized millions of dollars in assets connected to Martino as part of the investigation into the BlackCat-related conspiracy. One report says about $10 million was seized, while another says more than $7 million was seized.
Martino also admitted conspiring with former DigitalMint negotiator Kevin Tyler Martin and former Sygnia incident response manager Ryan Clifford Goldberg to deploy BlackCat ransomware against five additional U.S. companies. One medical company paid nearly $1.3 million, and another report says about $1 million in Bitcoin was extorted from one victim.
Prosecutors said Angelo John Martino III abused confidential information from victim organizations while working as a ransomware negotiator, sharing details such as negotiating positions, insurance limits, and planned ransom responses with BlackCat/ALPHV affiliates to help extract larger payments. The conduct affected multiple U.S. victims and contributed to tens of millions of dollars in extortion demands and payments.
Former ransomware negotiator Angelo Martino was sentenced to 70 months in federal prison for conspiring with BlackCat/ALPHV affiliates and betraying clients by misusing confidential victim information. The FBI Miami Field Office and U.S. Secret Service investigated the case, including under Operation Riptide.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcexakep.ru
Open sourcehelpnetsecurity.com
Open sourcecysecurity.news
Open sourcebleepingcomputer.com
Open sourcejustice.gov
Open sourcebitdefender.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.