Skip to content
Security Notes

How ransomware negotiation actually works

By Elias Lankinen11 min read

The eight-hour conversation nobody wants to have

Somewhere right now, in a chat window that looks a lot like a retail help desk, a stranger is typing to a criminal. The stranger is a professional negotiator hired to represent a hospital, a school district, or a mid-sized manufacturer whose files were encrypted overnight. The criminal, often working from a "support portal" the gang built for exactly this purpose, has opened with a number: pay this, in Bitcoin, within 48 hours, or we publish everything we stole. What happens over the next several days is not the Hollywood version of a hostage crisis. It is closer to a tense B2B procurement dispute conducted between two parties who despise each other, one of whom has already broken in and rifled through the drawers. Understanding how that conversation actually unfolds, who is in the room, what leverage each side holds, and why the whole model is quietly breaking down, tells you more about modern cybercrime than any headline about a "sophisticated attack" ever will.

Source: Wikipedia, WannaCry ransomware attack
Source: Wikipedia, WannaCry ransomware attack

From smash-and-grab to a business with a sales funnel

Early ransomware was a numbers game. The 2017 WannaCry outbreak locked hundreds of thousands of machines and demanded a few hundred dollars each, with no meaningful way to haggle. That model has almost entirely given way to what the industry calls "big game hunting": fewer targets, far larger demands, and a genuine back-and-forth. The turning point was the invention of double extortion, the practice of stealing a copy of the victim's data before encrypting it, so the attacker has a second threat in reserve: pay, or we leak. According to Check Point Research, the first well-documented case came in November 2019, when the Maze group hit the security firm Allied Universal, demanded 300 bitcoin (roughly $2.3 million at the time), and, when Allied refused, published about 700 MB of stolen files as a warning shot, claiming it was only 10 percent of what they held. Maze built a public "leak site" to name and shame holdouts, and rivals including REvil, DoppelPaymer, Clop, and LockBit copied the playbook within months. That single innovation reshaped every negotiation that followed. Encryption alone can be defeated by good backups; if you can restore your systems from a clean copy, you never need to talk to the attacker at all. Stolen data cannot be restored away. It is this shift toward theft, not locking, that keeps victims at the table, and the data confirms it: Coveware reported that data exfiltration featured in the overwhelming majority of its cases through 2025, with some quarters approaching universal. The most vivid proof that these are businesses came in February 2022, when a Ukrainian researcher leaked more than 60,000 internal chat messages from the Conti gang after it declared support for Russia's invasion. As Varonis documented, the logs revealed an organization with HR, payroll, performance reviews, and a research-and-development team, arguing about salaries and buggy code like any dysfunctional software company.

Who is actually in the room

The victim almost never negotiates directly. Once an attack is discovered, a small crisis team assembles, and its makeup scales with the size of the organization. As TechTarget's reporting describes, a small business might have a single overwhelmed IT manager, while a large enterprise fields a chief information security officer, outside legal counsel, a "breach coach" (a lawyer who specializes in orchestrating incident response), a digital-forensics firm, and, crucially, the cyber-insurance carrier that may be footing the bill. The professional negotiator sits at the center of this. These specialists usually work for incident-response firms or insurers, and their job blends two skills that rarely coexist: the technical fluency to verify what the attacker is claiming, and the composure to slow down a terrified client and a hostile criminal at the same time. They identify themselves to the attacker only as a third-party representative, never naming their firm or the specific insurer behind them, because any hint of deep pockets moves the number in the wrong direction. The first job is not to bargain but to buy time and gather intelligence. Before anyone discusses money, the team needs to answer questions the attacker would rather they not ask. What was actually stolen, as opposed to what is merely claimed? Does this particular gang have a track record of handing over working decryption keys after payment? Is the group, or the wallet it is using, on a sanctions list, which would make paying a federal crime regardless of the circumstances?

Proof of life

Any negotiator will tell you the same thing: never take the criminal's word for anything. So the early phase of nearly every negotiation involves demanding evidence, borrowing the language of kidnapping cases, where you insist on "proof of life" before paying. There are two proofs that matter. The first is proof of decryption. The victim sends two or three small, low-sensitivity encrypted files and the attacker returns them decrypted, demonstrating that the key they are selling actually works. Group-IB notes that gangs often offer this test for free, because it builds exactly the credibility and momentum they need to close the deal. The second is proof of exfiltration: a file tree or a sample of genuinely sensitive stolen documents, to establish that the threat to leak is real and not a bluff by someone who only managed to encrypt. Both proofs cut both ways. They reassure the victim, but they also hand the attacker leverage, because a directory listing of the crown-jewel data is itself a demonstration of how bad publication would be. This is the recurring theme of the whole exchange: almost every move that reduces the victim's uncertainty also sharpens the criminal's knife.

How the haggling really goes

The tactics on both sides are surprisingly legible once you have read enough transcripts. The attacker's opening number is not arrived at randomly. The Conti leaks showed operators doing open-source research on their targets, pulling annual revenue figures for public companies, and hunting specifically for cyber-insurance policies, because a policy tells them both the ceiling on what can be paid and that someone else will reimburse it. The demand is calibrated to hurt but stay payable. Then come the pressure mechanics. Deadlines run from 24 hours to about a week, with a countdown timer on the leak site and the threat of publication or of the ransom doubling when it expires. LMG Security has described attackers deliberately striking on Friday afternoons, so-called "Forensic Fridays," to catch skeleton weekend staff and amplify the panic. Operators alternate between menace and a weird, salesman-like helpfulness, sometimes offering a "security report" explaining how they got in, or a holiday discount, as if they were closing a quarter. The victim's side, meanwhile, is almost always able to move the number down. One negotiation firm told TechTarget that essentially all of its cases ended in a lower payment; in one LMG matter, simply asking whether the attacker was open to negotiating dropped an $800,000 demand to $600,000 on the spot. Kevin Kline of the Aggeris Group put the core tactic bluntly: "If we get a big ransom demand, $1 million or more, and we counter with 'We can pay you $100,000 in an hour,' they usually take it." Certain, immediate cash beats a larger sum that might never arrive, especially for an affiliate who has to split proceeds and move on. A single case reported by The Daily Beast captures the rhythm. Conti opened above $2 million. The victim's first counteroffer was waved away as "too low." After days of back-and-forth the gang issued an ultimatum, "$1.1m. We will never go lower and this offer is valid for 48 hours," and the deal closed at just over a million, roughly half the opening ask. The victim's final message was a plea: "Please confirm that you will delete it everywhere and give us proof of deletion." The attackers went silent for seven days after being paid before confirming anything.

Paying is its own ordeal

Suppose the two sides agree on a figure. The transaction that follows is neither simple nor safe. Payment is almost always in cryptocurrency, usually Bitcoin, occasionally the privacy coin Monero (sometimes with a discount for paying in Monero, because it is harder to trace). Most victims do not hold crypto, so specialist firms acquire it, and the transfer itself can take time to confirm on the blockchain while the deadline ticks.

Source: Wikimedia Commons, photo by Mike Cauldwell (Casascius).jpg)
Source: Wikimedia Commons, photo by Mike Cauldwell (Casascius)

The counterintuitive fact about crypto is that Bitcoin is not anonymous; it is pseudonymous, and every transaction is permanently public. That is why the Colonial Pipeline case ended the way it did. In May 2021 the pipeline operator paid the DarkSide gang 75 bitcoin, about $4.4 million, to end a shutdown that triggered panic fuel-buying across the US Southeast. Weeks later, the Department of Justice announced it had followed the money across the blockchain and seized roughly 63.7 of those bitcoin, then worth $2.3 million, from a wallet whose key the FBI had obtained. Traceability is a real, if inconsistent, check on the whole economy.

Source: Wikimedia Commons
Source: Wikimedia Commons

The part everyone gets wrong: paying does not end it

Here is the most important misconception to puncture. People imagine the ransom as a transaction: money in, problem out. It is not. It is a payment for a promise from someone who has already proven they lie for a living. Decryption keys, when they work, are slow and imperfect; large environments can take days or weeks to restore, and some files never come back clean. And the deletion promise, the thing the victim in that Conti chat begged for, is close to worthless. Group-IB has investigated cases where data the gang swore was destroyed remained accessible afterward. The "deletion log" an operator sends as proof is a screenshot, nothing more. The stolen data may be deleted, or retained as future leverage, or quietly sold to a second buyer, or dumped months later when the group needs cash or gets busted and its servers are seized. You cannot audit a criminal's hard drive. Paying to suppress a leak buys, at best, a probability, not a guarantee. This is precisely why the calculus has been shifting, and shifting fast.

The market is cracking

The single clearest trend in ransomware right now is that fewer victims are paying. Coveware, which reports on its own caseload, found the payment rate fell to about 23 percent in the third quarter of 2025, which it called a historic low, with extortion-only cases (theft, no encryption) lower still at 19 percent. Chainalysis, which traces payments on the blockchain and so measures something slightly different, put the full-year 2025 payment share around 28 percent and total on-chain ransom payments near $820 million, down about 8 percent even as the number of attacks rose by half. The two firms use different methodologies and their exact figures diverge, but they point the same direction: more attacks, less money. The amounts are volatile enough to defy any tidy narrative. Coveware's average payment swung from over $1.1 million in the second quarter of 2025 to about $377,000 in the third, with the median landing near $140,000, distorted by a handful of enormous outlier demands against a long tail of smaller ones. What is steadier is the strategic picture Chainalysis describes: with large enterprises increasingly refusing to pay, gangs are pivoting to a higher volume of smaller and mid-sized victims, raising typical demands while their overall take falls. Why the change? Better backups and incident-response muscle memory mean more organizations can simply restore and walk away. Law enforcement takedowns of groups like LockBit have eroded trust that a given gang will even be around to honor a deal. And the recognition, spreading through boardrooms and insurers, that paying does not reliably make the problem disappear.

The uncomfortable policy question

If paying funds the crime, sustains the gangs, and does not even guarantee relief, why is it legal at all? Increasingly, it may not be. The US has not banned payment, but it has made it hazardous. An advisory from the Treasury's Office of Foreign Assets Control, first issued in October 2020 and updated in September 2021, warns that paying a ransom to a sanctioned person or group, and many operators are tied to Russia, Iran, or North Korea, can itself violate sanctions law on a strict-liability basis, meaning you can be penalized even if you had no idea who was on the other end. The advisory's carrot is that promptly reporting the attack to the FBI and cooperating counts as a significant mitigating factor if enforcement follows. Britain has gone further. Following a consultation that opened in January 2025, the UK government confirmed in July 2025 that it will prohibit public-sector bodies and critical-infrastructure operators, hospitals, schools, and transport among them, from paying ransoms at all, while requiring private companies to notify the government before they pay. The logic, argued forcefully by former National Cyber Security Centre chief Ciaran Martin, is that as long as paying is legal and insurable, the crime stays profitable; remove the payday for an entire class of targets and you remove the incentive to hit them. Critics counter that a ban does not make the hostage situation go away. A hospital with locked systems and no backups still has patients, and a rigid prohibition could push desperate victims into paying secretly and reporting nothing, blinding the very authorities the policy means to inform. That is the open question worth watching. Ransomware negotiation exists because we have quietly decided, case by case, that paying criminals is sometimes the least-bad option. The moment enough victims, or enough laws, decide otherwise, the entire carefully professionalized apparatus of portals, negotiators, and proof-of-life demos loses its reason to exist. The numbers suggest that moment is arriving faster than the gangs would like. Whether it arrives as a market slowly starving or as a legal cliff imposed all at once will shape the next several years of cybercrime, and the answer is being written right now, one grim chat window at a time.

Sources

  1. Coveware, "Insider Threats Loom while Ransom Payment Rates Plummet" (Q3 2025 report), 2025
  2. Chainalysis, "Crypto Ransomware 2025: 35.82% YoY Decrease in Ransomware Payments", 2026
  3. TechTarget (Informa), "Ransomware negotiations: An inside look at the process", 2024
  4. Group-IB, "Ransomware Negotiation: What Enterprises Should Know", 2024
  5. Check Point Research, "Ransomware Evolved: Double Extortion Attacks", 2020
  6. Varonis, "ContiLeaks: Ransomware Gang Suffers Data Breach", 2022
  7. The Daily Beast, "Inside a Ransomware Negotiation: This Is How 'Asshole' Russian Hackers Keep Shaking Down Companies", 2022
  8. US Department of Justice, "Department of Justice Seizes $2.3 Million in Cryptocurrency Paid to the Ransomware Extortionists Darkside", 2021
  9. US Treasury, Office of Foreign Assets Control, "Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments", 2021
  10. World Economic Forum, "UK to ban ransom payments to cyber criminals", 2025