
A former ransomware negotiator has been sentenced to 70 months in prison after prosecutors showed he secretly assisted the BlackCat gang (Justice Department announcement). Angelo Martino, who worked for DigitalMint and advised victims on ransom payments, leaked confidential defence strategies to the attackers, enabling them to demand higher sums (report by Databreaches). His actions contributed to more than $75 million paid by five victim organisations before his arrest.
While acting as a trusted intermediary, Martino shared details about victims’ backup practices, incident response timelines and cyber‑insurance limits (SecurityAffairs coverage). This insider knowledge allowed BlackCat to tailor ransom notes and pressure tactics, effectively turning him into a double agent. The Department of Justice said the information flow directly increased the extortion amounts demanded in each case.
Martino pleaded guilty in April and asked the court for a 24‑month term, citing his help in securing convictions against two co‑defendants who each received four‑year sentences (SecurityWeek article). The judge rejected the request, imposing the 70‑month term and ordering the seizure of assets valued at over $10 million. Restitution negotiations are still under way.
BlackCat, also known as Alphv, has been linked to over 1 000 compromised organisations between 2021 and late 2023, amassing tens of millions in ransom payments, including a notable $22 million payout from a single target (The Hacker News story). Martino’s betrayal highlights how insider threats can amplify the impact of ransomware campaigns that already pose a serious risk to critical infrastructure and private enterprises.
Organisations should vet any third‑party negotiators or consultants, ensuring they are bound by strict nondisclosure agreements and monitored for anomalous communications (SecurityOnline info). Internal controls such as segregation of duties, regular access reviews and logging of all external consultations can help detect leaks before they are exploited. Security teams ought to treat insider risk with the same rigour applied to external malware, incorporating behavioural analytics and regular staff training.
Law enforcement agencies encourage victims to share indicators of compromise and any suspicious contact with negotiators, as this aids broader threat intelligence efforts (DOJ guidance). Incident response plans should be updated to include insider threat scenarios, and regular tabletop exercises can prepare teams to spot and halt betrayal early. By combining technical defences with vigilant personnel policies, firms can reduce the chance that a trusted advisor becomes a conduit for ransomware extortion.
The court heard that Martino’s leaks allowed BlackCat to increase ransom demands by an average of 40 percent across the cases he touched, a figure presented by prosecutors during sentencing (SecurityAffairs detail). Victims described the breach of trust as devastating, noting that they had relied on his expertise to navigate crises. The judge stressed that abuses of professional privilege strike at the heart of cybersecurity defenses and will be met with severe penalties.