A Chicago cybersecurity professional faces federal charges for allegedly running a sophisticated double-cross operation that netted more than $75 million in ransomware payments.
Angelo Martino, 41, worked as a negotiator for Chicago-based cybersecurity firm DigitalMint while secretly orchestrating the very cyberattacks that created his clients' need for his services, federal prosecutors allege.
The scheme targeted businesses across hospitality, retail, medical and financial services sectors, with two individual ransom payments exceeding $25 million each, according to court documents.
Martino and his associates allegedly used ALPHV BlackCat ransomware to infiltrate victims' computer networks, then demanded payment in exchange for decryption keys and promises not to publish stolen data.
Federal authorities have seized Martino's Florida properties, vehicles, and more than $9 million in cryptocurrency as part of the investigation.
"Martino was terminated the next day," DigitalMint CEO Jonathan Solomon said in a statement, referring to when the Justice Department informed the company of the allegations in April 2025. Solomon added that the company reviewed Martino's work and found "no" evidence of wrongdoing in his legitimate activities.
The case highlights a troubling trend in cybercrime, where insiders exploit their positions of trust to orchestrate attacks from within. Two additional defendants, identified as Martin and Goldberg, were also terminated from their respective positions at DigitalMint and cybersecurity firm Sygnia.
According to TRM Labs, which assists financial institutions and government agencies like the FBI in investigating cryptocurrency-related fraud, ransomware attacks increased significantly last year alongside the proliferation of various ransomware types.
The investigation remains ongoing as federal authorities work to dismantle what they describe as a complex criminal enterprise that exploited businesses' vulnerabilities while masquerading as their protector. The case underscores the critical importance of vetting cybersecurity professionals and implementing robust internal controls to prevent such insider threats.

