Angelo Martino got 70 months this week for moonlighting as a ransomware negotiator who negotiated for the wrong side. He’s the third American security professional sentenced in connection with the BlackCat/Alphv operation, which tells you this isn’t a one-off bad apple story anymore. It’s a pattern. And if you’re the kind of person who assumed the biggest risk to your cybersecurity posture was some anonymous crew in a bulletproof-hosted data center, this week is a good time to reconsider who’s actually sitting at your incident response table.
The uncomfortable truth is that ransomware has professionalized faster than the industry meant to defend against it has. Gangs run affiliate programs. They have HR problems. They occasionally, apparently, have moles inside the companies hired to fight them. Let’s get into it.
The Guy You Hired To Save You Was Also On Their Payroll
Martino’s case is the specific, personal version of a much bigger structural problem. He wasn’t some low-level affiliate deploying encryptors. He was a negotiator, the person a victim organization brings in specifically because they’re supposed to be the adult in the room during the worst week of your professional life. Instead, prosecutors say he was feeding information back to BlackCat/Alphv and taking a cut of the ransom he was ostensibly negotiating down. Two other security professionals have already been sentenced in related schemes. Three is not a coincidence, it’s a business model.
Here’s the part that should actually bother you: incident response and ransomware negotiation are trust relationships built almost entirely on credentials and reputation, not verification. You call a firm during a breach, you hand them access, logs, sometimes root on production systems, and you trust that the badge on their website means something. Most of the time it does. But “most of the time” isn’t a control, it’s a hope.
Ransomware Gangs Run Better Affiliate Programs Than Some SaaS Startups

Unit 42’s writeup on The Gentlemen ransomware operation is worth reading past the cute branding. What’s driving its growth isn’t a novel exploit or some breakthrough in evasion. It’s the affiliate model: recruit operators, give them tooling and a support structure, take a cut, scale horizontally. That’s a franchise, not a hacking crew. The “gentlemen” part is presumably ironic, since there’s nothing polite about double-extorting a hospital, but the business mechanics are the same ones that make any distributed sales org effective. Lower the barrier to entry, standardize the product, let volume do the work.
This matters for defenders because it changes who you’re actually up against. You’re not defending against one sophisticated actor with bespoke tradecraft. You’re defending against dozens of affiliates with varying skill levels, all running a shared playbook, all incentivized to move fast and get paid. Threat detection built around a handful of known TTPs from a single group ages badly against a franchise model where the operators rotate but the tooling stays consistent. That’s actually good news for defenders who focus on the tooling and infrastructure fingerprints rather than chasing individual actor attribution.
Nobody Grades Their Own Homework Like A Vendor Progress Report
Microsoft published its latest Secure Future Initiative progress report this week, and credit where it’s due: the initiative exists because of real, embarrassing incidents, and continuous public reporting on it beats silence. But read it next to the Martino sentencing and the framing gets a little rich. A self-authored report card on “AI-powered defense” and “secure foundations” is not the same thing as independently verified security. It’s a marketing document with better production values than most, graded by the company that wrote the assignment.
None of this is an argument against vendor transparency. It’s an argument against treating vendor self-assessment as equivalent to your own risk management. Big platform providers publishing progress reports is a fine input to your threat model. It is not a substitute for it.
What Actually Holds Up When You Can’t Fully Trust The Insiders
None of this means don’t hire an incident response firm, or don’t trust your vendors, or start treating every consultant like a suspect. It means defense in depth has to include the people and firms with privileged access, not just the network perimeter. A few things that actually move the needle:
- Vet incident response and negotiation firms the way you’d vet a managed service provider with domain admin, not the way you’d vet a conference speaker. Ask about staff background checks, subcontractor use, and who specifically will have hands on your environment.
- Scope third-party access tightly and time-box it. Nobody external needs standing credentials after the engagement ends, and every account they used during it should get rotated and reviewed, not just disabled.
- Treat ransomware negotiation and incident response as activities that need their own oversight, ideally with a second party, counsel or a separate firm, reviewing communications and decisions in real time rather than after the fact.
- Build threat detection around behavior and infrastructure patterns rather than actor attribution, since affiliate-model gangs like The Gentlemen rotate operators faster than you can update a watchlist.
- Harden the boring stuff before you ever need a negotiator: brute-force protections on remote access, tested backups that don’t rely on production credentials, and an incident response plan that assumes the outsiders you call in are a risk surface too, not just a resource.
Security hardening isn’t just patch cadence and firewall rules anymore. It’s asking harder questions about the humans who get privileged access when things go wrong, because apparently some of them have a second employer.
Sources
- Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
- No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
- Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
