When the Responder Is the Threat — Ransomware Negotiators, Insider Trust, and Incident Response Ethics
ID: 2b67e2a7-e27c-5111-a6e0-f475edb8c9cb
STIX ID: report--2b67e2a7-e27c-5111-a6e0-f475edb8c9cb
Feed Name: Security Boulevard
**Executive summary:** The DOJ reported that a former ransomware negotiator, Angelo Martino, pleaded guilty to conspiring with BlackCat/ALPHV affiliates in 2023 by leaking victims' negotiation strategies and insurance limits to maximize ransom payments; the case involved multi-million-dollar extortion, asset seizures, and guilty pleas by associates, and the document advocates strict segregation of duties, pre-vetted responders, logged threat-actor communications, revised engagement letters, and sanctions-aware payment discipline to mitigate insider risk in ransomware incidents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
