The Angelo Martino shows how fragile the “chain of trust” can become in the ransomware negotiation ecosystem. The 41-year-old former DigitalMint was sentenced to 70 months in prison after – according to US authorities – he acted as a “double agent”, helping victims while working with the BlackCat group (ALPHV) to maximize ransoms.

The CyberScoop describes how Angelo Martino used information he obtained through negotiations on behalf of DigitalMint clients (insurance policy limits, "red lines" and bidding strategy) and secretly channeled it to his associates, so that claims would rise and agreements would be closed for much higher amounts.
See also: Former ransomware negotiator confesses to participating in BlackCat attacks
How Angelo Martino "played" both sides
In practice, Angelo Martino played the role of a "middleman" who was supposed to protect the victim's interests. Instead, he allegedly gave the attackers crucial details about how much a company could pay and where it would "bend" in the negotiation. Thus, the perpetrators' demands were precisely tailored to the victims' financial data.
According to the same report, ransom payments made between April and September 2023 by five organizations ranged from hundreds of thousands of dollars to tens of millions. In one case, a non-profit organization paid approximately $26.8 million, while a financial services company reportedly paid approximately $25.7 million.

The BlackCat/ALPHV connection and the consequences
BlackCat/ALPHV has been one of the most active ransomware groups in recent years, targeting critical infrastructure and large organizations. The Martino case highlights that even when a business resorts to “professional negotiators,” there is a risk of abuse of access and exploitation of sensitive information.
In addition to the prison sentence, the authorities have proceeded – always according to what is publicly reported – to seize significant assets (real estate, vehicles and cryptocurrencies), showing that financial investigations surrounding ransomware cases are gaining increasing importance.
See also: Cybersecurity experts accused of BlackCat ransomware attacks

What it means for organizations facing ransomware
The SecNews technical/editorial team points out that managing a ransomware incident is not just a technical issue; it is also a governance. If an organization chooses an external negotiator or incident response provider, clear procedures are needed: controlling communication channels, restricting access to financial data, maintaining audit logs, and a clear policy on who approves offers and information sharing.
At the same time, it is critical to invest resources in prevention: minimal access rights, MFA everywhere, off-network backups, regular recovery exercises, and a plan for communicating with legal/insurance authorities. The Angelo Martino case shows that the “invisible” risks of third-party partners can be just as serious as the attack itself.
Another practical conclusion is that organizations should demand clarity about the provider’s procedures: who has permission to speak to the perpetrators, which accounts are used, how conversation logs are kept, and whether there is a policy prohibiting “parallel” communications. These details are not bureaucracy; they are the way to reduce the risk of a partner becoming a single point of failure.
Finally, it is worth having a plan for the “after”: third-party assessment (vendor risk management), revision of insurance terms, and technical improvements such as segmentations in critical networks and faster lateral movement detection. In an era when ransomware groups operate as businesses, defense requires a correspondingly disciplined organization.
For the same reason, experts recommend that sensitive financial information (such as insurance policy limits or available liquidity) be shared only with essential executives, as this data can directly influence the extortionists' "pricing." In critical cases, having a second independent assessment (second opinion) for the negotiation can act as a safety valve.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
