Angelo Martino has been sentenced to 70 months in prison for serving as an informant for the BlackCat/ALPHV ransomware operation against five U.S. companies that had engaged him as a negotiator. The sentence, handed down on July 9, 2026 in the Southern District of Florida, closes the case of the most severe documented betrayal in the history of commercial incident response: $75.3 million extorted using confidential information on insurance limits and negotiation strategies that Martino himself had stolen from clients.
The DOJ and FBI investigation reconstructed a months-long scheme, from spring through fall 2023, in which the negotiator's fiduciary position was converted into an intelligence asset for organized cybercrime. The conviction includes forfeiture of roughly $10 million in assets: a $1.68 million waterfront villa, a second home worth $396,000, cryptocurrency wallets, vehicles, a food truck, and a 30-foot fishing boat.
- Martino received 70 months for conspiracy to commit extortion; co-defendants Kevin Martin and Ryan Goldberg, formerly of DigitalMint and Sygnia respectively, had already been sentenced to four years each in April 2026.
- The five DigitalMint clients betrayed clients paid specific ransoms: a nonprofit roughly $26.8 million, a financial institution roughly $25.7 million, a hospitality company roughly $16.5 million, plus two other payments of $6.1 million and $213,000.
- Martino obtained a shared ALPHV affiliate account with his co-conspirators, receiving a cut of the payments; the group paid 20% to BlackCat administrators and split the remaining 80%.
- DigitalMint fired Martino in April 2025 after DOJ notification; the company was not charged, but the case raises structural questions about internal controls in the negotiation sector.
How the Double Game Worked
The mechanism required no software vulnerabilities, only the information asymmetry inherent in a ransomware crisis. Martino had access to clients' insurance documentation, internal financial assessments, and real-time negotiation telemetry. According to the indictment, he systematically passed this data to BlackCat affiliates to optimize ransom demands.
An excerpt from the plea agreement, cited by CyberScoop, shows Martino instructing an affiliate: "Keep denying our offers and I will let you know once I find out the max they want to pay" — an operational protocol for economic intelligence applied against his own principal. In the negotiation chats visible to clients, Martino presented compromise offers; in parallel communications with the attackers, he provided the target price.
The case also documents the group's parallel technical activity. Beyond betraying the five DigitalMint clients, Martino, Martin, and Goldberg independently deployed BlackCat against five other companies between April and November 2023, successfully extorting roughly $1.3 million from a healthcare-sector company in May 2023. Goldberg, a former Sygnia manager, and Kevin Martin, Martino's colleague at DigitalMint, handled the technical side of the intrusions.
The Pay Structure and Laundering
According to The Hacker News, the group operated with a standard ransomware-as-a-service split: 20% to ALPHV administrators, 80% divided among the three conspirators. Bitcoin proceeds were laundered through chains of successive transactions, per court documents cited by the same source.
The final asset seizure — roughly $10 million — includes diversified holdings indicating prolonged liquidation of gains: not just cryptocurrency, but real estate, vehicles, and commercial ventures. Martino surrendered in March 2026, was released on $500,000 bond, and pleaded guilty in April 2026 to conspiracy to obstruct commerce by extortion, a crime carrying a maximum 20-year sentence. The co-defendants had pleaded guilty in December 2025.
The sentence includes a restitution hearing set for September 17, 2026, where the amount owed to victims will be determined. The dossier does not specify whether the harmed companies have obtained partial or full reimbursement through insurance policies or legal action against DigitalMint.
Structural Impact on the Incident Response Supply Chain
The Martino case exemplifies a specific organizational vulnerability: the lack of fiduciary standards in the ransomware negotiation industry, an unregulated sector where professionals handle critical liquidity and sensitive information without oversight equivalent to that of regulated financial advisors. Compensation models based on a percentage of the ransom — or even processing fees — create structural tensions that this case makes explicit.
Coveware, a DigitalMint competitor, has already eliminated processing fees for ransom payments as a direct response to this affair, according to Centrexit. The measure, however, addresses only one distorted incentive: the question of internal controls over negotiators who simultaneously manage strategic information and access to attacker communication channels remains open.
The DOJ, through Assistant Attorney General A. Tysen Duva, indicated that "other unrelated instances of alleged fraud in the cybersecurity industry" are under investigation. The dossier does not specify whether these probes have already produced formal charges or whether they involve additional operators in the same supply chain.
"Angelo Martino sold out the very victims he was hired to represent, handing their confidential negotiating positions to BlackCat actors to drive up ransoms and enrich himself" — Brett Leatherman, Assistant Director, FBI Cyber Division
Why It Matters
Martino's sentence is not an isolated case of individual criminality but a warning signal about a security market operating under conditions of structural opacity. Companies hit by ransomware delegate crisis management to external providers in a state of vulnerability; the case documents that this delegation can be weaponized against them.
The dossier does not specify what internal controls DigitalMint had implemented, nor what methods Martino used to conceal his communications with BlackCat affiliates from his employer. The company stated it had no knowledge of the facts and had applied "industry-standard" controls that were circumvented.
For CISOs and business decision-makers, the affair raises due-diligence questions: vetting the background of incident response negotiators, the contractual structure of fiduciary relationships, the separation of roles between those with access to insurance information and those who communicate with attackers. The dossier does not document emerging industry standards on these points nor specific corrective measures beyond Coveware's decision on processing fees.
The source does not specify whether DigitalMint's compensation model for Martino included incentives tied to the size of negotiated ransoms. No infrastructure overlaps emerge linking the actor to additional industry operators not already mentioned in the sources.
The Other Victims and the ALPHV Context
The BlackCat/ALPHV group, prior to its disruption by the DOJ in December 2023, had struck more than 1,000 victims worldwide, according to The Hacker News. The disruption operation included the release of an FBI decryption tool that, per documents cited by CyberScoop, enabled roughly $99 million in avoided ransoms for hundreds of organizations.
The three conspirators operated during the group's ascent, exploiting its affiliate-marketing infrastructure before its judicial paralysis. The current operational status of remaining ALPHV affiliates is not documented in the brief; the dossier notes only the December 2023 disruption date.
Martino, 41, had a cybersecurity career dating back to at least 2015, with prior roles at Booz Allen Hamilton, Tracepoint, and TRM Labs. The professional trajectory — from government contractor to commercial crisis-services provider to convicted criminal conspirator — raises questions about the absence of red flags in the sector's hiring controls, which the brief does not document.
Information has been verified against cited sources and is current as of publication.
Information has been verified against cited sources and is current as of publication.
Sources
- https://cyberscoop.com/digitalmint-ransomware-negotiator-angelo-martino-sentenced/
- https://centrexit.com/blog/digitalmint-ransomware-negotiator-guilty-plea-nonprofit-healthcare/
- https://thehackernews.com/2026/05/two-cybersecurity-professionals-get-4.html
- https://www.helpnetsecurity.com/2026/04/21/ransomware-negotiator-blackcat-alphv-group/
- https://www.securityweek.com/12-million-impacted-by-data-breach-at-japanese-telco-kddi/
- https://www.securityweek.com/8layers-raises-2-9-million-for-identity-security-platform/