Ransomware Negotiation Tactics and Real-Life Examples

June 23, 2026

Your files are locked. A countdown timer is ticking. And someone you’ve never met is demanding $2 million in Bitcoin before the clock hits zero.

For thousands of organizations every year, this isn’t a hypothetical; it’s Tuesday morning. And in that moment, the instinct is to panic, pay, and pray. But the organizations that come out ahead aren’t the ones who act the fastest. They’re the ones who act the smartest.

Ransomware negotiation has quietly evolved into a professional discipline, complete with its own playbook, psychology, and practitioners. What looks like a hostage situation is actually a business transaction — one with leverage points, bluffs, and countermoves that most victims never think of using. By employing the right negotiation strategies, organizations may be able to protect critical data, reduce operational disruption, and minimize reputational damage.

While paying the ransomware may be the individuals first thought, the FBI strongly suggests not paying a ransom in response to an attack. Their reasoning states three separate factors: 

  1. No guarantees: Paying does not ensure your network or encrypted files will be successfully restored.
  2. Encourages more crime: Submitting to demands funds the perpetrators and incentivizes them to target you and others again.
  3. Operational funding: Ransomware payments provide capital for threat actors to grow their criminal enterprises. 

The U.S. Joint Ransomware Task Force (JRTF), co-chaired by the FBI and CISA, represents a coordinated national effort to combat the growing threat of ransomware attacks. The task force brings together government agencies and private sector partners to improve information sharing, strengthen operational coordination, and streamline the federal response to ransomware incidents. Through joint investigations, threat disruption operations, and the development of cybersecurity best practices, the JRTF plays a critical role in helping organizations prevent, respond to, and recover from ransomware attacks. Its creation marks a significant step toward a more unified and proactive approach to defending against evolving cyber threats.

However, some victims do choose to pay.

If your organization has decided to engage in negotiations with the threat actors, several steps should be taken before and during communications to help ensure the situation is managed as effectively and efficiently as possible. The following are recommended tactics and considerations for organizations that choose to pursue negotiations with threat actors.

  1. Gather Professional Assistance/a Team: Ransomware response requires coordinated decision-making across security, legal, business continuity, and executive leadership teams, with incident response leads managing containment, forensic analysis, regulatory obligations, and communications. Organizations should never respond to ransomware incidents alone; instead, they should engage cybersecurity experts, CERTs, ransomware recovery specialists, cyber insurance providers, and law enforcement to ensure a structured, legally compliant, and effective response. All communication with attackers should be centralized through a single authorized point of contact, while critical decisions such as ransom payment approval and business continuity actions remain restricted to C-level leadership.
  2. Begin Forensic Analysis: Forensic analysis should determine the extent of both encryption and potential data exfiltration by examining network logs, endpoint detection telemetry, and threat intelligence related to the ransomware variant involved. Incident response teams should confirm whether exfiltration occurred, identify the affected systems, and assess the types of data that may have been compromised, while preserving evidence for legal and regulatory requirements. Understanding the tactics of the ransomware group, such as RansomHub, can help predict the likelihood and timing of data exposure. 
  3. Monitor Leak Sites and Extortion Channels Early: Organizations should begin monitoring leak sites and underground channels as soon as there are indications that data may have been stolen. Threat actors increasingly use dedicated leak platforms to apply pressure, damage reputations, and create urgency around payment demands. Monitoring should extend beyond the organization’s primary name to include subsidiaries, brands, executive names, and other identifiable assets. Early visibility into leak activity can help organizations understand the threat actor’s tactics, anticipate public disclosures, and prepare appropriate communications responses.

    Many ransomware groups release small samples of allegedly stolen data before publishing larger datasets. Tracking these developments in real time allows organizations to validate claims, assess potential business impact, and make informed decisions without relying solely on information provided by the attacker.
  1. Establish Controlled Communication: Centralizing communication prevents mixed messages, unauthorized concessions, and tactical mistakes that can weaken the organization’s position. It also ensures that discussions remain consistent and aligned with legal, operational, and business objectives. The initial response typically acknowledges receipt of the ransom demand while requesting additional time for internal review and executive decision-making. Every interaction should be carefully documented to support legal, regulatory, insurance, and post-incident reporting requirements.
  2. Buy Time and Manage Expectations: Time is one of the most valuable assets during a ransomware incident. Every additional hour allows incident responders to collect forensic evidence, IT teams to validate backup and recovery options, legal teams to conduct sanctions screening, and leadership to evaluate potential courses of action.

    Experienced negotiators use legitimate business processes to slow the pace of discussions. Requests for additional approvals, verification of impacted assets, or assessments of operational impact can all create valuable breathing room. Negotiations may pause and resume multiple times as new information emerges, and recovery efforts progress. At the same time, negotiators can begin shaping expectations around what the organization can realistically pay by referencing constraints such as insurance coverage limits, financial approval requirements, or board-authorized spending thresholds.
  3. Keep Record of all Correspondence: If ransom negotiations are pursued, maintain detailed records of all communications and payment instructions to support law enforcement and investigative efforts. Additionally, request that the attackers demonstrate the validity of the decryption key by successfully decrypting several randomly selected files.

Instructure (2025) – On May 01, 2026, the threat actor group, ShinyHunters, revealed on their data leak site that they had allegedly breached the education technology company Instructure, a cloud-based education technology company best known for its Canvas learning management system, which schools and universities use to manage coursework, assignments, grading, and communication. The group had claimed to have stolen 280 million records connected to students and staff from over 8K colleges, school districts, and online education platforms. Using Canvas data export feature ShinyHunters was able to harvest “hundreds of gigabytes of user records, messages, and enrollment data”. According to the data leak site, ShinyHunters extended their deadline until May 12, claiming some of the affected institutions were engaging with the group.

In a statement on May 11, Instructure, announced they had reached an “agreement” with ShinyHunters to prevent recently breached data from being leaked. The company also disclosed that ShinyHunters had returned the stolen data and provided proof of destruction. ShinyHunters removed the warning from their leak site and posted a press statement saying they had no comment and all data had been destroyed. The FBI has warned against paying ransoms, noting that doing so does not guarantee threat actors will refrain from selling stolen data. However, the company said it acted in what it believed was the best interest of its “community”.

On May 12, the U.S. House Committee on Homeland Security requested Instructure executives to testify on the two cyberattacks by ShinyHunters on the company. The Homeland Security Committee said the repeated breaches raise “serious questions” about Instructure’s incident response practices and its ability to safeguard the data in its possession. The committee asked Instructure to participate in a briefing by May 21 to address both incidents, including the scope of the compromised data, containment and notification measures, and the company’s coordination with federal agencies.

CWT Global (2020) – In July 2020, the ransomware group Ragnar Locker infiltrated U.S. travel management company, CWT’s network, shutting down more than 30,000 computers and exfiltrating sensitive corporate data. After the attack, the threat actors demanded a $10 million ransom in exchange for a promise not to publicly release the stolen information. To demonstrate the credibility of their threat, Ragnar Locker directed CWT to a password-protected press release hosted on a hidden section of the group’s website, detailing the impending data leak.

Facing significant financial challenges caused by the COVID-19 pandemic, CWT reportedly negotiated the ransom demand down to $4.5 million. The payment was ultimately made in Bitcoin, after which Ragnar Locker claimed to honor its agreement by deleting the stolen data. The group provided CWT with credentials to access a cloud storage repository containing the exfiltrated files and removed the prepared leak announcement from its website.

In an unusual ending to the incident, Ragnar Locker also shared recommendations for improving cybersecurity defenses. Among their suggestions were stronger internal security policies and employee awareness measures, arguing that antivirus software alone is often insufficient to prevent sophisticated ransomware attacks.

University of California San Francisco (2020) – In June 2020, the University of California, San Francisco (UCSF) became the victim of a significant ransomware incident when cybercriminals encrypted critical servers and data belonging to the institution. The attack was carried out by operators of the NetWalker ransomware, a notorious malware strain responsible for numerous high-profile extortion campaigns. Although UCSF’s School of Medicine was heavily involved in leading COVID-19 antibody testing research at the time, university officials stated that the attack was not specifically directed at the institution.

After gaining access to UCSF’s network, the attackers encrypted important files and demanded a substantial ransom for their release. Ultimately, the university agreed to pay more than $1 million to the cybercriminals in exchange for a decryption key and assurances that copies of the stolen data would be returned or destroyed.

According to university officials, the payment enabled the restoration of access to critical files and systems. While UCSF declined to disclose the exact nature of the data involved, it emphasized that there was no evidence suggesting that patient medical records had been compromised during the incident.

While negotiating with ransomware attackers may appear to be the quickest path to recovery, organizations should approach that decision with extreme caution. Paying a ransom can fund future criminal operations, incentivize additional attacks, and potentially mark an organization as a willing target for future extortion attempts.

Perhaps most importantly, payment offers no certainty. Threat actors may fail to provide a working decryption key, demand additional payments, or retain stolen data despite receiving the ransom. As a result, ransomware negotiation should never be viewed as a guaranteed solution.

The most effective defense against ransomware remains preparation: maintaining secure backups, implementing strong cybersecurity controls, developing a tested incident response plan, and engaging experienced legal, cybersecurity, and negotiation professionals when an attack occurs. By focusing on resilience rather than reaction, organizations can reduce the impact of ransomware incidents and make informed decisions that align with both their operational needs and long-term security objectives.


Learn how DarkOwl can help. Contact us.

See why DarkOwl is the Leader in Darknet Data

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.