[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqQNFn2jXi-BksEEUkabtB6tYuglqfDh3mxOLwqtbWHM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"76ec10ce-c8cf-4550-a011-e10dfc5eb164","insider-threat-ransomware-negotiator-turned-extortionist-sentenced","3725e3ed-90c3-433d-b253-8ae85e935a89","Insider Threat: Ransomware Negotiator Turned Extortionist Sentenced","Angelo Martino exploited his privileged position as a trusted ransomware negotiator to betray clients by secretly sharing their confidential information with the very threat actors he was supposed to be negotiating against. This case illustrates how insider threats can be catastrophic when third-party service providers operate with unchecked access to sensitive victim data and communications. The scheme also highlights the danger of engaging intermediaries without verifying their integrity, loyalty, and potential conflicts of interest. Organizations trusting external ransomware negotiators or incident response firms must treat these relationships with the same rigor as any high-risk third-party vendor, applying strict oversight and data minimization principles.","**Immediate actions:**\n- Vet all third-party ransomware negotiators and incident response firms through background checks, references, and conflict-of-interest disclosures before engagement.\n- Limit the volume and sensitivity of information shared with external negotiators using a strict need-to-know and data minimization policy.\n\n**Long-term improvements:**\n- Establish formal vendor risk management programs that continuously monitor the behavior and access of third-party service providers.\n- Implement contractual obligations requiring negotiators and IR firms to disclose any affiliations or relationships that could constitute conflicts of interest.\n- Separate communications channels and negotiation processes so no single external party has unilateral access to all victim data.\n\n**Detection measures:**\n- Log and audit all communications and data transfers between your organization and any external incident response or negotiation partner.\n- Deploy insider threat detection tools that flag anomalous data access or exfiltration patterns by privileged third-party accounts.\n- Require dual-authorization for sharing sensitive ransom negotiation details with external parties.",[12,13,14,15,16,17,18,19,20,21,22,23],"NIST SP 800-161 (Supply Chain Risk Management)","NIST AC-2 (Account Management)","NIST AC-6 (Least Privilege)","NIST IR-4 (Incident Handling)","CIS Control 6 (Access Control Management)","CIS Control 15 (Service Provider Management)","CIS Control 17 (Incident Response Management)","GDPR Article 28 (Processor Obligations)","GDPR Article 32 (Security of Processing)","ISO\u002FIEC 27001 A.7.1.1 (Background Verification)","ISO\u002FIEC 27001 A.15.1 (Supplier Relationships)","ITIL Service Design — Supplier Management","published","2026-07-10T02:20:21.278045+00:00","2026-07-10T02:20:21.162+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fcyberscoop.com\u002Fdigitalmint-ransomware-negotiator-angelo-martino-sentenced\u002F","former-digitalmint-ransomware-negotiator-who-duped-clients-sentenced-to-70-month-dfd455","Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]