Key Takeaways

  • Angelo Martino sentenced to over five years in prison.
  • Involved in a scheme to extort U.S. companies using ransomware.
  • Over $10 million in cryptocurrency and assets seized.
  • Part of a larger group of cybersecurity professionals turned criminals.

Conviction Details

Angelo Martino, a Florida resident, has been sentenced to more than five years in prison for his role in a ransomware extortion scheme. Martino worked as a negotiator for a U.S. cybersecurity firm, where he conspired with hackers to deploy ransomware attacks against various companies.

Seizure of Assets

The U.S. Department of Justice announced the sentencing, revealing that authorities seized over $10 million in cryptocurrency and other assets linked to Martino’s illegal activities. Among the seized items were a food truck and a luxury fishing boat, purchased with funds obtained through the ransomware attacks.

Criminal Network

Martino is the third individual to face imprisonment in connection with this criminal operation. He collaborated with cybersecurity professionals Kevin Martin and Ryan Goldberg to execute ransomware attacks using the BlackCat ransomware throughout 2023. One notable incident involved extorting approximately $1.2 million from a company, which the trio then laundered and divided among themselves.

Impact on Cybersecurity Practices

This case underscores a rare instance of security professionals engaging in criminal activities while employed in the cybersecurity sector. Authorities have consistently advised companies not to pay ransoms to avoid enabling cybercriminals, although some organizations still opt to do so to protect sensitive customer data.

Ransomware Trends

The rise of extortion attacks has led to the emergence of a specialized insurance sector in the U.S. designed to address ransomware incidents. Many companies in this field employ negotiators to help reduce ransom costs.

About BlackCat Ransomware

BlackCat, also known as ALPHV, operates as a ransomware-as-a-service platform, allowing independent hackers to rent access to its file-encrypting malware in exchange for a share of the profits from their attacks. This group gained notoriety for a significant data breach in February 2024, which compromised sensitive medical and billing information of over 192 million Americans, although the hackers responsible for that breach have not been identified.