A third US cybersecurity expert, Angelo Martino, has been sentenced to 70 months in prison for helping a ransomware gang while working as a ransomware negotiator. This latest development highlights the increasing threat of insider threats and underscores the need for robust measures to prevent such collaborations.
Martino, 41, from Florida, was accused of working with BlackCat/Alphv ransomware operators, who targeted over 1,000 organizations between 2021 and December 2023. According to investigators, Martino provided confidential information about his employer’s clients’ negotiating positions and strategies, enabling the hackers to maximize the ransoms paid by victims. In return for this assistance, BlackCat paid Martino a share of the profits.
Martino is one of three individuals charged by US authorities last year over their role in ransomware attacks. The other two suspects, Kevin Martin from Texas and Ryan Goldberg from Georgia, were each sentenced to 4 years in prison in late April. This case raises questions about the vetting process for cybersecurity professionals who deal with high-stakes negotiations. How can companies ensure that their employees are trustworthy and not vulnerable to bribery or coercion?
The investigation into Martino’s activities revealed that he had been working with BlackCat since April 2023, helping the hackers extort at least five victims. Authorities seized $10 million worth of assets from him, including cryptocurrency, vehicles, a food truck, and a fishing boat. Martino will also have to pay restitution, but the amount will be determined in a hearing scheduled for September.
The BlackCat/Alphv gang’s activities were marked by brazenness and ruthlessness. In one notable incident, they received a $22 million ransom from a victim and subsequently pulled an exit scam. The US has been offering a $10 million reward for information leading to the identification of key members of the group.
The Martino case serves as a stark reminder that even those entrusted with sensitive cybersecurity work can be tempted by financial gain or other incentives. Companies must implement robust security measures, including background checks and regular monitoring of employee activity, to prevent such insider threats from occurring. Additionally, employees should be aware of the red flags of insider threats and report any suspicious behavior to their superiors immediately.
Ultimately, this case highlights the importance of vigilance and collaboration in the cybersecurity community. By working together, we can prevent further instances of insider threats and protect organizations from the devastating impact of ransomware attacks.
Source: SecurityWeek — 2026-07-10