惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
F
Fortinet All Blogs
J
Java Code Geeks
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
M
MIT News - Artificial intelligence
腾讯CDC
Last Week in AI
Last Week in AI
The Cloudflare Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
Microsoft Security Blog
Microsoft Security Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
P
Proofpoint News Feed
博客园 - 叶小钗
Recent Announcements
Recent Announcements
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
人人都是产品经理
人人都是产品经理
L
LangChain Blog
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
Ransomware ‘Negotiator’ Faces 20 Years in Prison for Alle...
Filip TRUȚĂ · 2026-04-22 · via Consumer Insights

A Florida man who allegedly worked as a ransomware negotiator has pleaded guilty to conspiring with cybercriminals to carry out ransomware attacks against U.S. organizations—while simultaneously advising victims on how to respond.

Key takeaways:

  • A ransomware negotiator has pleaded guilty to secretly working with the BlackCat (ALPHV) ransomware crew
  • He is accused of sharing sensitive client data to help hackers maximize ransom payments
  • The insider also allegedly helped deploy ransomware attacks against victims
  • Authorities seized over $10 million in illicit assets

According to the U.S. Department of Justice, Angelo Martino, 41, abused his role at a cyber incident response firm to help the BlackCat (ALPHV) ransomware group, one of the most notorious ransomware-as-a-service operations in recent years.

His job was to help organizations recover from ransomware attacks. Instead, prosecutors say, he secretly worked with the attackers behind the scenes.

Playing both sides of the negotiation

Between April and November 2023, Martino acted as a negotiator for multiple ransomware victims. During that time, he allegedly leaked highly sensitive information to the attackers, including insurance coverage limits and internal negotiation strategies.

This intelligence allowed cybercriminals to fine-tune their demands and extract higher ransom payments.

Authorities say the attackers paid Martino for this insider access. In some cases, he allegedly went even further—actively participating in ransomware deployments alongside co-conspirators.

In one documented incident, the group extorted roughly $1.2 million in Bitcoin, later splitting and laundering the proceeds.

A broader conspiracy

Court documents say Martino was part of a larger scheme involving other cybersecurity professionals, including a former incident response manager and another ransomware negotiator.

“Martino has admitted to conspiring with Ryan Goldberg of Georgia and Kevin Martin of Texas to successfully deploy BlackCat ransomware between April 2023 and November 2023 against multiple victims located throughout the United States,” according to the US Department of Justice.

“All three men worked in the cybersecurity industry and leveraged their knowledge and skills to commit these crimes,” the department adds. “After successfully extorting one victim for approximately $1.2 million in Bitcoin, the men split their share of the ransom three ways and laundered the funds through various means.”

Law enforcement has seized $10 million worth of assets from Martino, including digital currency, cars, a food truck, and a luxury fishing boat “that Martino obtained using proceeds of the offense or acquired as a result of the offense.”

Guilty plea

Martino pleaded guilty to one count of “conspiracy to obstruct, delay or affect commerce or the movement of any article or commodity in commerce by extortion.”

He is scheduled to be sentenced on July 9 and faces up to 20 years in prison.

Martin and Goldberg, his co-conspirators, separately entered guilty pleas to the same charge in December 2025, and face the same penalty.

A judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.

Law enforcement actions against BlackCat operators

The DOJ’s announcement follows prior actions to disrupt the BlackCat ransomware operation, during which the FBI seized several websites operated by the BlackCat ransomware actors and developed a decryption tool that allowed hundreds of victims to restore their systems, saving some $99 million in ransom payments.

At that time, the FBI also seized several websites operated by the BlackCat ransomware actors.

You may also want to read:

Cybercrime Losses Hit a Record $21 Billion Last Year, Fueled by AI

Alleged RedLine malware developer extradited to United States

Lapsus$ claims AstraZeneca breach exposes code and credentials