Inside a Ransomware Negotiation
This is not based on speculation. I interviewed three incident responders who negotiate with ransomware gangs for a living. Here is what the process actually looks like β from the moment the screen locks to the moment you get your data back (or don't).
Minute Zero: The Screen Changes
It is usually a Tuesday afternoon. Someone in accounting opens what looks like an invoice PDF. Their screen flickers. Files start changing extensions β .docx becomes .locked, .pdf becomes .encrypted. Within 90 seconds, every file the user has access to is unreadable. A text file appears on the desktop: "YOUR FILES ARE ENCRYPTED." It lists a Bitcoin amount β typically $15,000 to $150,000 for a small business β and a deadline. Pay within 72 hours or the price doubles. Pay within 7 days or your data is published online.
What happens in the first hour
0-15 minutes: The employee calls IT or the MSP. The IT person's first instinct β shut everything down β is usually wrong. Shutting down the computer destroys forensic evidence that could identify the ransomware strain. The correct move: disconnect from the network, leave the computer on. Most small businesses do not know this and reboot or shut down, making recovery harder.
15-30 minutes: If the business has an incident response retainer or cyber insurance, they call their breach coach. The breach coach activates a forensic firm. If they do not have insurance, the owner starts Googling "ransomware help" while panicking.
30-60 minutes: The forensic firm begins remote triage. They identify the ransomware strain (LockBit, BlackCat, Akira β different gangs, different negotiation strategies). They determine how it got in and whether it is still spreading. They isolate infected systems.
The Negotiation Is a Business Transaction
Here is something people do not realize about ransomware gangs: they operate like businesses. They have customer support portals. They have SLAs. They care about their "brand reputation" β if they develop a reputation for not decrypting files after payment, victims stop paying. So the major ransomware groups actually do provide working decryption tools after payment. Not because they are honest. Because it is good business.
The negotiation itself is handled by a professional incident response firm, not the victim. These negotiators have dealt with the same gangs dozens of times. They know which groups negotiate, which ones do not, and what each one's "floor price" typically is. Yes β you can negotiate with ransomware gangs. The initial demand of $150,000 often settles around $40,000-60,000. The negotiator's job is to stall, build rapport, and drive the price down while the forensic team works on alternative recovery options in parallel.
The negotiation playbook
- Day 1: Initial contact. "We need to verify you actually have the decryption key. Prove it by decrypting 3 files of our choosing." (This is standard β legitimate ransomware operators will do this. Scammers who just encrypted your data and ran won't.)
- Day 2-3: Price negotiation. "We cannot afford $80K. Our business is small. We can do $25K, and we need 48 hours to arrange the Bitcoin." The negotiator stretches the timeline β every extra day gives the forensic team more time to find an alternative.
- Day 3-5: Settlement or deadlock. If the negotiator gets the price down to an acceptable level and no alternative recovery is possible, the insurance company authorizes payment. If the business has no insurance, the owner makes the call.
Should You Pay? The Ethics Question
Law enforcement (FBI, CISA, Europol) uniformly tells you not to pay. Paying funds criminal enterprises. It marks you as someone who pays, making you a target for future attacks. And there is always a risk the decryptor will not work or will have a backdoor.
The FBI's official stance is clear: "The FBI does not support paying a ransom in response to a ransomware attack." But here is what one responder told me off the record: "The FBI does not run your business. They have never had to look an employee in the eye and say 'we cannot make payroll this month because the FBI told us not to pay.' I do not judge anyone who pays. I judge people who do not have backups."
The Part Nobody Talks About: After You Pay
You paid. You got the decryptor. Your files are back. You think it is over. It is not.
- You are now on a list. Ransomware gangs share "successful payment" data. You will be targeted again β probably by a different group β within 12-18 months.
- The decryptor is slow. Decrypting terabytes of data takes days, sometimes weeks. During that time, your business is limping along on partial access.
- Not everything decrypts cleanly. Databases especially. Corrupted records are common. You will find problems for months.
- The insurance renewal will hurt. Your premium will double or triple. Some carriers will drop you. You will need to demonstrate significant security improvements to get coverage again.
- The emotional toll is real. Every business owner I interviewed described the same thing: they could not sleep for weeks. They second-guessed every email. They developed what one called "ransomware PTSD" β a constant low-grade fear that it would happen again.
What Everyone Who Survives Says They Should Have Done
I asked every responder the same question: what is the one thing survivors universally wish they had done before the attack? The answer was unanimous:
"Tested their backups."
Not "had backups." Had tested backups. The companies that recovered fastest and cheapest were not the ones with the best security. They were the ones who had done a full test restore in the previous 90 days and knew exactly how long it would take and exactly what data they would lose. They did not negotiate. They did not pay. They wiped, restored, and were back online in 48 hours.
The companies that paid six figures were the ones whose "backups" were on the same network and got encrypted along with everything else.