← All posts

When the Negotiator Works for the Other Side

On Thursday, the Department of Justice sentenced Angelo Martino, a 41-year-old Florida man, to 70 months in federal prison. His job title, until recently, was ransomware negotiator. Companies in the worst week of their existence hired his firm to talk ransomware gangs down from their demands.

He was on the gangs' payroll.

According to the DOJ, Martino spent months in 2023 feeding the BlackCat ransomware operation confidential information about his employer's clients — their negotiating positions, their strategy, how much they could actually pay. BlackCat paid him for it, and used it to squeeze five victims for larger ransoms. The people sitting across the virtual table believed their negotiator was fighting for them. He was helping the other side read their cards.

Then he went further. Martino and two other cybersecurity professionals — one hired as his own coworker, another employed at a separate incident response firm — started deploying BlackCat ransomware themselves against additional U.S. companies. They extorted one victim for roughly $1.2 million in Bitcoin and split the proceeds three ways. When law enforcement caught up with him, they seized $10 million in assets, including cryptocurrency, vehicles, a food truck, and a luxury fishing boat.

Crisis concentrates trust

Here is what makes this case worth your attention as an executive, and it is not the fishing boat.

When ransomware hits, your organization hands an extraordinary amount of trust to outsiders, fast. The incident response firm gets access to your network. The negotiator learns things your own board may never discuss in an open meeting: your payment ceiling, your insurance limits, how many days of downtime you can survive before the damage becomes permanent.

In my experience, nobody vets these people at the moment they're hired — because at that moment, you have no time. The forensics team is coming in the door at 2 a.m. and the question on everyone's mind is "how fast can you start," not "how do you screen your own employees."

That information asymmetry is exactly what Martino sold. Your negotiating position, in the hands of the attacker, converts directly into a bigger ransom. It was worth enough that a criminal enterprise was willing to pay a professional insider for it.

The retainer is not the diligence

Most mid-size and large companies now have an incident response retainer. Good. Your cyber insurer probably required it, your auditors like seeing it, and the box is checked.

But a signed retainer tells you nothing about the firm behind it. This is the compliance-versus-security trap I write about in Cyber Risk Is Business Risk: the artifact that satisfies the checklist is not the same thing as the condition that keeps you safe. The retainer satisfies the checklist. What keeps you safe is the answer to a harder question — what controls does that firm apply to its own people, who will soon know your most sensitive secrets?

The Three Questions framework from the book applies to your own security program, but it applies with equal force to the vendors you'll lean on in a crisis. You are entitled to demand evidence, not assurances. A firm that handles ransom negotiations should be able to describe, specifically, how it monitors for exactly the betrayal Martino committed: insider access controls, separation of duties on negotiations, background screening, and monitoring of employee communications on active cases.

If they can't answer, that is an answer.

What to ask your CISO this week

  • Who is on our incident response retainer, and when did we last perform real due diligence on them — not procurement paperwork, but questions about their insider-threat controls?
  • During a ransom negotiation, who on our side independently verifies what the negotiator reports back? A single person relaying the attacker's words with no second channel is a single point of failure.
  • Does our playbook limit what outside parties learn on a need-to-know basis? The negotiator may not need to know our full insurance limit or our true payment ceiling.
  • If we discovered mid-incident that a response vendor was compromised, what would we do? It sounds paranoid. It just happened to five American companies.

The uncomfortable takeaway

Martino pleaded guilty in April. His two co-conspirators were sentenced to 48 months each in May. A restitution hearing is set for September. The system worked, eventually — the FBI's Miami field office built the case, and the Justice Department notes that Americans reported more than $20 billion in cybercrime losses last year, up 26 percent in a single year.

But the victims don't get that week back. They hired help in a moment of crisis and got a second attacker instead. The only time you can protect yourself from that outcome is before the crisis — when you still have the leverage to ask hard questions and the time to hear real answers.