Florida ransomware negotiator sentenced to 70 months for aiding BlackCat extortion scheme

Daily Feed
Florida ransomware negotiator sentenced to 70 months for aiding BlackCat extortion scheme

A Florida ransomware negotiator who was supposed to help victims cut their losses allegedly helped BlackCat/ALPHV squeeze them harder instead. The Justice Department says Angelo Martino was sentenced to 70 months in federal prison, and law enforcement has seized more than $10 million in assets tied to the scheme.

  • Angelo Martino was sentenced to 70 months.
  • The DOJ says he betrayed clients while working as a ransomware negotiator.
  • BlackCat/ALPHV was the ransomware crew involved.
  • Authorities say they have seized more than $10 million in assets.

According to the Department of Justice, Martino, 41, of Land O’Lakes, Florida, worked for a U.S.-based cyber incident response company. These firms help companies deal with ransomware attacks, including negotiation, recovery, and damage control. In this case, prosecutors say Martino used that access to do the opposite of his job description.

The DOJ says he began conspiring with BlackCat, also known as ALPHV, in April 2023 and helped extort five ransomware victims. Instead of protecting client information, he allegedly passed along confidential details about negotiating positions and strategy so the criminals could push for higher payments. That is not a “grey area.” That is a straight-up betrayal.

BlackCat/ALPHV was one of the more aggressive ransomware-as-a-service operations in recent years. In simple terms, ransomware-as-a-service means the malware crew builds and runs the extortion platform, while affiliates or partners carry out attacks and split the proceeds. It is organized crime with a SaaS subscription model, which is somehow even more annoying than it sounds.

The DOJ says Martino’s conduct was not limited to one slip-up. He allegedly helped criminal actors target additional victims across the United States between April 2023 and November 2023. Prosecutors also say he conspired with Kevin Martin and Ryan Goldberg in a scheme that extorted one victim for approximately $1.2 million in Bitcoin.

That detail matters because Bitcoin still sits at the center of a lot of ransomware economics. Criminals like it because it is liquid, widely recognized, and easy to move across borders. But Bitcoin is not some magical invisibility cloak. Its blockchain is public, and once investigators connect an address to a person or exchange account, the trail can become very useful evidence.

That is the part too many people miss. Bitcoin is traceable. Attribution is the hard part. To tie funds to a suspect, investigators usually need a mix of on-chain analysis, exchange records, device seizures, or good old-fashioned operational mistakes. Crypto can make criminals faster, but it does not make them untouchable.

The DOJ says more than $10 million in assets has been seized from Martino to date. Prosecutors described those assets as including digital currency, vehicles, a food truck, and a luxury fishing boat. The specific composition matters less than the larger point: the government is not just going after malware crews anymore. It is going after the facilitators, the insiders, and the people who grease the wheels.

That should make some people in cyber incident response very uncomfortable, and rightly so. If the person hired to negotiate with ransomware operators is secretly feeding the other side, the whole system becomes a rigged game. The victims think they are paying for expertise and damage control. Instead, they are paying a criminal middleman to sharpen the ransom knife.

There is also a useful distinction here between privacy and concealment. Some criminals prefer privacy-focused coins like Monero because they make transaction details harder to follow than transparent chains such as Bitcoin. That does not mean Monero is some kind of perfect criminal shield. It just makes tracing harder. In practice, seizures usually come from a combination of blockchain tracing, exchange cooperation, and plain human sloppiness, which, to be fair, remains one of the internet’s most reliable features.

The bigger lesson is not “crypto bad” or “blockchain solved crime.” It is more basic than that. Extortion depends on money, yes, but it also depends on trust, insider access, and the ability to exploit fear under pressure. When a negotiator allegedly flips sides, the damage multiplies fast.

The Justice Department has increasingly treated ransomware as a serious financial and national security threat, not just a tech problem. That means the net is widening. The government is not only chasing the hackers who deploy the malware; it is also targeting the people who help them cash out, calculate pressure points, and keep the racket running.

Martino’s 70-month sentence makes clear that this kind of insider conduct is not being treated as a minor lapse in judgment. It is being treated as part of the criminal machine itself. And that is exactly how it should be.

Key questions and takeaways

  • What did Angelo Martino do?
    The DOJ says he abused his role as a ransomware negotiator by helping BlackCat/ALPHV extort victims and by sharing confidential client negotiating information.

  • How long was he sentenced to prison?
    He was sentenced to 70 months in federal prison.

  • How much did authorities seize?
    Law enforcement says it has seized more than $10 million in assets tied to Martino.

  • Why does Bitcoin show up in a ransomware case?
    Bitcoin is widely used for ransom payments because it is liquid and easy to move. It can still be traced on-chain, but investigators usually need additional evidence to connect wallets to real people.

  • Is crypto the real problem here?
    No. The crime is extortion and insider betrayal. Crypto is just the payment rail, not the root cause.

  • Why does this case matter beyond one defendant?
    It shows that ransomware operations are not only about malware. Insider leaks, negotiated payments, and facilitators can be just as damaging as the code itself.

Further reading

A few related pieces on ransomware, seized crypto, and the darker side of digital finance.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog