A Florida man who worked as a ransomware negotiator for a U.S. cybersecurity company has been sentenced to more than five years in prison after being convicted of conspiring with hackers to deploy ransomware against American businesses.
The U.S. Department of Justice confirmed on July 10, 2026 that Angelo Martino had been sentenced, and announced the seizure of more than $10 million in cryptocurrency and assets — including a food truck and a luxury fishing boat — allegedly purchased with proceeds from the attacks.
Martino is the third person jailed in connection with the scheme. Cybersecurity professionals Kevin Martin and Ryan Goldberg were previously incarcerated for their roles. Prosecutors say the three worked together throughout 2023 to deploy the BlackCat ransomware against U.S. companies. In one attack, the group extorted a victim for approximately $1.2 million, which they split three ways after laundering the funds.
BlackCat, also known as ALPHV, operates as a ransomware-as-a-service platform, allowing independent hackers — called affiliates — to rent access to its file-encrypting malware in exchange for a share of the ransom proceeds. The group gained wider attention after its ransomware was used in a February 2024 attack on health technology company Change Healthcare, which resulted in the theft of sensitive medical and billing data belonging to more than 192 million Americans. The affiliates responsible for that breach were never identified.
The case is described as a rare instance of security professionals exploiting their positions to assist criminal hackers. It highlights a vulnerability within the ransomware response industry, where negotiators — employed to reduce ransom demands on behalf of victim companies — had direct access to both victims and attackers. U.S. authorities have long advised companies against paying ransoms, though some do so to prevent the public release of stolen customer data.
Source: TechCrunch