When Your Ransomware Negotiator IS the Ransomware Operator: The DigitalMint Betrayal
The Scheme That Should Rewrite Your IR Vendor Contracts
Angelo John Martino III, a 41-year-old ransomware negotiator at DigitalMint, stands accused of conducting at least 10 ALPHV/BlackCat ransomware attacks while simultaneously serving as the trusted intermediary companies hired to negotiate their way out. Federal authorities allege he extorted $75.25 million, with individual payments reaching $26.8 million and $25.7 million — numbers that only make sense when the attacker has perfect intelligence on the victim's insurance limits, backup status, and pain threshold.
This wasn't a lone wolf. Two other DigitalMint employees — Kevin Tyler Martin and Ryan Clifford Goldberg — already pleaded guilty in December 2025 to similar attacks. They face sentencing April 30. Three employees at the same firm, all running ransomware operations while being paid to stop them.
How the Dual-Role Attack Model Worked
Map this to your incident response workflow and the picture is devastating:
- Initial compromise: Martino allegedly deployed ALPHV/BlackCat via standard affiliate vectors (compromised VPNs, phishing, credential abuse)
- Victim engages DigitalMint: At least 5 confirmed companies hired Martino's own employer to negotiate on their behalf
- Intelligence harvesting: Through the negotiation process, Martino allegedly accessed financial details, backup status, insurance coverage, and business continuity timelines
- Calibrated extortion: Armed with insider knowledge, demands were tuned for maximum extraction — far above the ransomware average
The ultimate social engineering: the attacker is positioned as the defender, and the victim voluntarily shares their most sensitive recovery information.
Why Your Current Vendor Controls Likely Failed
Most IR retainer agreements focus on response time SLAs, scope of services, and hourly rates. They rarely address:
- Conflict-of-interest provisions and information barriers between offensive/intelligence teams and negotiation teams
- Employee criminal background check requirements, including ongoing monitoring
- Data compartmentalization — what information the vendor can access and how it's segregated
- Attestation that no employees have active cybercrime investigations
Martino was released on $500K bond and banned from cybersecurity work. $9.2M in cryptocurrency and $2M+ in real estate and vehicles were seized. He faces up to 20 years. But the damage to the IR vendor trust model is already done.
The Broader Pattern
This cycle also surfaced the confirmed SSA data exfiltration via thumb drive by a DOGE engineer, proving removable media controls fail even in federal environments handling the most sensitive PII in government. The common thread across both incidents: privileged insiders with trusted access exploiting the trust itself. Your vendor is only as trustworthy as their least-vetted employee.
What to do
Audit all IR retainer and ransomware negotiation vendor agreements for conflict-of-interest provisions, information barriers, and employee background check requirements by end of this sprint
Compartmentalize information shared with negotiation firms — never provide a single vendor with simultaneous visibility into insurance limits, recovery timeline, and financial position
Add conflict-of-interest certification to all cybersecurity vendor contracts requiring vendors to attest no employees have active criminal investigations related to cybercrime
Brief board or senior leadership on the DigitalMint case as a concrete third-party risk scenario to justify enhanced vendor due diligence budget