Security News

Cybersecurity news aggregator

💀
HIGH Attacks SecurityWeek

Third US Security Expert Sentenced to Prison for Helping Ransomware Gang

This article details a case of insider threat, where a ransomware negotiator exploited his trusted position to aid the BlackCat/Alphv ransomware gang. The individual provided the attackers with confidential information on victim negotiation strategies, enabling the gang to maximize ransom extortion. The article serves as a critical reminder for organizations to implement stringent controls and oversight for personnel in trusted roles, particularly those handling sensitive incident response data.
Read Full Article →

Cybercrime Third US Security Expert Sentenced to Prison for Helping Ransomware Gang Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group. By Eduard Kovacs | July 10, 2026 (8:58 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Another cybersecurity expert from the United States, accused of helping a cybercrime gang while working as a ransomware negotiator, has been sentenced to prison. Angelo Martino, 41, of Florida, was sentenced on Thursday to 70 months in prison after he pleaded guilty in April. Martino is one of the three individuals charged by US authorities last year over their role in ransomware attacks. The three men worked at cybersecurity firms, and two of them served as ransomware negotiators tasked with helping victims, but instead they helped the threat actors in return for a share of the ransom. The other two suspects, Kevin Martin from Texas and Ryan Goldberg from Georgia, were each sentenced to 4 years in prison in late April. According to investigators, Martino began working with BlackCat/Alphv ransomware operators in April 2023 and helped the hackers extort at least five victims. The DOJ said Martino was paid by BlackCat to “provide confidential information about the negotiating position and strategy of his employer’s clients and enable the ransomware actors to maximize the ransoms paid by the victims”. Advertisement. Scroll to continue reading. Authorities seized $10 million worth of assets from Martino, including cryptocurrency, vehicles, a food truck, and a fishing boat. Martino will also have to pay restitution, but the amount will be determined in a hearing scheduled for September. Over 1,000 organizations were targeted in BlackCat ransomware attacks between 2021 and December 2023, when the criminal enterprise was disrupted . A few months later, the hackers received a $22 million ransom from a victim and pulled an exit scam . The US has been offering $10 million for information leading to the identification of key members of the group. Related : County Government Reportedly Paid $1 Million to Cyber Extortion Group Related : Alleged Scattered Spider Hacker Extradited to US Related : Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Microsoft Patches Defender ‘RoguePlanet’ Vulnerability AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique Google Patches 382 Chrome Vulnerabilities BlueHammer Vulnerability Exploited in Ransomware Attacks Nissan Employee Data Breached in Oracle PeopleSoft Hack New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack Latest News China, India-Linked Hackers Both Targeted Same Pakistani Police Force Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers GigaWiper Combines Multiple Malware for System-Level Sabotage ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism Network of 200 GitHub Repositories Used for Malware Infection QIZ Security Raises $17 Million for Cryptographic Governance Platform UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge Palo Alto Networks Patches 13 Vulnerabilities Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 16, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the Move BlueVoyant has appointed Ravi Subramanian as CFO and Jamie Coleman as CCO. Solana Foundation has appointed Michael Coates as Chief Information Security Officer. Michael Sikorski has joined Coinbase as Chief Information Security Officer. More People On The Move Expert Insights The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) When Information Becomes the Attack Surface – Understanding AI Agent Traps From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email

Share this article