Insider Ransomware Negotiator Leaked Victim Strategies to BlackCat, Driving $75 M in Payments
What Happened — A negotiator employed by DigitalMint, Angelo John Martino III, secretly fed the BlackCat (ALPHV) ransomware gang confidential details about victims’ cyber‑insurance limits, internal negotiation positions, and financial circumstances via a hidden tab in the same negotiation panel he used for legitimate work. Between April and September 2023, five of his clients paid more than $75.3 million in ransom, amounts likely inflated by the insider’s disclosures.
Why It Matters for Compliance & Audit Readiness —
- The case shows how privileged access to incident‑response tools can be abused, reinforcing the need for SOC 2‑aligned access‑control policies and continuous monitoring of privileged actions.
- It underscores the importance of third‑party risk management: incident‑response firms must be vetted, and their staff activities auditable to satisfy SOC 2 vendor‑management controls.
- An immutable audit trail and segregation of duties become critical evidence when demonstrating SOC 2 compliance after an insider‑driven breach.
Who Is Affected — Hospitality, non‑profit, and financial‑services organizations that engaged external negotiators, as well as the incident‑response service provider (DigitalMint) itself.
Recommended Actions —
- Perform a privileged‑access review of all third‑party negotiation platforms and enforce least‑privilege principles.
- Deploy continuous monitoring and immutable logging of every action within negotiation tools; retain logs as SOC 2 audit evidence.
- Re‑evaluate third‑party contracts to include mandatory security‑awareness training, insider‑threat detection clauses, and right‑to‑audit provisions.
Source: Bitdefender Blog
Technical Notes — The insider used a hidden interface within the BlackCat negotiation panel to exfiltrate policy limits and negotiation strategies. No software vulnerability was disclosed; the breach resulted from insider misuse of legitimate credentials. Source: same article