TL;DR: On July 10-11, 2026, the U.S. District Court for the Southern District of Florida sentenced Angelo Martino, a former DigitalMint ransomware negotiator, to 70 months in federal prison. Martino conspired with BlackCat/ALPHV threat actors to extort the same companies he was hired to represent as a negotiator. Co-conspirators Kevin Martin (48 months) and Ryan Goldberg (48 months) received sentences the same week. The scheme extorted more than $75 million from four companies and a nonprofit. Law enforcement seized $10 million in assets — cars, cryptocurrency, a food truck, a luxury fishing boat. For North Carolina small businesses that keep ransomware negotiators, incident response firms, MSPs, and cyber counsel on retainer, this case is the wake-up call: vendor due diligence for cybersecurity providers is now a board-level control. This is the NC SMB IR-vendor risk playbook.
Key takeaway: The people you call in the worst hour of your business's life can be the same people extorting you. Vendor due diligence for incident response, ransomware negotiation, MSP, and cyber counsel providers is a first-order control — not a procurement checkbox. If your NC SMB has an IR retainer with a firm you cannot verify has never been touched by a Martino-class case, you are exposed.
Need to build a due-diligence playbook for your IR, MSP, and cyber counsel providers? Contact Preferred Data Corporation — BBB A+ rated, 37+ years of NC IT expertise, on-site within 200 miles of High Point. Call (336) 886-3282.
What Happened With the DigitalMint Case?
Angelo Martino, 41, of Land O'Lakes, Florida, was employed at Chicago-based cybersecurity firm DigitalMint as a ransomware negotiator. Between April 2023 and November 2023, Martino and two co-conspirators orchestrated the same ransomware attacks Martino was retained to negotiate against.
- Coordinated attacks with BlackCat/ALPHV. Martino used his position and insider knowledge to feed the criminal group victim-specific information — pain points, negotiation strategy, willingness to pay — while collecting a fee for his "negotiation" services.
- Kevin Martin, 36, of Texas. Hired as Martino's coworker after the conspiracy began. 48-month sentence.
- Ryan Goldberg, 41, of Georgia. Employed by a separate incident response company. 48-month sentence.
- Deployed BlackCat ransomware against additional victims across the United States April-November 2023.
- Extorted more than $75 million from four companies and a nonprofit organization Martino represented as a negotiator.
- $10 million in assets seized — digital currency, vehicles, a food truck, a luxury fishing boat.
- Restitution hearing: September 17, 2026.
The Justice Department press release, CyberScoop reporting, and DataBreaches.Net coverage detail a scheme that exploited the trust-and-information asymmetry inherent in ransomware negotiation.
Why Is This Different From "Just Another Insider Threat"?
Insider threat cases at end-user businesses are common. This case is different because it targets the cybersecurity vendor supply chain that NC SMBs increasingly depend on.
- The vendor role includes privileged insight. A ransomware negotiator sees the victim's crown jewels: what got encrypted, what backups survived, what the leadership team is willing to pay, what the board deadline is, what regulators are aware of the incident.
- The vendor role also includes access to threat actor communications. Negotiators build working relationships with criminal groups. That contact surface is exploitable.
- The victim has no negotiation leverage. In the middle of a live ransomware incident, the SMB CEO cannot fire the negotiator without collapsing the response.
- The vendor's other clients are collateral risk. Martin was on the same team as Martino. Goldberg was at a different IR firm. The scheme's structure implies that any IR firm's staff roster is now a due-diligence input.
Key takeaway: Cybersecurity vendor selection has been treated as a technical evaluation for two decades. The Martino case demonstrates that it must now be a governance evaluation — one that examines vendor employment practices, insider-threat controls, and background-check standards inside the firms you might call in your worst hour.
What Categories of Vendors Are Now In Scope for Vendor-Risk Review?
Any NC SMB that engages third parties for ransomware readiness or response should include these vendor categories in its risk-management program.
| Vendor Category | Typical NC SMB Engagement | Risk Vector |
|---|---|---|
| Incident response firm | Retainer contract for post-incident response | Access to compromised environment, breach details, negotiation posture |
| Ransomware negotiator | Sub-engaged by IR firm or independently retained | Direct communication with threat actor, victim intelligence |
| Managed IT services provider (MSP) | Day-to-day IT operations | Privileged domain access, admin credentials, backup systems |
| Managed security services provider (MSSP) | 24/7 SOC, EDR management | Full endpoint visibility, alert triage, containment authority |
| Cyber counsel | Legal representation during incident | Executive/board access, breach notification decisions, insurance coordination |
| Digital forensics | Post-incident evidence collection | Compromised systems, evidence chain of custody |
| Insurance broker / cyber underwriter representatives | Policy-related communications | Loss data, incident details, claim status |
The Martino case is a fact pattern for the first two categories, but the systemic lesson generalizes across all seven.
What Should a NC SMB Actually Do?
A defensible vendor-risk program pairs contractual controls, operational controls, and reputational controls.
Contractual Controls (Master Services Agreement level):
- Background check standards for personnel with access to sensitive customer data — including criminal history, financial pressures, and conflict-of-interest disclosures.
- Insider-threat program requirements at the vendor: role separation, dual approval for high-risk actions, immutable audit logging.
- Right to audit vendor personnel screening at least annually.
- Termination-for-convenience with well-defined transition periods so the SMB is not locked into a compromised vendor during a live incident.
- Explicit prohibition on the vendor engaging in any communication with the threat actor outside the sanctioned negotiation channel.
- Notification obligations if the vendor is subject to a law-enforcement inquiry.
Operational Controls:
- Segregate ransomware negotiation from incident response — do not source both from the same vendor without contractual separation.
- Require two-person integrity: negotiator plus IR lead plus counsel on every threat-actor communication.
- Immutable, tamper-evident logging of all negotiation communications.
- Independent post-incident review by counsel and (where applicable) forensics not involved in the original response.
Reputational Controls:
- Vet vendors by cross-referencing court dockets, DOJ announcements, and industry reporting.
- Ask directly during vendor selection whether the vendor has ever had personnel indicted, sued, or investigated for insider misconduct — and require a written answer.
- Include vendor risk in your quarterly board or ownership report.
Explore Preferred Data's managed IT services
What Are the Retainer Contract Clauses NC SMBs Should Update?
An IR retainer contract signed in 2022-2023 likely lacks the language now required to manage this risk. Update as follows.
- Background-check attestation. Vendor represents and warrants that all personnel with access to customer environments have passed criminal background checks and financial-integrity checks within the prior 12 months.
- Insider-threat program representation. Vendor represents its personnel operate under an insider-threat program consistent with recognized standards (CERT Insider Threat Center, NIST 800-53 PS-family controls).
- Conflict-of-interest disclosure. Vendor discloses any personnel relationships — direct or indirect — with known threat-actor groups, prior threat-actor-linked prosecutions, or law-enforcement inquiries.
- Communication controls. All threat-actor communications occur through recorded, monitored, immutable channels. Direct out-of-band contact with threat actors is prohibited absent SMB written consent.
- Termination for cause. SMB may terminate the retainer immediately upon evidence of vendor personnel misconduct without penalty.
- Cyber-insurance cooperation. Vendor cooperates with SMB's cyber-insurance carrier including personnel interviews and evidence production.
How Does This Fit the July 2026 Threat Picture?
The Martino sentencing is the newest data point in a broader trend: the cybersecurity vendor supply chain itself is a target and a risk vector.
- Ingram Micro SafePay breach (July 2-3, 2026). MSP/reseller supply-chain disruption to NC SMBs downstream.
- SimpleHelp CVE-2026-48558 (KEV July 2, 2026). RMM software vulnerability compromising MSP-managed customer environments.
- Multiple 2025-2026 MSP compromises enabling downstream ransomware.
- JADEPUFFER agentic ransomware operating at machine speed with insider-quality target intelligence.
- Cyber-insurance carriers now underwriting on MSP/IR vendor quality with specific questionnaire items about vendor risk management.
The convergence is a structural signal: the "we outsource that" answer to cybersecurity is being replaced by "we outsource that AND we manage vendor risk actively."
Key takeaway: The Martino conviction, the Ingram Micro breach, the SimpleHelp KEV entry, and the agentic-ransomware wave are the same story told from four angles. NC SMBs that treat cybersecurity as a one-vendor problem are exposed on every angle. NC SMBs that build vendor-risk management as a first-class governance function survive.
Explore Preferred Data's cybersecurity services
How Does Preferred Data Support NC SMB IR-Vendor Due Diligence?
Preferred Data Corporation delivers managed IT, cybersecurity, IR planning, and vendor risk management for NC manufacturers, contractors, distributors, and specialty SMBs. With 37+ years of NC IT expertise, an average client retention of 20+ years, and BBB A+ rating, we bring a full-stack view of the vendor-risk problem — including our own vendor practices, which we publish as evidence.
- IR-retainer contract review. Line-by-line MSA rewrite with background-check attestations, insider-threat program representations, and conflict-of-interest disclosures.
- Vendor-risk questionnaire library. Ready-to-issue questionnaires for MSP, MSSP, IR firm, negotiator, forensics, and cyber-counsel selection.
- Cyber-insurance renewal support. Vendor-risk evidence organization for the renewal questionnaire.
- Table-top exercise design. IR simulations that include the "compromised vendor" scenario.
- Board reporting cadence. Quarterly vendor-risk report for ownership or the board.
Ready to know whether your IR retainer would survive a Martino-class scenario? Call (336) 886-3282 or contact our team.
Frequently Asked Questions
Was DigitalMint itself charged in this case?
Public DOJ materials and court filings do not indicate charges against DigitalMint as a corporate entity. The prosecution focused on individual actors. NC SMBs using any IR firm should nonetheless ask about post-Martino changes to personnel screening and insider-threat controls.
Does this mean I should not use a ransomware negotiator?
No. Ransomware negotiators can add substantial value: buying time, negotiating price, coordinating with cyber counsel and insurance. The lesson is not to avoid the category — it is to select vendors with defensible personnel practices and to structure the engagement so a single person cannot compromise the response.
How do I check whether my current IR firm has had personnel issues?
Ask directly and require a written answer. Cross-reference court dockets (PACER), Justice Department announcements, and reputable industry reporting. Include the question in your vendor renewal cycle.
What if we do not have any IR retainer today?
That is a separate risk. Median time-to-decide-on-a-vendor during a live incident is 24-72 hours — time you do not have when your production database is encrypted. A vetted IR retainer with defensible contract language is preferable to no retainer at all.
How does this affect cyber-insurance underwriting?
Increasingly directly. Carriers now include vendor-risk questionnaire items and, in some cases, require the SMB to disclose IR firm identities. Some carriers maintain approved-vendor lists. A vetted IR retainer aligned to your carrier's expectations reduces friction at claim time.
How fast can Preferred Data help update our IR contracts and vendor questionnaires?
Contract review and vendor-questionnaire library rollout for a typical NC SMB (2-5 cybersecurity vendors under management) completes in 15-30 business days. Call (336) 886-3282.
Related Resources
- Managed IT Services for NC Small Businesses
- Cybersecurity Services for NC Manufacturers and SMBs
- Mergers and Acquisitions Advisory Services
- Ingram Micro SafePay Breach: NC SMB IT Distributor Supply Chain Plan
- SimpleHelp CVE-2026-48558: NC SMB MSP Supply Chain Defense
- 94% SMB MSP Adoption: In-House IT Unviable for NC Small Businesses