Ransomware Negotiator Turned BlackCat Insider

The real breach was inside the negotiation room. A ransomware negotiator with access to victims’ insurance limits and bargaining positions can help attackers set demands that fit the victim’s ceiling, which makes extortion more efficient than random pricing. Angelo Martino pleaded guilty to working with BlackCat/ALPHV from April 2023 and to sharing information from five corporate ransomware cases, including insurance policy limits and internal negotiation positions. The Justice Department said he also conspired with others to deploy ransomware against US victims between April and November 2023, and court records tie the scheme to multimillion-dollar payments. For defenders, the risk is not just stolen data. Any third party brought in to negotiate or respond to ransomware can become a source of leverage for the attacker, and that leverage can persist across future incidents if the same contacts, limits, and playbooks are reused.

Part of the PlainSec briefing for 2026-04-22

Editions

Sources