{"id":62815,"date":"2026-07-10T20:54:39","date_gmt":"2026-07-11T00:54:39","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62815"},"modified":"2026-07-10T20:54:39","modified_gmt":"2026-07-11T00:54:39","slug":"ransomware-negotiator-sentenced","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/ransomware-negotiator-sentenced\/","title":{"rendered":"Ransomware negotiator sentenced to 5 years for extorting US companies"},"content":{"rendered":"<p>Florida man Angelo Martino, a ransomware negotiator employed by a U.S. <a href=\"https:\/\/overcentral.com\/en\/conan-obrien-hosts-ai-cybersecurity-training-videos\/\" title=\"Conan O&apos;Brien Hosts Educational Videos for AI Cybersecurity Company\" data-iacss-internal=\"1\">cybersecurity company<\/a>, has been sentenced to more than five years in prison for conspiring with hackers to deploy ransomware against the very organizations he was paid to protect. The <a href=\"https:\/\/www.justice.gov\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">U.S. Department of Justice<\/a> confirmed the sentence on Thursday, revealing that authorities seized over <a href=\"https:\/\/overcentral.com\/en\/us-10-million-russian-hackers-signal-whatsapp\/\" title=\"US Offers $10 Million for Russian Group\u2019s Signal and WhatsApp Hacks\" data-iacss-internal=\"1\">$10 million<\/a> worth of cryptocurrency and assets linked to the scheme, including a food truck and a luxury fishing boat purchased with proceeds from the hacks.<\/p>\n<h2>How the Insider Ransomware Scheme Operated<\/h2>\n<p>Martino is the third individual sentenced in this conspiracy, following the incarceration of cybersecurity professionals Kevin Martin and Ryan Goldberg. Prosecutors determined that the trio worked together throughout 2023 to deploy the BlackCat ransomware against U.S. companies while holding legitimate positions in the cybersecurity industry. In one successful attack, the group extorted a company for approximately $1.2 million, laundering the funds before splitting them three ways.<\/p>\n<p>The case highlights a rare but deeply concerning scenario: security professionals using their inside knowledge and access to facilitate the very attacks they were hired to prevent. Governments have long advised ransomware victims not to pay ransoms, arguing that doing so fuels the criminal ecosystem. Despite this guidance, some companies continue to pay in attempts to prevent sensitive customer data from being leaked, a dynamic that has fueled an entire insurance sub-sector dedicated to ransomware response and negotiation.<\/p>\n<h2>Understanding the BlackCat Ransomware Threat<\/h2>\n<p>BlackCat, also known as ALPHV, operates as a ransomware-as-a-service platform. This model allows independent hackers, referred to as affiliates, to rent access to the group&#8217;s file-encrypting malware in exchange for a percentage of any <a href=\"https:\/\/overcentral.com\/en\/inc-ransomware-healthcare-target-ransom\/\" title=\"INC Ransomware Exploits Healthcare to Force Ransom Payments\" data-iacss-internal=\"1\">ransom payments<\/a>. The decentralized structure of such operations makes attribution and prosecution particularly challenging for law enforcement.<\/p>\n<p>The same ransomware strain was infamously used to steal highly sensitive medical and billing data belonging to more than 192 million people in the United States during a February 2024 attack on health technology giant Change Healthcare. The affiliate hackers responsible for that specific breach were never publicly identified, underscoring the persistent risk posed by the ransomware-as-a-service ecosystem.<\/p>\n<h2>What This Case Means for Ransomware Negotiation<\/h2>\n<p>This prosecution sends a clear signal that the U.S. Department of Justice is actively investigating and prosecuting insiders within the cybersecurity industry who abuse their positions. For companies that employ ransomware negotiators, this case underscores the importance of rigorous background checks, continuous monitoring, and strict separation of duties. The scheme succeeded in part because the individuals involved had legitimate access to sensitive information about victims and the negotiation process, which they exploited for personal gain.<\/p>\n<h2>What Affected Organizations and Individuals Should Do Now<\/h2>\n<p>Any organization that has engaged external cybersecurity or ransomware negotiation services should review those relationships and ensure that appropriate oversight mechanisms are in place. For individuals concerned about the broader ransomware threat, the following steps are critical for reducing risk:<\/p>\n<ul>\n<li>Enable multi-factor authentication on all accounts, especially those with access to sensitive data.<\/li>\n<li>Maintain offline, encrypted backups of critical data and test restoration procedures regularly.<\/li>\n<li>Implement a reputable endpoint protection solution with behavioral analysis capabilities to detect and block ransomware before encryption occurs.<\/li>\n<li>Use a reliable virtual private network with a verified no-logs policy when accessing corporate resources from untrusted networks.<\/li>\n<li>Adopt a zero-trust security model that limits lateral movement within your network, reducing the damage a single compromised credential can cause.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Florida man Angelo Martino, a ransomware negotiator employed by a U.S. cybersecurity company, has been sentenced to more than five years in prison for conspiring with hackers to deploy ransomware against the very organizations he was paid to protect. The U.S. Department of Justice confirmed the sentence on Thursday, revealing that authorities seized over $10 [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84260,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62815.png","fifu_image_alt":"Ransomware negotiator sentenced to 5 years for extorting US companies","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62815","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62815.png","fifu_image_alt":"Ransomware negotiator sentenced to 5 years for extorting US companies","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62815","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62815"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62815\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84260"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}