Ransomware negotiator stole at least $10M while selling out his own clients

Angelo Martino was hired to keep one number hidden from ransomware gangs: the maximum amount his clients were willing to pay.
Instead, he sold it to the attackers.
Federal prosecutors say the former ransomware negotiator secretly supplied BlackCat affiliates with his clients’ insurance limits, internal strategy and payment ceilings, then collected a portion of the resulting ransoms. Investigators have already seized more than $10 million in criminal proceeds from Martino, including cryptocurrency, houses, vehicles, a food truck and a luxury fishing boat.
A federal judge in Miami sentenced the 41-year-old Florida man to 70 months in prison on July 9. He will also serve three years of supervised release, while a separate hearing to determine how much restitution he owes his victims is scheduled for September 17.
The $10 million is not the total amount paid by the organizations Martino betrayed. It is the amount of criminal proceeds authorities say they have already traced back to him.
His clients paid far more.
He was negotiating against himself
Martino worked for Chicago-based incident response company DigitalMint, where organizations hired him to communicate with ransomware operators, reduce demands and arrange payments when necessary.
Beginning in April 2023, Martino used that access to run two negotiations at once.
In the official chat, visible to DigitalMint and its client, he appeared to argue that the organization could not afford the attackers’ demand. In a separate intermediary channel, visible only to Martino and the BlackCat criminals, he disclosed what the client and its insurer were actually prepared to pay.
According to the factual proffer Martino signed as part of his guilty plea, he told one BlackCat actor:
“Keep denying our offers and I will let you know once I find out the max they want to pay.”
The victim was a U.S. hospitality company. In the client-facing chat, Martino offered $1 million and argued that a $17 million payment could put the company out of business. Behind the client’s back, he advised the attacker to search the stolen files for insurance information, mention the company’s cyber policy and continue rejecting offers until Martino discovered the real ceiling.
The hospitality company ultimately paid approximately $16.48 million.
Martino performed the same role during attacks against four other DigitalMint clients. Court records reviewed by CyberScoop show that a nonprofit paid approximately $26.79 million, a financial services company paid $25.66 million, a retailer paid $6.1 million and a medical company paid $213,000.
Together, the five organizations paid approximately $75.25 million.
The court filing does not disclose Martino’s exact cut from each payment. It does say that he received financial compensation from the attackers in every case and collected “a portion of the ransomware payments” in cryptocurrency.
DigitalMint was not charged with participating in the scheme. The company said it had no knowledge of Martino’s backchannel communications and suspended his access after the Justice Department contacted it in April 2025, terminating him the following day.
At least $10 million made it back to Martino
Martino did not leave the money sitting in one Bitcoin wallet.
The factual proffer says he used ransomware proceeds to purchase two Florida houses, a 1999 Nissan Skyline, a 2023 boat, a Polaris vehicle and a food truck. The FBI also recovered Bitcoin, Monero, XRP, Solana and Stellar from cryptocurrency wallets seized at his residence.
The seized cryptocurrency alone was valued at approximately $9.2 million, while the additional property pushed the total value of assets connected to Martino above $10 million.
That figure is best understood as a floor, not a final accounting. Martino’s restitution has not yet been determined, and the government has not publicly itemized how much of the $75.25 million in client payments was passed to Martino, retained by individual BlackCat affiliates or delivered to the ransomware operation’s administrators.
What prosecutors have established is that Martino received millions in cryptocurrency from the conspiracies and used those proceeds to build a collection of property, vehicles and digital assets.
As TechCrunch reported following his sentencing, the items were not incidental possessions seized during an investigation. Authorities say they were purchased with money stolen through the ransomware schemes.
Then the negotiator became the attacker
Martino eventually went beyond helping BlackCat affiliates squeeze his employer’s clients.
He joined DigitalMint employee Kevin Martin and former Sygnia incident response manager Ryan Goldberg to become BlackCat affiliates themselves. The three cybersecurity professionals obtained access to the gang’s ransomware platform and agreed to give BlackCat’s administrators 20% of any ransom payments they collected.
The group attacked five additional organizations in 2023, including a Florida medical-device company, a Maryland pharmaceutical company, a California engineering firm, a Virginia drone manufacturer and a California doctor’s office, according to reporting based on the original indictment.
Only one of those organizations paid. The medical-device company transferred approximately $1.27 million in Bitcoin after its systems were encrypted. The conspirators paid BlackCat its share, split the remainder three ways and laundered the proceeds.
Martin and Goldberg were each sentenced to four years in federal prison. Martino received a longer sentence because his conduct also included betraying the five organizations he had been specifically assigned to represent.
Ransomware negotiators are trusted with the exact information attackers are trying to uncover: insurance coverage, operational urgency, internal approval limits and the point at which an organization will finally pay.
Martino converted that trust into at least $10 million in criminal proceeds.
The person hired to hide the ceiling was secretly selling it.















