/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The US DOJ says a former ransomware negotiator pleaded guilty to helping cybercriminals extort companies in cyberattacks in five different incidents

Angelo Martino, a former ransomware negotiator, has pleaded guilty to helping cybercriminals extort companies in cyberattacks.

TechCrunch Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

The related coverage traces this case from Martino’s guilty plea to a later 70-month sentence tied to collusion with BlackCat and extortion of his employer’s clients. It also sits alongside DOJ actions against participants in Netwalker and Robbinhood ransomware operations.

What distinguishes this case in the supplied coverage is the alleged role of a ransomware negotiator: a professional positioned to help victims manage attacks was instead found to have assisted extortionists across five incidents.

First-order effects

  • Martino faces criminal accountability, while the affected clients and his former employer must contend with the consequences of compromised incident-response and negotiation work.
  • The DOJ’s case puts ransomware negotiators and the firms employing them under sharper scrutiny where they handle victim communications, payments, or attacker access.

Second-order effects

  • Incident-response providers are likely to strengthen separation of duties, access controls, client-conflict checks, and oversight around negotiations, since insider collusion can turn a defensive service into an extortion channel.
  • Victims may demand more transparency and independent verification from outside responders, adding friction to already time-sensitive ransomware response decisions.

Third-order effects

  • If enforcement continues to reach facilitators around ransomware groups as well as the attackers themselves, the sector’s trusted-intermediary model will face more formalized compliance and governance expectations.
  • The case underscores that ransomware risk is not limited to network intrusion: the integrity of the response supply chain can become part of an organization’s exposure.

The trend: Ransomware enforcement is broadening from pursuing malware operators to scrutinizing the intermediaries and service relationships that can enable extortion.

Discussion

  • @campuscodi.risky.biz Catalin Cimpanu on bluesky
    The third security firm employee who worked with the BlackCat ransomware has also pleaded guilty now  —  www.justice.gov/opa/pr/flori...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on bluesky
    NEW: Angelo Martino, a former ransomware negotiator, pleaded guilty to helping a ransomware gang get more money — of which he took a cut — from their victims.  —  He was secretly playing both sides in several ransomware negotiations, and he also deployed ransomware himself with c…