Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Insider Ransomware Negotiator Leaked Victim Strategies to BlackCat, Driving $75M in Payments

A DigitalMint negotiator secretly shared victims' insurance limits and negotiation tactics with the BlackCat ransomware gang, leading to over $75 million in ransom payouts. The incident highlights the need for SOC 2‑aligned access controls and third‑party audit evidence.

LiveThreat™ Intelligence · 📅 July 14, 2026· 📰 bitdefender.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
bitdefender.com

Insider Ransomware Negotiator Leaked Victim Strategies to BlackCat, Driving $75 M in Payments

What Happened — A negotiator employed by DigitalMint, Angelo John Martino III, secretly fed the BlackCat (ALPHV) ransomware gang confidential details about victims’ cyber‑insurance limits, internal negotiation positions, and financial circumstances via a hidden tab in the same negotiation panel he used for legitimate work. Between April and September 2023, five of his clients paid more than $75.3 million in ransom, amounts likely inflated by the insider’s disclosures.

Why It Matters for Compliance & Audit Readiness —

  • The case shows how privileged access to incident‑response tools can be abused, reinforcing the need for SOC 2‑aligned access‑control policies and continuous monitoring of privileged actions.
  • It underscores the importance of third‑party risk management: incident‑response firms must be vetted, and their staff activities auditable to satisfy SOC 2 vendor‑management controls.
  • An immutable audit trail and segregation of duties become critical evidence when demonstrating SOC 2 compliance after an insider‑driven breach.

Who Is Affected — Hospitality, non‑profit, and financial‑services organizations that engaged external negotiators, as well as the incident‑response service provider (DigitalMint) itself.

Recommended Actions —

  • Perform a privileged‑access review of all third‑party negotiation platforms and enforce least‑privilege principles.
  • Deploy continuous monitoring and immutable logging of every action within negotiation tools; retain logs as SOC 2 audit evidence.
  • Re‑evaluate third‑party contracts to include mandatory security‑awareness training, insider‑threat detection clauses, and right‑to‑audit provisions.

Source: Bitdefender Blog

Technical Notes — The insider used a hidden interface within the BlackCat negotiation panel to exfiltrate policy limits and negotiation strategies. No software vulnerability was disclosed; the breach resulted from insider misuse of legitimate credentials. Source: same article

📰 Original Source
https://www.bitdefender.com/en-us/blog/hotforsecurity/ransomware-negotiator-working-other-side ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →