Inside The Scheme That Turned The Most Trusted Seat In Incident Response Into A Weapon

You get the call on a Tuesday, or a Sunday, or at two in the morning, and it doesn't matter which, because from that moment the clock belongs to someone else. Your files are encrypted. Your backups may or may not still exist. Somewhere, a stranger has a copy of everything your company has ever touched, and they are deciding how much of your life to burn down if you don't pay. You're not in control of your business anymore. You're barely in control of your own hands.

So you do the smart thing. You call in professionals, and you hand them the wheel.

I've worked these incidents. I've sat in the room while a company absorbs the worst week of its existence, watching leadership try to make seven-figure decisions on no sleep with a gun to the head of everything they built. It's one of the only situations in business where a total stranger walks in and you tell them absolutely everything, because you have no other option.

The person who ends up holding the most in that room is the negotiator. When a criminal crew has your data hostage, someone has to talk to them, and that job goes to a specialist whose entire value is the ability to build rapport with extortionists, read the people on the other side, and keep a terrified leadership team from panic-buying their way into a worse outcome. To do the job, they have to know what you know: your real financial ceiling, what your cyber insurance will cover, how badly the outage is bleeding you by the hour, and whether your backups are as dead as you're afraid they are.

They see your whole hand, and you show it to them willingly, because the alternative is playing a game you don't understand against people who play it every day.

If you've never lived that, picture the closest thing most people can imagine. Someone you love has been taken. There's a voice on the phone, calm and even and professional, and that voice is the only thing standing between the person you love and the outcome you can't let yourself think about. You can't hear the other side of the call. You don't know what's being offered, what's being withheld, what's being gambled with. You sit there and you hand over every private detail they ask for and you wait, because you're along for the ride whether you like it or not, and the ride is being driven by someone you met an hour ago. All you can do is trust the calm voice and pray it knows what it's doing.

That's the exact seat a ransomware victim sits in, and that's the weight a negotiator carries.

Angelo Martino was that voice for five different companies. Angelo Martino was also working for the people on the other end of the line.

The Man on Both Sides of the Call

Martino was a ransomware negotiator at DigitalMint, one of the better-known names in the business. Five organizations hired that firm during the worst moment of their corporate lives, and the firm put Martino on their cases. Not one of them knew that the calm professional steering their crisis was quietly on the payroll of the criminals holding them hostage. He would type steady, reassuring messages to his clients in the channel everyone could see, then turn around and hand the attackers the one thing that guaranteed his clients would lose. Their real limits. Their insurance ceilings. How much they could pay, and roughly when their nerve would give out.

There's an exchange sitting in the court record that shows exactly how it worked. In the negotiation his client could watch, Martino floated a serious offer and played the role of the advocate pushing back on the attacker. Moments later the attacker pushed back with unnerving precision, telling the victim to hang onto that money for the lawsuits coming their way, to stop stalling, that they knew what the company could pay and they knew all about the insurance carrier. Of course they knew. The man the victim was paying to protect them had already told them.

He ran both ends of the same conversation, comforting the victim with one hand and arming the extortionist with the other, and he took a cut from the side doing the damage. Prosecutors called him a double agent, which is about as generous a term as the facts allow.

This is the failure almost nobody plans for. You can plan for attackers. You can plan for downtime and a bad week and a ransom demand. But nobody writes the tabletop exercise where the person you hired to save you is the one quietly sharpening the knife.

The Operation He Chose to Feed

Martino was feeding BlackCat, also known as ALPHV, and for a stretch they were one of the most prolific ransomware operations on earth. They ran a ransomware-as-a-service model, where the core group built and maintained malware and leased it to affiliates who carried out the actual break-ins, kicking a percentage of every ransom back upstairs. They specialized in double extortion, stealing your data before encrypting it so that a clean restore still wouldn't save you from having your secrets dumped online. Before the FBI disrupted the operation at the end of 2023, they tied BlackCat to more than a thousand victims and over three hundred million dollars in ransom payments. These weren't bored teenagers, like Scattered Spider. This was an industrialized criminal enterprise, and Martino decided to be their man on the inside.

Leaking wasn't enough for him, either. He went into business with them. Working with a coworker at DigitalMint who was hired after the scheme was already running, and with a man employed at a separate incident response firm called Sygnia, Martino helped deploy BlackCat ransomware against more companies directly. Two different, reputable firms in the response industry, each with an employee who decided the criminals were paying better. This was never a story about one bad apple in one break room.

And the money was grotesque. The single attack the three of them pulled off together netted a little over a million dollars in Bitcoin, split three ways and laundered. That's the figure that ran in most of the headlines, but it badly undersells what happened.

The five victims Martino sold out paid ransoms that, according to the court record, included roughly $26.8 million from a nonprofit, $25.7 million from a financial services firm, and $16.5 million from a hospitality company, with two more around $6.1 million and $213,000 respectively. That's more than seventy-five million dollars pulled out of five organizations, among them school districts and medical facilities.

Martino took his slice, and he spent it.

Seventy-Five Million Dollars and a Fishing Boat

We know he spent it, because the government seized around ten million dollars in assets from him on the way to prison. Cryptocurrency, vehicles, a food truck, and, I'm not making this up, a luxury fishing boat.

Picture that boat, bobbing somewhere off the sunny Florida coast, bought and paid for by a nonprofit and a couple of school districts who never knew they were the ones cutting the check. For years I've told business owners not to buy their attacker a yacht, by which I mean don't let a preventable breach turn into a criminal’s spending spree. I spent all that time telling people to watch the water for the bad guys. It never once occurred to me that the man hired to stand watch would be the one who sailed off in the boat.

Every piece of access Martino weaponized was access that had been earned and freely given, because there was no other way to do the job. That's what makes this category of betrayal different from anything a firewall catches.

The threat was inside the building, behind the trust, holding the keys everyone had handed over because they had no choice.

That distinction matters beyond this one case. The access that makes a negotiator useful is also the access that makes a negotiator dangerous, and there's no clean way to separate the two. The industry runs on trust because it has to. When that trust gets turned into a weapon, every calm voice in every future crisis carries a question mark that didn't exist before Martino put it there.

The practical answer, for any organization that might one day make that call, is to treat the negotiator the same way you'd treat any other vendor with access to your most sensitive information: verify their firm's reputation independently, keep your own people looped into your real numbers, and put controls around who can see your negotiating position and your insurance limits, even inside your own response. The access you grant during a crisis should be the minimum required, not the maximum available.

None of Martino's clients did anything wrong. They followed the playbook exactly as it's written, and they still got burned. The best you can do is make the playbook harder to turn against you.

That's the part of this case I keep coming back to, and it's connected to something I haven't said yet. I have my own history with this industry, and it's the reason this case sits differently with me than it would for anyone reading it from the outside. That's what Part 2 is all about, so check back soon.