ThreatPaper
RansomwareInsider ThreatExtortion & BlackmailHigh

BlackCat Insider Case: Ransomware Negotiators Who Attacked and Betrayed Their Own Clients

By Sethu Satheesh · 3 Sept 2026 · 18 min read

Threat Actor: Ryan Goldberg, Kevin Martin, Angelo Martino (convicted); ALPHV/BlackCat affiliate programme · Target: US medical, pharmaceutical, engineering and manufacturing firms — and the ransomware victims one defendant was retained to represent

Source: www.justice.gov


Executive Summary

Between April and December 2023, three men who worked in the cybersecurity incident response industry deployed ALPHV/BlackCat ransomware against US companies, paying the ransomware operators 20% of proceeds for use of the platform and keeping 80%.

That is the headline, and it is the less serious half of the case.

Angelo Martino, 41, of Land O'Lakes, Florida, worked as a ransomware negotiator at a US-based incident response company — the professional a company hires after an attack to deal with the attackers on its behalf. According to the Department of Justice, beginning in April 2023 he provided BlackCat attackers with "confidential information about the negotiating position and strategy of his company's clients" without authorisation. That information included victims' insurance policy limits and internal negotiation positions, which the DOJ states "assisted the ransomware actors and maximized the ransoms that the victims were required to pay."

He was negotiating for five different ransomware victims while doing it.

Insurance policy limits are the single most valuable fact in a ransomware negotiation. They tell the attacker precisely how much the victim is able to pay, which converts a negotiation into a calculation. A victim who believed they had a professional arguing their side was instead facing an adversary who had been handed their ceiling.

The two men sentenced alongside him held comparable positions. Ryan Goldberg, 40, of Georgia, was a manager of incident response at Sygnia. Kevin Martin, 36, of Texas, was a ransomware negotiator at DigitalMint. Both pleaded guilty in December 2025 to conspiracy to obstruct, delay or affect commerce by extortion, and on 30 April 2026 each received four years in prison. Martino pleaded guilty in April 2026; his sentencing was set for 9 July 2026, with a maximum of 20 years. Assets worth $10 million were seized from him — digital currency, vehicles, a food truck, and a luxury fishing boat.

Reported victims include a Tampa medical device manufacturer, a Maryland pharmaceutical company, a California doctor's office, a California engineering firm and a Virginia drone manufacturer. One victim was extorted for approximately $1.2 million in Bitcoin.

This paper is shaped differently from most in this archive. Usually the Legal and Regulatory Response section records an absence — no advisory, no charges, no consequence. Here the legal record is the primary source, and the technical record is the thin part: no indicators of compromise were published, because this was a prosecution rather than a malware analysis. What can be established with unusual confidence is who did it, what they were charged with, what they admitted, and what it cost them.

Verification of Claims

Claim: Three men employed in the cybersecurity incident response industry deployed ALPHV/BlackCat ransomware against US victims. → Verified — Established by guilty plea and sentencing. The Department of Justice names Ryan Goldberg, 40, of Georgia, a manager of incident response at Sygnia; Kevin Martin, 36, of Texas, a ransomware negotiator at DigitalMint; and Angelo Martino, 41, of Land O'Lakes, Florida, a ransomware negotiator at a US-based cyber incident response company.

Claim: One defendant passed his own clients' confidential negotiating positions to the attackers. → Verified — The DOJ states that Martino "provided BlackCat attackers with confidential information about the negotiating position and strategy of his company's clients," including insurance policy limits and internal negotiation positions, which "assisted the ransomware actors and maximized the ransoms that the victims were required to pay." He pleaded guilty.

Claim: The defendants paid ALPHV 20% of proceeds. → Verified — The DOJ states the defendants split 80% of proceeds while paying ALPHV administrators 20%, which matches the affiliate model documented for the platform generally.

Claim: The offences ran from May to November 2023. → Unverified — Three different windows appear across sources, including two DOJ releases. The sentencing announcement of 30 April 2026 gives "April 2023 to December 2023." The Martino plea announcement of 20 April 2026 gives "April to November 2023" for the deployment conspiracy specifically, while dating his negotiation betrayal to "beginning April 2023." Secondary reporting gives May to November 2023. The DOJ's own two releases do not agree, most likely because they describe overlapping but distinct conduct, and this paper uses the widest documented window rather than choosing one.

Claim: Five organisations were the victims of this case. → Unverified, and probably an undercount — Reporting identifies five victim organisations of the ransomware deployments. Separately, the DOJ states Martino was working as a negotiator on behalf of five different ransomware victims whose positions he compromised. These are two distinct groups of five, and coverage that reports "five victims" appears to describe only the first. The second group were harmed without being attacked by these defendants at all — their attackers were other BlackCat actors, and what these defendants did was ensure they paid more.

Claim: A victim paid $1.27 million. → Partially verified — The DOJ states one victim was extorted for "approximately $1.2 million in Bitcoin." Secondary reporting gives $1.27 million, attributes it to the Tampa medical device manufacturer, and states the original demand was $10 million in May 2023. The approximate DOJ figure and the precise press figure are consistent; the attribution and the demand come from reporting rather than the released DOJ statements.

Claim: Sygnia or DigitalMint were complicit. → False — Neither company has been charged and both are described as cooperating. Sygnia's chief executive Guy Segal confirmed Goldberg had been an employee and was terminated once the company learned of his alleged involvement, declining further comment during the FBI investigation. DigitalMint's president Marc Grens stated Martin was employed at the time but was acting entirely outside the scope of his employment, and that the company is cooperating with the government. The DOJ describes the conduct as the defendants abusing their roles, not as corporate conduct.

Claim: Technical indicators of compromise were published. → False — None have been. This is a prosecution record, not an incident report. There is no malware analysis, no infrastructure list and no victim-side forensic detail in the public record, which is a real limitation on what defenders can operationalise from it.

Timeline

Date Actor Event Source
2023-04 Martino Begins providing BlackCat attackers with clients' confidential negotiating positions and insurance limits DOJ
2023-04 → 2023-12 Goldberg, Martin, Martino Deploy ALPHV/BlackCat against multiple US victims as affiliates, paying 20% to the operators DOJ
2023-05 Tampa medical device manufacturer extorted; approximately $1.2M paid in Bitcoin against a reported $10M demand DOJ / reporting
2025-11 DOJ Indictment unsealed, Southern District of Florida DOJ
2025-12 Goldberg, Martin Plead guilty to conspiracy to obstruct, delay or affect commerce by extortion DOJ
2026-04-20 Martino Pleads guilty; $10M in assets seized including digital currency, vehicles, a food truck and a luxury fishing boat DOJ
2026-04-30 Court Goldberg and Martin each sentenced to four years in prison DOJ
2026-07-09 Court Martino sentencing scheduled; maximum 20 years DOJ

Attack Anatomy

The Position — Access Without Intrusion

The defendants did not need to compromise anything to obtain their advantage. They were given it.

Incident response is a profession built on privileged access at the worst moment in an organisation's life. A responder sees the network as it actually is rather than as documented, learns which controls failed, reads the internal correspondence about what the company can afford, and is trusted precisely because the client has no capacity left to verify anything. A ransomware negotiator sits closer still: they hold the victim's walk-away number, their insurance position, and their instructions.

That is the access this case turns on. Two of the three were negotiators; the third managed incident response.

Technique mapping (this paper's assessment): T1078 Valid Accounts is inapposite — no account was misused. The closest published framing is insider abuse of authorised access; ATT&CK has no technique for a trusted third party disclosing a client's negotiating position, which is itself a gap.

The Deployment — An Affiliate Arrangement

For the attacks, the three operated as ordinary ALPHV/BlackCat affiliates. The platform supplies the ransomware, the leak site and the extortion infrastructure; the affiliate supplies the intrusion and takes the majority share. Here the split was 80% to the defendants, 20% to the ALPHV administrators.

That arrangement is why ransomware scales. The operators never touch a victim network, and the affiliates never build tooling. What this case adds is the observation that the affiliate pool is not confined to career criminals — it recruited from the profession that responds to the attacks, and the DOJ's framing is explicit that the skills were the qualification. Assistant Attorney General A. Tysen Duva: they "used their high-level cyber skills to feed greed."

The public record does not describe how the victim networks were breached. No initial access vector, no tooling, no dwell time. That absence is characteristic of prosecutions, which establish conduct rather than methodology.

T1486 Data Encrypted for Impact; T1657 Financial Theft.

The Betrayal — Selling the Negotiation

Martino's separate conduct is the part with no real precedent in this archive.

A ransomware negotiation is an information asymmetry contest. The attacker knows what they took and how badly they have hurt the victim. The victim knows what they can pay, what their insurance covers, what their board will tolerate, and how long they can survive without recovery. The negotiator's job is to manage that asymmetry on the victim's behalf — to avoid revealing the ceiling while establishing the floor.

Handing the attacker the insurance policy limit collapses the exercise entirely. The attacker no longer needs to probe for the maximum, because they have been told it. The DOJ's language is precise about the effect: the information "assisted the ransomware actors and maximized the ransoms that the victims were required to pay."

Five clients were represented by him during this period. Their attackers were, as far as the record shows, other BlackCat actors — not the defendants. These victims were not hacked by the three men. They were simply made to pay more, by the person they had hired to prevent exactly that.

T1213 Data from Information Repositories is a poor fit; the disclosure was of professional work product, not data exfiltrated from a system.

Detection — A Prosecution, Not an Alert

How the investigation began is not in the public record. What is known is that it ended with the FBI's Miami Field Office leading, supported by the US Secret Service and the Policía de Investigación of Mexico City International Airport — an unusual partner, and one that suggests an arrest or interception at that airport.

FBI Assistant Director Brett Leatherman stated that "the FBI tracked him through 10 countries."

Nothing indicates the employers detected this. Sygnia terminated Goldberg after learning of his alleged involvement, which is a response to an external disclosure rather than to internal detection.

Threat Actor Profile

Unusually for this archive, the actors are named, convicted and sentenced, so this section states facts rather than assessments.

Ryan Goldberg, 40, of Georgia. Manager of incident response at Sygnia. Pleaded guilty December 2025 to conspiracy to obstruct, delay or affect commerce by extortion. Sentenced to four years, 30 April 2026.

Kevin Martin, 36, of Texas. Ransomware negotiator at DigitalMint. Same charge, same plea, same sentence.

Angelo Martino, 41, of Land O'Lakes, Florida. Ransomware negotiator at a US-based incident response company. Pleaded guilty April 2026 to one count of the same conspiracy. Sentencing set for 9 July 2026, maximum 20 years. $10 million in assets seized, including digital currency, vehicles, a food truck and a luxury fishing boat.

ALPHV/BlackCat operated the platform and took 20% of proceeds. The operators are not defendants here; this is a case about affiliates.

Two things are worth drawing out.

The skills were the qualification, not an aggravating detail. The DOJ's framing throughout is that these men were effective because of what the profession had taught them. US Attorney Jason A. Reding Quiñones: "These defendants exploited specialized cybersecurity knowledge not to protect victims, but to extort them."

The domestic point is made deliberately. Reding Quiñones again: "Ransomware is not just a foreign threat — it can come from inside our own borders." Leatherman made the same point on Martino's plea. Both are pushing against a default assumption in this field that ransomware means Russia, and the record here does not support that assumption.

Technical Indicators

There are none published, and that is a finding rather than an omission from this paper.

No indicators of compromise, malware hashes, infrastructure, initial access vectors or victim-side forensics have been released. The public record is a prosecution: it establishes who did what and what they admitted, and it does not establish how they got in.

The consequence is that a defender cannot hunt for this. What can be acted on is organisational rather than technical, and that is set out under Lessons.

The only operational artefacts in the record are the charge and the money:

Charge         Conspiracy to obstruct, delay or affect commerce by extortion
Affiliate cut  80% defendants / 20% ALPHV administrators
Known payment  ~$1.2 million in Bitcoin (one victim)
Seized         $10 million from Martino — digital currency, vehicles,
               a food truck, a luxury fishing boat
Agencies       FBI Miami (lead) · US Secret Service ·
               Policía de Investigación, Mexico City International Airport

This is the section that in most papers in this archive records an absence. Here it is the substance of the case.

Prosecution. Brought in the Southern District of Florida. All three defendants pleaded guilty to conspiracy to obstruct, delay or affect commerce by extortion — the Hobbs Act. Goldberg and Martin were sentenced to four years each on 30 April 2026. Martino's sentencing was set for 9 July 2026 with a statutory maximum of 20 years.

Asset forfeiture. $10 million was seized from Martino, including digital currency, vehicles, a food truck and a luxury fishing boat. Forfeiture in the other two cases is not specified in the released statements.

Investigation. Led by the FBI's Miami Field Office with the US Secret Service and the Policía de Investigación of Mexico City International Airport.

No regulatory action against the employers. Neither Sygnia nor DigitalMint has been charged, and both are described as cooperating. There is no indication of a licensing, certification or regulatory consequence for either — which is unremarkable, because the incident response industry has no licensing regime to invoke. There is no register of ransomware negotiators, no bar to be struck from, and no obligation to disclose that an employee has been charged with betraying clients.

No breach notification obligation is engaged by the negotiation betrayal. Martino's five negotiation clients suffered a financial harm caused by disclosure of their own confidential position. No data protection regime treats that as a reportable breach, and the harm is not one any existing framework measures.

Four years for conduct that included attacking healthcare and defence manufacturers, and separately selling out five ransomware victims mid-negotiation, is a sentence readers can weigh for themselves. The maximum available on the conspiracy count was 20 years.

Impact Assessment

The direct financial harm is partly quantified and mostly not. One victim paid approximately $1.2 million. Demands reportedly ranged from $300,000 to $10 million across the victims. What Martino's negotiation clients paid in excess of what they would have paid is the harm specific to his conduct, and it is unquantified and probably unquantifiable — you cannot measure a counterfactual negotiation.

The victims chosen matter. A medical device manufacturer, a doctor's office, a pharmaceutical company, an engineering firm and a drone manufacturer. Healthcare ransomware has documented consequences for patient care, and the DOJ noted the harm to firms "providing med and engineering services."

The damage to the response industry is the durable part. Ransomware negotiation depends entirely on the victim trusting a stranger with the two facts they most need to conceal. That trust is not contractual — it is professional, and it has now been shown to fail in the most direct way possible. Every victim who reads this case will ask a question they had no reason to ask before, and there is currently no good answer available to the firms they will ask it of.

Cyber insurance is implicated more than it appears. The information leaked was the policy limit. That figure exists because insurance exists, it is knowable to the negotiator because the negotiation requires it, and it functions as a price ceiling that becomes a price floor the moment the attacker learns it. This is a structural problem with how ransomware, insurance and negotiation interact, and this case is the first prosecution to expose it that clearly.

The domestic insider vector is under-modelled. Most ransomware threat models place the adversary outside the organisation and outside the country. Here the adversary was a US-based contractor with authorised access, recruited into an affiliate programme.

Lessons and Defensive Recommendations

For Organisations Retaining Incident Response or Negotiation Services

Ask what your provider does about insider risk before you need them. Specifically: are negotiators supervised, is negotiation correspondence reviewed by a second person, is access to your insurance position restricted to those who need it, and what background verification is performed. These are answerable questions and almost nobody asks them, because they are asked at a moment of crisis when scrutiny is impossible.

Retain and vet your responder in advance. The worst time to evaluate a firm is while encrypted. A pre-agreed relationship is the only realistic point at which due diligence can happen.

Compartmentalise your insurance position. Your negotiator needs an authorised ceiling. They do not necessarily need your policy documents. Giving them a mandate rather than a limit changes what a leak discloses.

Require a second pair of eyes on negotiation. A single individual holding sole contact with the attacker on your behalf is a single point of failure, and this case is what that failure looks like.

For Incident Response and Negotiation Firms

Assume this question is now being asked about you, and be able to answer it. What supervision exists over negotiators? Who else reads the correspondence? What separates a negotiator from a client's most sensitive commercial facts?

Dual control over negotiation is the obvious structural answer, and it is inconvenient in exactly the way controls usually are.

Monitor for the tell that would have surfaced this: contact between staff and known ransomware infrastructure, and unexplained wealth. Neither is comfortable to implement and both are proportionate to the access the role carries.

For Security Teams and Investigators

Add trusted third parties to your insider threat model. Contractors, responders and negotiators hold access that employees frequently do not, under conditions where oversight is weakest.

In a post-incident review, ask whether the negotiation ran as expected. A demand that anchored suspiciously close to a policy limit is not proof of anything, but it is now a question worth asking.

For Policymakers and Leadership

The response industry is unlicensed and unregistered. There is no professional body to sanction, no register to be removed from, and no obligation on a firm to disclose that an employee has been charged. Whether that should change is a policy question, and this case is the strongest available argument that it is worth asking.

Note where the adversary was. Not overseas, not state-sponsored, not a foreign affiliate — a US contractor with legitimate access, recruited by a platform that takes 20%. A threat model that starts at the perimeter does not contain this.

Sources

Original Incident Report →

Related Research

LockBit, BlackSuit and Play didn't run their own servers. They rented them from a company in St Petersburg that answered no abuse reports and no takedown requests, and billed like any other host.

RansomwareFinancial FraudBotnet & DDoS

The ALPHV/BlackCat ransomware group compromised Change Healthcare, the largest US healthcare claims clearinghouse, causing a nationwide outage of pharmacy, medical claims, and payment processing affecting hundreds of thousands of providers, pharmacies, and patients — the most significant cyberattack on US healthcare infrastructure to date.

RansomwareFinancial Fraud

A market that took only Monero ran for five years and €330 million. The playbook that broke Silk Road and AlphaBay did not apply — and the authorities who dismantled it have not said what did.

Darknet & Illicit MarketsCryptocurrency & Web3