A Trusted Insider Turned Against His Own Clients

When a company gets hit by ransomware, it typically calls in a negotiator, someone whose job is to communicate with attackers, assess the situation, and try to reduce the damage. That relationship depends entirely on trust. A former negotiator at incident response firm DigitalMint just showed what happens when that trust is broken.

Angelo Martino, 41, was sentenced to 70 months in federal prison for conspiring with the BlackCat ransomware group (also known as ALPHV) while working as a negotiator supposedly representing victims' interests. Instead of purely defending his clients, Martino used his position to feed information back to the very criminals his clients were trying to fend off, according to reporting from Help Net Security. The case, detailed further in our earlier coverage of the DigitalMint negotiator's 70-month sentence, highlights a threat that most ransomware victims never think to consider: the person hired to protect them.

Why Ransomware Negotiators Hold So Much Sensitive Data

Ransomware negotiators occupy a uniquely privileged position. To do their job effectively, they typically need access to details that most employees inside a victim organization never see: the scope of the breach, what data was stolen, how much cyber insurance coverage the company carries, and how much the company is realistically willing or able to pay. That information is gold to an attacker. Knowing a victim's insurance limits, for example, lets a ransomware group calibrate its ransom demand to squeeze out the maximum possible payment.

This is precisely what makes the Martino case notable from a privacy standpoint. It was not an external hacker breaking into a company's systems. It was an insider, someone brought in specifically because of the sensitive access his role required, allegedly using that access against the people who hired him. Incident response and negotiation firms exist because most organizations do not have the specialized skills to handle a ransomware crisis internally. That reliance on outside experts is reasonable and often necessary, but it also means victims are extending trust to a third party with minimal ability to independently verify that trust is warranted.

The broader ransomware ecosystem already forces victims to make difficult privacy tradeoffs. Paying a ransom does not guarantee stolen data will be deleted, and negotiating in good faith assumes the other side, and everyone advising you, is acting in good faith too. A case like this one undermines that assumption in a way that could make victims more hesitant to fully disclose information to the very professionals meant to help them, potentially slowing incident response at the moment it matters most.

What This Means For You

Most readers will never personally hire a ransomware negotiator, but the underlying lesson applies broadly: third-party vendors with access to your sensitive data are only as trustworthy as the weakest link inside that vendor's organization. Whether it is a law firm, an incident response contractor, a cloud provider, or any company handling your personal or financial information, the security of that relationship depends on internal controls you cannot see from the outside.

For businesses, this case is a reminder to ask hard questions before and during a ransomware incident. Who at the negotiating firm has access to insurance details and payment authority? Are there internal controls preventing a single employee from communicating directly with threat actors without oversight? Are conversations logged and reviewed? These are not questions most companies think to ask in the middle of a crisis, but they should be part of due diligence before a breach ever happens, not after.

For individuals, the takeaway is more indirect but still relevant. When a company you do business with suffers a ransomware attack, the handling of that incident, including who has access to your compromised data during negotiations, is largely out of your control. That is one more reason to minimize how much sensitive personal data you share with any single organization in the first place, and to use tools like password managers and multi-factor authentication so a single breach cannot cascade into broader account compromise.

Takeaways for Staying Ahead of Insider Risk

This sentencing sends a clear signal that insider betrayal during a ransomware response carries serious legal consequences, but prevention matters more than punishment after the fact. If your organization works with incident response or negotiation firms, insist on documented access controls, independent oversight of negotiations, and clear contractual accountability. If you are an individual affected by a breach at a company you trust, treat notifications seriously, change reused passwords, and monitor accounts tied to that organization.

The Martino case will likely be cited for years as a cautionary example in the ransomware negotiator field. For everyone else, it is a useful reminder that trust in a crisis has to be earned and verified, not assumed.