A US Cybersecurity Expert Sentenced to 70 Months in Prison for Helping Ransomware Gang
Angelo Martino, a 41-year-old cybersecurity expert from Florida, has been sentenced to 70 months in prison after pleading guilty to charges of helping a ransomware gang while working as a negotiator. This is the third high-profile case in recent years where US-based cybersecurity professionals have been accused of collaborating with cybercrime gangs.
Martino was part of a group of three individuals who worked at cybersecurity firms and were tasked with helping victims of ransomware attacks. However, instead of providing assistance to the affected parties, they secretly worked with the hackers to extort more money from their clients. According to investigators, Martino began working with BlackCat/Alphv ransomware operators in April 2023 and helped them extort at least five victims.
As part of his plea deal, Martino agreed to cooperate with authorities and provide information about his involvement with the cybercrime gang. In exchange for his cooperation, he will receive a reduced sentence. However, the full extent of his crimes is still not clear, as some details are yet to be revealed in court proceedings.
The case highlights the growing threat posed by insiders who compromise their professional integrity to help malicious actors. Cybersecurity professionals often have access to sensitive information and can use this knowledge to facilitate cybercrime operations. In Martino’s case, he allegedly provided confidential information about his employer’s clients to the hackers, enabling them to maximize their ransoms.
The US authorities have taken a tough stance on insider threats in recent years, with numerous high-profile cases involving cybersecurity professionals accused of collaborating with cybercrime gangs. The government has also increased its efforts to detect and prevent such incidents, including offering a $10 million reward for information leading to the identification of key members of the BlackCat/Alphv group.
The case serves as a reminder that cybersecurity is not just about technology; it’s also about human behavior and ethics. As the threat landscape continues to evolve, organizations must prioritize their security culture and ensure that their employees understand the importance of integrity and professionalism in their work.
In practical terms, this means that companies should implement robust background checks and screening processes for new hires, particularly those working in sensitive roles such as cybersecurity. They should also establish clear policies and procedures for reporting suspicious behavior or insider threats, and provide regular training and awareness programs to educate employees about the risks of insider attacks.
Source: SecurityWeek — 2026-07-10