惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
博客园 - 三生石上(FineUI控件)
爱范儿
爱范儿
Vercel News
Vercel News
aimingoo的专栏
aimingoo的专栏
The GitHub Blog
The GitHub Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
A
About on SuperTechFans
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
Hugging Face - Blog
Hugging Face - Blog
C
Check Point Blog
Engineering at Meta
Engineering at Meta
有赞技术团队
有赞技术团队
月光博客
月光博客
M
MIT News - Artificial intelligence
V
Visual Studio Blog
Stack Overflow Blog
Stack Overflow Blog
阮一峰的网络日志
阮一峰的网络日志
D
DataBreaches.Net
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
雷峰网
雷峰网

Consumer Insights

After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss
The ransomware negotiator who was working for the other side
Graham CLULEY · 2026-07-14 · via Consumer Insights

When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.

Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. They know how the ransomware gangs operate, how to buy time, and how to push back on extortionate demands. They can help manage the technical side of any payment if needed, and help a corporate victim assess whether decryptors actually work.

What victims don't expect is that their trusted negotiator might be separately sharing details of the victim's cyber-insurance policy and negotiation strategy directly with the attackers themselves.

That's precisely what Florida man Angelo John Martino III did, and last week a federal judge sentenced him to 70 months in prison for it.

41-year-old Martino worked as a ransomware negotiator for DigitalMint, an incident response company based in Chicago. His job was to negotiate on behalf of organisations who had been held to ransom by ransomware attacks.

However, starting in April 2023, Martino started to live a double life. Unknown to his employer or clients, Martino was feeding information to the BlackCat (also known as ALPHV) ransomware group through a hidden tab within the same BlackCat negotiation panel he used for his legitimate work.

In exchange for a cut of the ransom payment, Martino fed the criminals everything they wanted: victims' insurance policy limits, their internal negotiating positions, and their financial circumstances.

On one occasion, Martino secretly tipped off a BlackCat affiliate that the victim's insurance company had only approved a limited payout.

In the official negotiation chat - visible to both DigitalMint and the victim - he acted the role of concerned intermediary with aplomb. However, behind the scenes, the gang already knew exactly what they could extract.

The BlackCat operator's response in the official negotiation chat was clear: "We know how much you can pay. Contact your insurance. We know about them also."

The ransomware victim, a hospitality company, ultimately paid out nearly US $16.5 million.

In total, five of Martino's clients collectively made more than US $75.3 million in ransom payments between April and September 2023. This included a non-profit organisation that paid nearly US $26.8 million, and a financial services company that paid nearly US $25.7 million - each payment likely inflated due to the information Martino shared with the extortionists.

But that wasn't the limit of Martino's wrongdoing, because he and two colleagues (Kevin Martin, another DigitalMint negotiator, and Ryan Goldberg, an incident response manager at cybersecurity firm Sygnia) deployed BlackCat ransomware against more victims themselves.

The trio kept 80% of ransoms and paid 20% to the BlackCat gang, as affiliates - successfully extorting US $1.2 million from a medical device company.

In April 2026, Goldberg and Martin were both sentenced to four years in prison.

Martino spent the cryptocurrency proceeds of his criminal activity on two Florida properties, a boat, and several vehicles. Authorities say that they have seized US $10 million of his assets, and a hearing in September will determine what other restitution he will have to make.

"Angelo Martino sold out the very victims he was hired to represent, handing their confidential negotiating positions to BlackCat actors to drive up ransoms and enrich himself," said Assistant Director Brett Leatherman of the FBI Cyber Division. “[The] sentence demonstrates that the FBI will pursue not just the criminals who deploy ransomware, but the insiders who enable them. Working with our partners, the FBI will find those who betray that trust and hold them accountable.”

US authorities have described DigitalMint as an "unknowing victim," and said that Martino deliberately concealed what he was doing from his employer. The company has since changed the way its negotiators communicate with ransomware gangs, and is working with the Department of Homeland Security to establish a registry for the currently highly-unregulated world of ransomware negotiation.