29 days ago
TechCrunch Jul 10, 2026

Florida ransomware negotiator convicted for helping ransomware gang extort US companies

Angelo Martino, a ransomware negotiator from Florida, has been sentenced to over five years in federal prison for conspiring with hackers to carry out ransomware attacks against U.S. companies. While working as a negotiator for a cybersecurity firm, Martino secretly collaborated with a notorious ransomware gang to deploy BlackCat ransomware across various American organizations during 2023. The Department of Justice revealed that authorities seized more than $10 million in cryptocurrency and assets linked to Martino, including a food truck and a luxury fishing boat purchased with stolen funds.

Martino is the third individual tied to this criminal operation to be imprisoned, joining cybersecurity professionals Kevin Martin and Ryan Goldberg who were previously convicted for similar offenses. Prosecutors described how the trio orchestrated ransomware extortion schemes where they would demand and collect ransom payments on behalf of the hackers. In one case, a victim company paid approximately $1.2 million, which the conspirators then laundered and split among themselves.

This case exposes a rare and troubling breach of trust where security experts actively aided malicious actors rather than defending victims. Although government agencies generally advise organizations to refuse ransom payments to prevent fueling cybercrime, many companies continue to pay attackers to protect sensitive data and avoid disruptions. The extortion market has even given rise to a specialized insurance sector in the U.S., with some providers offering ransomware negotiators to lower ransom demands, though this incident highlights the risks if such negotiators turn rogue.

The BlackCat group, also known as ALPHV, operates as a ransomware-as-a-service platform, allowing hackers to rent its malware in exchange for a cut of extortion proceeds. The gang has been linked to high-profile intrusions, including a massive 2024 attack exposing medical and billing records of nearly 200 million Americans. Although the affiliates responsible for that breach remain unidentified, the BlackCat ransomware operation continues to pose a significant threat to U.S. businesses and critical infrastructure.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.