Cybercrime

Third US Security Expert Admits Helping Ransomware Gang

Angelo Martino of Florida has pleaded guilty to collaborating with the BlackCat cybercrime group while working as a ransomware negotiator.

Hacker

A third man has pleaded guilty to participating in ransomware attacks while working for a cybersecurity company hired to negotiate with hackers.

In October 2025, the US announced charges against three individuals for allegedly conducting ransomware attacks against several companies. Authorities said the suspects were tasked with helping victims, but instead they helped the attackers in return for a share of the ransom.

Two of the suspects, Kevin Martin from Texas and Ryan Goldberg from Georgia, pleaded guilty in late 2025 and await sentencing, scheduled for the end of April.

The identity of the third individual was only revealed in March 2026. He is 41-year-old Angelo Martino from Florida, who worked with Martin as a ransomware negotiator at an incident response firm. Goldberg worked for a different cybersecurity company.

Martino has now also pleaded guilty and, similar to Goldberg and Martin, faces up to 20 years in prison.

According to the Justice Department, Martino abused his role as a ransomware negotiator for five companies by providing the BlackCat/Alphv cybercrime group with information useful in negotiating a ransom payment. 

Advertisement. Scroll to continue reading.

“This confidential information assisted the ransomware actors and maximized the ransoms that the victims were required to pay. The BlackCat actors paid Martino for this confidential information,” the DOJ said.

Law enforcement has seized $10 million worth of assets from Martino.

Over 1,000 organizations were targeted in BlackCat ransomware attacks between November 2021 and December 2023, when the operation was disrupted by law enforcement. The cybercriminals continued operating for a few more months until they received a $22 million ransom, then pulled an exit scam.

The US has been offering a $10 million reward for information on key members of the BlackCat group, but no charges have been announced to date.    

Related: British Scattered Spider Hacker Pleads Guilty in the US

Related: Another DraftKings Hacker Sentenced to Prison

Related: Two North Korean IT Worker Scheme Facilitators Jailed in the US

Related Content

Ransomware

The company has yet to determine the full scope, nature, and impact of the incident.

Cybercrime

The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. 

Cybercrime

Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group.

Data Breaches

Hackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data.

Artificial Intelligence

Attack demonstrates how LLM agents can combine known exploitation techniques with real-time reasoning to automate complex, multi-stage intrusions.

Cybercrime

Prosecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100...

Ransomware

The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released.

Data Breaches

Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version