The images in this article were generated with artificial intelligence. How we publish
The recent ruling that sentenced Angelo Martino to 70 months in prison for collaborating with the BlackCat group and betraying victims he was allegedly helping as a rescue negotiator poses a double threat: not only are there Ransomware operators, but also response professionals who, by greed or collusion, can turn the aid into damage. In this case, according to the authorities, Martino provided the attackers with confidential information on the limits of policies and negotiating tactics of their own clients, which allowed extortors to maximize the required amounts and caused severe financial and operational damage to companies already in crisis. The Department of Justice and the FBI have emphasized that, in addition to pursuing the direct perpetrators, the internal and external facilitators who enable these campaigns will be pursued.
Beyond the individual impact, the episode has systemic implications for incident management: confidence in suppliers and negotiators becomes a critical failure point. Many organizations delegate negotiation and communication with attackers to external specialists during a crisis, in part to avoid tactical errors and to achieve better results. However, when these third parties have access to sensitive information - insurance policies, internal positions on payments, or financial capabilities - they can turn that advantage into a lever that damages the client if they collude with the attackers. The judgement and confiscation of assets demonstrate that illicit profits can be pursued, but do not redo destroyed business or damaged professional relations.

For security teams and business leaders, this case highlights the need to incorporate contractual and technical controls before and during an incident response. Agreements with response and impact providers should include clear clauses on conflict of interest, audit and reporting obligations to the company as well as penalties for fraudulent conduct. In addition, it is essential to limit and monitor access to sensitive information even for external consultants: detailed records of what is shared, with whom and why, and the maintenance of forensic copies to verify communications and decisions made in the management of the incident.
At the technical level, building resilience reduces reliance on costly rescue negotiations. Maintaining network segregation, offline and proven backup, and continuous visibility through centralized EDR and logging prevents an intrusion from becoming a crisis where the only output seems to pay. Effective cyberhealth and preparedness are the best ways to reduce the leverage that attackers and their facilitators can have on an organization. CISA and the FBI offer practical guidelines on prevention and response that should be reviewed as part of corporate plans: CISA Ransomware Guide and FBI resources on cybersecurity.
Another critical edge is the relationship with insurers. The case shows that the limits and terms of the policies may be targets of the attackers or, at worst, of corrupt intermediaries. Organizations should demand transparency in the use of insurance information during negotiation and document any communication involving policy terms. It is also recommended to coordinate in advance with legal teams and insurance corridors to define how contractual obligations and disclosure of information will be handled in a crisis.
Internal detection and response should include mechanisms to identify anomalous third-party behaviour: unusual data transfers, off-schedule access or duplication of communication channels with unknown actors. Identity and access controls, the rotation of credentials, the segmentation of privileges and the monitoring of exfiltration help to limit the damage that a malicious actor - internal or external - may cause. An ongoing accreditation and verification process for incident consultants is as important as the verification required of critical technology providers.

From a legal and enforcement perspective, the action of the Department of Justice sends a clear message: there are criminal and civil consequences for those who betray clients in security incidents. This should encourage companies to document their chain of decisions during incidents and to work quickly with authorities when they identify signs of collusion or fraud. It is also a wake-up call for response teams and negotiators to operate with codes of conduct, audits and, where appropriate, independent external oversight.
For security professionals, this case raises an ethical reflection: the negotiating position carries fiduciary responsibility in situations of extreme vulnerability. Industry needs professional standards, certification and ethical obligations that mitigate the risk of bad actors that exploit the trust of the victims. Until these standards are consolidated, organizations must require verifiable references, strict contractual clauses and, if possible, security deposit mechanisms or trusted third parties to handle sensitive funds and communications.
Ultimately, Martino's conviction is an uncomfortable reminder that security is not only technological but also relational and contractual. The best defence against extortion and fraud is a combination of technical preparation, rigorous governance over third parties and a coordinated response with legal advisers and authorities. Action now to strengthen controls, review response contracts and ensure transparency in all incident communications can make the difference between mitigating an attack and making it a financial and reputational disaster.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...