Poacher Turned Poacher: Ransomware Negotiator Gets 70 Months for Helping BlackCat Extort Victims

There is betrayal, and then there is being extorted by the person you hired to make the extortion stop. This case is the latter, and a federal court just put a number on it: 70 months.

According to BleepingComputer, a former employee of cybersecurity incident-response company DigitalMint was sentenced to 70 months — nearly six years — in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. SecurityWeek identifies the individual as Angelo Martino, a former ransomware negotiator, and reports he was sentenced for helping the now-defunct BlackCat/ALPHV operation. Per the reporting, he conspired with the ransomware operators to extort multiple victims and worked with two other cybersecurity professionals to target additional victims in 2023.

The trust that got weaponized

Ransomware negotiators occupy an unusually sensitive seat. When an organization is hit, it hands the negotiator a detailed picture of the worst day of its corporate life: what was encrypted, how bad the exposure is, how much cyber insurance might cover, and how desperate leadership is to make the problem disappear. That knowledge is exactly what an extortionist most wants — it is the difference between guessing at a ransom and knowing precisely how much pain a victim will pay to avoid. An insider on the response side who feeds that context to the attackers isn’t just breaking the law; they’re corrupting the one role a victim is supposed to be able to trust in the middle of a crisis.

What this means for how you handle incidents

  • Vet your responders: Choose IR and negotiation firms with strong reputations, clear conflict-of-interest policies, and references you actually check.
  • Limit and log access: Even trusted third parties should get least-privilege access to incident data, with logging of who saw what.
  • Compartmentalize sensitive figures: Insurance limits and maximum acceptable payouts are the crown jewels of a negotiation — restrict who inside and outside the org knows them.
  • Involve law enforcement early: Engaging the FBI and relevant authorities from the start adds oversight and options beyond the negotiation table.

The outrage

We spend a lot of words in this business on external threats — the gangs, the affiliates, the leak sites. This one is a reminder that the call is sometimes coming from inside the response. The insider threat is the hardest to defend against precisely because it wears the badge of the person you called for help, and it does the most damage because that person is handed the map to your vulnerabilities as a matter of routine.

A 70-month sentence is a real consequence, and it’s good to see one land. But the deterrent value only goes so far when the underlying model requires victims, mid-catastrophe, to trust strangers with their most sensitive information. Verify who you’re letting into the room — because the whole point of hiring a negotiator is that they’re supposed to be on your side of the table.

Leave a Reply

Discover more from Cyber Outrage

Subscribe now to keep reading and get access to the full archive.

Continue reading