/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The US DOJ says a former ransomware negotiator pleaded guilty to helping cybercriminals extort companies in cyberattacks in five different incidents

Angelo Martino, a former ransomware negotiator, has pleaded guilty to helping cybercriminals extort companies in cyberattacks.

TechCrunch Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

This guilty plea sits within a broader DOJ-led pattern of prosecutions tied to ransomware operations, including convictions involving Netwalker and Robbinhood participants.

The related coverage also follows this case from plea to a later 70-month sentence, tying the alleged conduct to BlackCat and five clients of the negotiator’s employer. It highlights risk not only from ransomware operators but from trusted intermediaries in the response process.

First-order effects

  • Martino’s plea establishes criminal exposure for a former ransomware negotiator accused of aiding extortion across five incidents; the DOJ gains a public enforcement result against an insider-linked participant.
  • Incident-response and ransomware-negotiation firms face immediate scrutiny of employee access, case controls, and safeguards around client and attacker communications.

Second-order effects

  • Organizations engaging negotiators may demand tighter segregation of duties, auditing, and disclosure obligations from response providers before sharing incident details or payment-related information.
  • Other response firms and insurers may reassess how negotiations are staffed and supervised, since a compromised intermediary can compound the harm of an already active ransomware event.

Third-order effects

  • If enforcement continues to reach facilitators and insiders alongside ransomware operators, the ransomware-response market may shift toward more formalized controls and greater accountability for third-party handling of extortion cases.
  • The case underscores that disrupting ransomware increasingly involves policing the service ecosystem around attacks, not solely identifying the groups that deploy malware.

The trend: Ransomware enforcement is broadening from prosecutions of attack operators to alleged enablers embedded in the cyber-incident response and extortion-negotiation ecosystem.

Discussion

  • @lorenzofb Lorenzo Franceschi-Bicchierai on bluesky
    NEW: Angelo Martino, a former ransomware negotiator, pleaded guilty to helping a ransomware gang get more money — of which he took a cut — from their victims.  —  He was secretly playing both sides in several ransomware negotiations, and he also deployed ransomware himself with c…
  • @campuscodi.risky.biz Catalin Cimpanu on bluesky
    The third security firm employee who worked with the BlackCat ransomware has also pleaded guilty now  —  www.justice.gov/opa/pr/flori...