Florida resident Angelo Martino received a 70‑month prison term for providing confidential negotiation data to the BlackCat/Alphv ransomware group. This marks the third case where a security professional was penalised for colluding with cybercriminals.

Key Takeaways

  • Angelo Martino sentenced to 70 months in prison
  • Martino supplied confidential client negotiation details to BlackCat/Alphv
  • US offers $10 million reward for information leading to key group members

Florida‑based Angelo Martino, a 41‑year‑old cybersecurity specialist, was sentenced on Thursday to 70 months after pleading guilty in April. He was found to have handed the BlackCat/Alphv ransomware operators confidential information about his employer’s clients’ negotiation positions, enabling the gang to extract higher ransoms.

Context and Uniqueness of the Case

Martino joins Kevin Martin of Texas and Ryan Goldberg of Georgia as the third security professional charged by U.S. authorities for abusing their roles as ransomware negotiators. While ostensibly tasked with helping victims, all three allegedly tipped off attackers in exchange for a share of the payout.

Collaboration with BlackCat/Alphv

Investigators say Martino began cooperating with the ransomware operators in April 2023, assisting them in extorting at least five victims. The Department of Justice (DOJ) stated that BlackCat paid Martino to “provide confidential information about the negotiating position and strategy of his employer’s clients and enable the ransomware actors to maximize the ransoms paid by the victims.”

Asset Seizure and Future Obligations

Authorities seized approximately $10 million in assets, including cryptocurrency, vehicles, a food‑truck, and a fishing boat. Martino will also be required to pay restitution, the amount of which will be set at a September hearing.

Broader Impact and Government Response

Between 2021 and December 2023, BlackCat ransomware targeted over 1,000 organizations before the criminal enterprise was disrupted. Months later the group executed an “exit scam,” extracting a $22 million ransom from a victim. The U.S. government has posted a $10 million bounty for information leading to the identification of the gang’s core members, underscoring the high‑stakes nature of the investigation.

This case highlights the evolving ethical landscape for security professionals who negotiate ransomware attacks. It sends a clear signal that collusion with cyber‑criminals will attract severe penalties, reinforcing the need for stricter oversight and robust internal controls within cybersecurity firms.