In April 2023, Angelo Martino, a ransomware negotiator at DigitalMint, a Chicago-based incident response firm, began quietly working against the clients who had hired him. Martino used a private chat channel his employer could not see to relay confidential details, including a client's cyber-insurance policy limits and internal board discussions about how much they were willing to pay, directly to negotiators for the BlackCat ransomware gang, also known as ALPHV. In effect, he told the attackers what to ask for before they even asked.
The scheme ran for seven months. Five DigitalMint clients whose negotiations Martino handled, spanning hospitality, a nonprofit, financial services, retail and medical companies, paid ransoms ranging from $213,000 to $26.8 million, a combined total exceeding $75 million. In one case, Martino told DigitalMint he was submitting a client's lower settlement offer to the attackers while secretly telling BlackCat the client would actually pay $2 million more. The client paid the extra $2 million because of what Martino had done.
The scheme escalated. In May 2023, Martino signed up as a BlackCat affiliate in his own right and shared that access with a fellow DigitalMint negotiator, Kevin Martin, and Ryan Goldberg, an incident response manager at the cybersecurity firm Sygnia. The three had been conspiring since the previous year, before DigitalMint had even hired Martin. Together they began deploying BlackCat ransomware directly against additional victims, extorting at least $1.2 million from one medical device company alone.
Martino was sentenced on 3 July 2026 to 70 months in federal prison for conspiracy to interfere with interstate commerce by extortion, below the six-to-seven-and-a-quarter-year range federal guidelines recommended. Martin and Goldberg were each sentenced to four years in prison in April 2026. Authorities seized roughly $10 million in assets from Martino, including cryptocurrency, vehicles, a food truck and a luxury fishing boat. BlackCat itself was a particularly aggressive operation, one that had targeted healthcare facilities and published stolen breast cancer imaging from victims before law enforcement disrupted its infrastructure in December 2023.
The defences that failed here were not weak by conventional standards. DigitalMint and Sygnia are cybersecurity and incident response firms, staffed by people whose job is to understand exactly how attackers operate. Both companies say they had no knowledge of the scheme, and the court accepted that. That is the more troubling detail: whatever vetting and monitoring either firm had in place failed to surface a seven-month criminal conspiracy involving three insiders operating across two organisations, using a communication channel neither employer could see.
A ransomware negotiation is not a routine transaction. It is the moment a company's true financial ceiling, its insurance coverage, and its board's private tolerance for loss are all committed to a channel the client cannot fully audit. That is an execution event. Before a negotiator can transmit a client's settlement position, insurance limits or authorised offer to any external party, GoFirm requires a confirmation request to go to the named authority on the client's side, the person who actually approved that number, on their registered device.
The same boundary applies to the negotiator's own firm. Before confidential client material can leave DigitalMint's systems through any channel, sanctioned or otherwise, the export is an execution event requiring confirmation from a named compliance authority, not just trust in the employee handling it. Martino's private channel worked precisely because no one outside it had to confirm what was being sent, or to whom. A negotiator secretly working for the other side, however convincing his standing inside the firm, cannot produce a biometric confirmation from an authority who was never told what he was doing. The execution boundary holds regardless of how trusted the insider appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Bradbury, D. 2026. The inside job that cost ransomware victims millions. Malwarebytes, 14 July 2026.
2. Whittaker, Z. 2026. Florida ransomware negotiator convicted for helping ransomware gang extort US companies. TechCrunch, 10 July 2026.
