A Trusted Insider Turned Accomplice
When a company falls victim to ransomware, it often turns to a specialized negotiator to handle the delicate, high-stakes conversation with the attackers. That's exactly the role Angelo Martino, 41, played at DigitalMint, a firm that helps organizations navigate ransomware incidents and negotiate payments on their behalf. Martino was brought in during active breach cases, sitting on the side of the table meant to protect victims.
Instead, according to court records, Martino was secretly working with affiliates of the BlackCat (also known as ALPHV) ransomware group, one of the more notorious extortion operations of recent years. Rather than defending his clients' interests, he allegedly fed the attackers confidential information from inside the negotiations he was supposed to be conducting on the victims' behalf. That inside knowledge reportedly helped the gang extract larger payments, with reports indicating the scheme contributed to roughly $75 million squeezed from victim organizations across multiple cases. Martino pleaded guilty and was sentenced to 70 months in federal prison.
How the Scheme Undermined Ransomware Negotiation
Ransomware negotiation exists because companies facing an attack often lack the specialized expertise to communicate with criminal groups, assess the credibility of threats, or determine whether paying a ransom is even advisable. Firms like DigitalMint are supposed to act as a firewall, using their experience to reduce demands, verify data recovery capabilities, and keep victims from being exploited twice.
Martino's case flips that model on its head. By leaking sensitive details from active negotiations, including internal client information, financial thresholds, and the state of a victim's leverage, he effectively handed BlackCat affiliates the playbook they needed to push for maximum payouts. That is a profound breach of trust, not just between Martino and his employer, but between his employer and every client who assumed their crisis response team was working exclusively for them.
This kind of insider collusion is particularly damaging because ransomware victims are already in a vulnerable position. They are often under pressure to make fast decisions about sensitive data, operational downtime, and regulatory exposure. Cases like Instructure's paid ransom after the Canvas breach show how organizations sometimes conclude that payment is the least damaging option available. When the negotiator handling that decision has a financial incentive to work against the victim, the entire calculation used to justify a payment becomes compromised.
Why This Case Raises Bigger Privacy Concerns for Businesses
The privacy implications here extend well beyond the immediate financial losses. Ransomware negotiations typically involve sharing highly sensitive material: the scope of stolen data, internal security assessments, executive communications, and details about what a company is willing to pay. Victims share this information under the assumption that it stays within a tightly controlled circle of trusted responders.
Martino's actions demonstrate that the incident response ecosystem itself can become a point of failure. Even organizations that do everything right after a breach, hiring reputable firms, following recommended protocols, and cooperating with law enforcement, can still have their data and negotiating position undermined from within. This mirrors the pressure tactics seen in other high-profile extortion campaigns, such as the escalating tactics used when ShinyHunters defaced school portals during its Canvas ransom campaign, where attackers leaned on public embarrassment and data leverage to force a resolution.
What This Means For You
If your organization ever finds itself negotiating with a ransomware group, this case is a reminder that the vendor selection process deserves as much scrutiny as your cybersecurity tools. Ask potential negotiation firms about internal controls, employee vetting, and how client data is segmented and monitored during an active case. Request clarity on who has access to negotiation details and whether any individual has unchecked authority over communications with attackers.
For individuals and smaller businesses without the resources for extensive vendor due diligence, the takeaway is broader: minimize the sensitive data that could be exposed in the first place. Strong backup practices, network segmentation, and limiting the amount of personal or financial data stored in easily accessible systems all reduce how much leverage a ransomware group, or a compromised insider, can hold over you.
Key Takeaways
- Vet incident response and negotiation firms with the same rigor you'd apply to any vendor handling sensitive data.
- Ask how negotiation firms internally monitor and audit employee access during active ransomware cases.
- Reduce the volume of sensitive data stored in systems vulnerable to compromise, since less exposure means less leverage for attackers or insiders.
- Treat ransomware negotiation as a decision requiring its own oversight, not a black box handled entirely by a third party.
The Martino case is a rare but serious example of insider betrayal within the ransomware response industry. It doesn't mean negotiation firms can't be trusted broadly, but it does underscore that trust should be verified, not assumed, especially when a company's most sensitive breach details are on the line.




