INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Former ransomware negotiator gets 4 years for BlackCat attacks
| 2026-07-10 08:17 HIGH HIGH RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
A former employee of cybersecurity incident response company DigitalMint, Angelo Martino, was sentenced to 70 months in prison for his role in targeting U.S. companies in BlackCat (ALPHV) ransomware attacks between April 2023 and April 2025. The FBI linked the BlackCat ransomware gang to more than 60 breaches between November 2021 and March 2022, with the cybercrime group collecting at least $300 million in ransom payments from over 1,000 victims through September 2023. Martino was directly involved in these attacks alongside accomplices Ryan Goldberg and Kevin Tyler Martin, who also received prison sentences for their roles. The attackers used BlackCat to demand ransom payments and threatened to leak stolen data before encrypting their systems, with the three former employees sharing confidential information about victims' insurance policy limits and negotiation positions to maximize extortion demands from at least five U.S. organizations.
Technical Mitigations AI-generated
• Use a 20% share reduction for ransomware admins to limit their access and control.
• Implement breach and attack simulation tests on SIEM and EDR rules to detect unseen threats.
• Monitor insurance policy limits and negotiation positions to prevent extortion.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BlackCatBlackCatALPHVALPHV
Target & Sectors
Global Scope
financefinance
Incident Timeline
2026/07/10
A former employee of DigitalMint was sentenced to 4 years in prison for sharing confidential information about victims' insurance policy limits and negotiation positions with BlackCat ransomware operators.
Click on any entity below to view its context and source!
financial
$300 group
The FBI linked the BlackCat ransomware gang to
more than 60 breaches
between November 2021 and March 2022, adding in a separate advisory that the cybercrime group had
collected at least $300 million in ransom payments
from more than 1,000 victim…
victims
1,000 victims
…t ransomware gang to
more than 60 breaches
between November 2021 and March 2022, adding in a separate advisory that the cybercrime group had
collected at least $300 million in ransom payments
from more than 1,000 victims through September 2023.
financial
$25,660,000 firm
Their victims include at least five U.S. organizations, including a financial services firm that paid $25,660,000 and a nonprofit that paid a $26,793,000 ransom, as well as school districts, medical facilities, law firms, and other financial service…
financial
$26,793,000 $ ransom
Their victims include at least five U.S. organizations, including a financial services firm that paid $25,660,000 and a nonprofit that paid a $26,793,000 ransom, as well as school districts, medical facilities, law firms, and other financial service…
Tactical Metrics
Metrics
financial
300,000,000
Group
Click for context!
The FBI linked the BlackCat ransomware gang to
more than 60 breaches
between November 2021 and March 2022, adding in a separate advisory that the cybercrime group had
collected at least $300 million in ransom payments
from more than 1,000 victim…
Metrics
victims
1,000
Victims
…t ransomware gang to
more than 60 breaches
between November 2021 and March 2022, adding in a separate advisory that the cybercrime group had
collected at least $300 million in ransom payments
from more than 1,000 victims through September 2023.
Metrics
financial
25,660,000
Firm
Their victims include at least five U.S. organizations, including a financial services firm that paid $25,660,000 and a nonprofit that paid a $26,793,000 ransom, as well as school districts, medical facilities, law firms, and other financial service…
Metrics
financial
26,793,000
$ Ransom
Their victims include at least five U.S. organizations, including a financial services firm that paid $25,660,000 and a nonprofit that paid a $26,793,000 ransom, as well as school districts, medical facilities, law firms, and other financial service…
Intelligence Sources
BleepingComputer
2026-07-10
Former ransomware negotiator gets 4 years for BlackCat attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:25
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
timeline
Temporal Reference
4 years
date
5x
organisation
Identified Entity
Sygnia
entity
3x
general metric
%
20
%
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
malware
Malware Payload
BlackCat
tool
Contextual Telemetry
Context Block
7 METRICS
attribution
Attributing Entity
FBI
authority
general metric
Breaches
60
breaches
financial
Group
300,000,000
group
victims
Victims
1,000
victims
general metric
Conspirator
1
conspirator
financial
Firm
25,660,000
firm
financial
$ Ransom
26,793,000
$ ransom
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.