Former ransomware negotiator gets 4 years for BlackCat attacks

A former employee of cybersecurity incident response company DigitalMint has been sentenced to four years in prison for his role in orchestrating BlackCat (ALPHV) ransomware attacks that targeted US companies, resulting in significant financial losses and compromising sensitive data.

Angelo Martino, 41, was part of a group that collected at least $300 million in ransom payments from over 1,000 victims between November 2021 and September 2023. The BlackCat gang’s activities were linked to more than 60 breaches during this period, with several high-profile US organizations falling victim to their attacks. These included a financial services firm that paid $25,660,000 in ransom and a nonprofit organization that paid $26,793,000.

The court documents reveal that Martino was directly involved in the BlackCat ransomware attacks alongside accomplices Kevin Tyler Martin and Ryan Clifford Goldberg, who were also former employees of DigitalMint and Sygnia. The trio operated as affiliates of the BlackCat gang, demanding ransom payments and threatening to leak stolen data before encrypting their systems. In exchange for access to the ransomware and extortion portal, they paid a 20% share of all ransom proceeds to the BlackCat administrators.

What’s particularly disturbing is that Martino, while working as a negotiator for five victims, shared confidential information about their insurance policy limits and negotiation positions with the BlackCat operators. This allowed the cybercriminals to extort the maximum possible amount from these organizations. The victims included school districts, medical facilities, law firms, and other financial services companies.

DigitalMint CEO Jonathan Solomon condemned Martino’s actions, stating that the company had terminated him immediately after discovering his involvement in the attacks. “We strongly condemn these former employees’ criminal behavior, which violated our values, ethical standards, and the law,” Solomon said.

This case serves as a stark reminder of the insider threat and the importance of vetting employees who work with sensitive information. It also highlights the devastating consequences of ransomware attacks on organizations and individuals alike.

In light of this incident, security teams must remain vigilant and ensure that their defenses are robust enough to prevent such breaches from occurring in the first place. By regularly testing their systems through breach and attack simulation exercises, they can identify vulnerabilities and strengthen their security posture before attackers do.


Source: Bleeping Computer — 2026-07-10