Ransomware negotiator admits leaking client information to attackers
Angelo Martino, a cyber security specialist from Florida, has pleaded guilty to conspiring to commit ransomware attacks in 2023. At the time Martino was employed as a ransomware negotiator and used his position in BlackCat cases to feed sensitive information about victims to the operators. He later teamed up with Ryan Goldberg and Kevin Martin, also security professionals, to launch BlackCat attacks of their own. All three are now on trial and will be sentenced in the coming months, facing a maximum of 20 years in prison. Police have also seized ten million dollars in assets from Martino, including digital currency and vehicles.
What this means for your organisation
The negotiator in a ransomware case learns everything: what is encrypted, what the backups are worth, how much the business can absorb and what it is prepared to pay. It is the most asymmetric trust relationship that exists in a crisis, and it is usually entered into under time pressure with no real vetting of the counterparty. The lesson for Norwegian organisations is that crisis advisers should be chosen before the crisis, not during it.
Berigo recommends
- Agree in advance who you would use for negotiation and incident response, and check their background while things are calm.
- Write confidentiality, conflict of interest and notification obligations into agreements with advisers who gain visibility into an incident.
- Limit how much information external advisers actually need, and log what is shared with whom.
- Establish a clear internal decision path for whether and how ransom demands are handled at all, before you face one.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch