INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
US Charges Another Ransomware Negotiator Linked to BlackCat Attacks
| 2026-03-12 11:31 HIGH LOW RANSOMWARE & EXTORTION DATA BREACH LAW ENFORCEMENT
Executive Summary
AI-generated
On March 10, 2026, Angelo Martino surrendered to the U.S. Marshals after being charged with one count of conspiracy to interfere with interstate commerce by extortion. The charges stem from an insider scheme in which ransomware negotiators secretly partnered with the BlackCat (ALPHV) ransomware operation. As a former DigitalMint employee, Martino shared confidential information regarding ongoing negotiations with BlackCat operators while working as a ransomware negotiator for the company between April 2023 and April 2025. The scheme allegedly involved at least five U.S. organizations, including a nonprofit that paid $26,793,000 in ransom and a financial services firm that paid $25,660,000, with other targets across various industries such as medical facilities, law firms, school districts, and financial services companies. Martino was previously identified alongside accomplices Kevin Tyler Martin and Ryan Goldberg, who pleaded guilty to their roles in the scheme.
Technical Mitigations AI-generated
• Block or hunt for indicators of BlackCat ransomware, such as the use of ALPHV (BlackCat) ransomware variants.
• Patch DigitalMint systems to prevent exploitation by former employees who shared confidential information with BlackCat operators.
• Use techniques like those described in The Red Report 2026 to detect and block new threats that use math to evade detection.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BlackCatBlackCatALPHVALPHV
Target & Sectors
Global Scope
financefinance
Incident Timeline
March 2022
The US charged another ransomware negotiator linked to BlackCat attacks, which were reportedly carried out by a cybercrime gang that collected at least $300 million from over 1,000 victims until September 2023.
Click on any entity below to view its context and source!
financial
$300 gang
In a separate advisory, the bureau also said the cybercrime gang
raked in at least $300 million in payments
from over 1,000 victims until September 2023.
victims
1,000 victims
In a separate advisory, the bureau also said the cybercrime gang
raked in at least $300 million in payments
from over 1,000 victims until September 2023.
October 2025
The US Department of Justice charged two individuals linked to the BlackCat ransomware group, alleging they operated as affiliates and demanded ransom payments from at least five U.S. organizations between October 2025.
Click on any entity below to view its context and source!
financial
$26,793,000 $ ransom
The list of victims included at least five U.S. organizations, among them a nonprofit that paid a $26,793,000 ransom and a financial services firm that paid $25,660,000.
financial
$25,660,000 firm
The list of victims included at least five U.S. organizations, among them a nonprofit that paid a $26,793,000 ransom and a financial services firm that paid $25,660,000.
Tactical Metrics
Metrics
financial
300,000,000
Gang
Click for context!
In a separate advisory, the bureau also said the cybercrime gang
raked in at least $300 million in payments
from over 1,000 victims until September 2023.
Metrics
victims
1,000
Victims
In a separate advisory, the bureau also said the cybercrime gang
raked in at least $300 million in payments
from over 1,000 victims until September 2023.
Metrics
financial
26,793,000
$ Ransom
The list of victims included at least five U.S. organizations, among them a nonprofit that paid a $26,793,000 ransom and a financial services firm that paid $25,660,000.
Metrics
financial
25,660,000
Firm
The list of victims included at least five U.S. organizations, among them a nonprofit that paid a $26,793,000 ransom and a financial services firm that paid $25,660,000.
Intelligence Sources
BleepingComputer
2026-03-12
US charges another ransomware negotiator linked to BlackCat attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:48
Comprehensive Tactical Telemetry
Highly Correlated Entities
8x
timeline
Temporal Reference
March 10
date
7x
organisation
Identified Entity
The U.S. Department of Justice
entity
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
malware
Malware Payload
BlackCat
tool
Contextual Telemetry
Context Block
13 METRICS
source region
Origin Country
United States
country
general metric
%
20
%
attribution
Attributing Entity
FBI
authority
general metric
Breaches
60
breaches
general metric
Conspirator
1
conspirator
financial
Gang
300,000,000
gang
victims
Victims
1,000
victims
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
general metric
Red Report
2,026
red report
financial
$ Ransom
26,793,000
$ ransom
financial
Firm
25,660,000
firm
general metric
Malicious Samples
1,100,000
malicious samples
general metric
Top Techniques
10
top techniques
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.