A ransomware negotiator is supposed to be the one person in the room fighting for the victim. That trust was shattered in the case of Angelo Martino, a former negotiator at incident response firm DigitalMint, who was sentenced to 70 months in federal prison for secretly feeding confidential client information to the BlackCat ransomware gang, the very attackers he was hired to negotiate against.
The sentencing closes out one of the more unsettling chapters in recent ransomware history: a case where the supposed defender was working both sides of the negotiating table.
A Trusted Insider Turned Traitor
When a business is hit by ransomware, hiring a professional negotiator is often one of the first calls made after law enforcement and legal counsel. These specialists are brought in precisely because victims are panicked, technically overwhelmed, and desperate to avoid further damage. A good negotiator is supposed to buy time, push back on inflated demands, and ultimately bring the ransom down to something the victim can survive paying, if payment happens at all.
Martino's role at DigitalMint put him inside that exact relationship. According to the underlying reporting, he used his access to client details, including information about the pressure victims were under and what they might be willing to pay, to help BlackCat's operators extract larger payouts rather than smaller ones. In effect, he flipped the negotiator's job on its head, working to maximize harm to the very clients who had hired him for protection.
As vpn.social previously reported, this arrangement depended entirely on the assumption that a negotiator's loyalty runs one direction. Martino's conduct broke that assumption in a way that has rattled the incident response industry.
How the Double-Agent Scheme Worked
The mechanics of the scheme were straightforward but damaging. By passing along confidential details, insurance information, negotiating strategy, or how much a victim organization could realistically afford, Martino gave BlackCat's attackers an unfair advantage in every negotiation he touched. Instead of ransom demands shrinking under his supposed advocacy, they were quietly engineered to grow.
This wasn't an isolated incident either. Related coverage of the case, including reporting on the broader BlackCat negotiator scheme, notes that Martino was not the only negotiator implicated in this kind of conduct tied to the same ransomware operation. A separate case involving a Florida-based negotiator convicted in a related extortion scheme underscores that this wasn't a one-off lapse of judgment by a single bad actor, but a pattern that exploited the structural trust built into the incident response industry.
The 70-month sentence reflects the seriousness with which federal prosecutors treated the betrayal: this wasn't simple negligence or a security failure, it was an insider deliberately working against the people who had put their faith, and their sensitive data, in his hands.
What This Means For You
For most people, this case might seem far removed from daily life, but it touches on something everyone should care about: how much trust we place in the intermediaries handling our most sensitive information during a crisis. Ransomware negotiators sit in a uniquely privileged position. They see internal financial details, security gaps, and communications that a victim organization would never want made public.
When that trust is abused, the fallout extends beyond the immediate victim companies. Employees, customers, and anyone whose personal data was held in those breached systems can end up paying the price twice: once through the original ransomware attack, and again through a negotiation process that was secretly working against them.
This case is a reminder that privacy and security in a ransomware incident don't end once a specialist is hired. Oversight, verification, and independent review of negotiator conduct matter just as much as the initial response to an attack itself.
Actionable Takeaways
If your organization ever finds itself negotiating with ransomware operators, or if you simply want to understand how these incidents unfold, a few lessons stand out from the Martino case:
- Vet incident response vendors carefully, and ask how they monitor their own staff for conflicts of interest during active negotiations.
- Request transparency around who has access to sensitive negotiation details, including financial limits and insurance information.
- Consider independent oversight or a second point of contact when large ransom demands are involved, rather than relying solely on one negotiator's account of the process.
- Stay informed about how ransomware negotiation actually works, since understanding the incentives at play helps organizations ask better questions before, not after, an attack happens.
The sentencing of a ransomware negotiator for betraying his own clients is an extreme case, but it highlights a simple truth: trust in a crisis has to be earned and verified, not assumed.




