Angelo Martino, a Florida-based ransomware negotiator, was sentenced to 70 months in prison after admitting he worked both sides of the extortion attacks he was hired to help resolve. According to the Justice Department, Martino was retained by five separate BlackCat ransomware victims to negotiate on their behalf, and while doing so he passed the attackers confidential details about each client’s insurance policy limits and internal negotiation strategy, information that let the ransomware operators push for higher payouts than they would otherwise have gotten. Prosecutors also tied Martino to two former cybersecurity professionals, Ryan Goldberg and Kevin Martin, in a conspiracy to deploy BlackCat against multiple U.S. victims between April and November 2023. Investigators seized about $10 million in assets traced to the scheme, including cryptocurrency, vehicles, a food truck, and a fishing boat.
The case matters beyond one bad actor. Ransomware negotiation and incident response have grown into a cottage industry that most organizations only engage during the worst week of their year, under time pressure, and frequently without the vetting rigor applied to other vendors handling equally sensitive data. A negotiator sees a victim’s insurance ceiling, its appetite to pay, and its internal deliberations in real time, which is exactly the information an attacker needs to price an extortion demand. Martino’s case shows that information can leak from the inside as easily as from a breached network.
The original insight for CISOs is a governance one: negotiation and IR retainers are typically signed in advance of an incident, often through cyber insurance panels, with little independent verification of who is actually on the call once a breach happens. This sentencing is a concrete argument for building conflict-of-interest attestations and independent oversight into those retainer agreements now, before an incident forces the choice, rather than trusting the panel vetting alone. It is a theme that runs through the broader consolidation of the ransomware ecosystem, where a smaller number of groups increasingly rely on human intermediaries, not just malware, to maximize payouts.
Source: U.S. Department of Justice