Ransomware is a cybersecurity threat that holds organizations' data hostage until a ransom is paid. Past research has mainly focused on the technical aspects of prevention or the ransom payment when an attack occurs. Little attention has been devoted to the strategies of organizations that lead to this payment. In this study, we analyze 41 authentic chat logs from 16 private and 25 open-source ransomware incidents, focusing on the phases of ransomware negotiations and the influence strategies employed by both threat actors and victims. The analysis identifies three distinct phases in ransomware negotiations: the proof-of-life phase, the bargaining phase, and the support phase. Across these stages, threat actors predominantly use being credible and direct pressure, while victims rely on rational persuasion and kindness to secure favorable terms. Both parties adapt their strategies as the negotiation progresses and phases change, moving from establishing what data is stolen to exchanging offers about the ransom amount. This analysis was complemented by a qualitative exploration of how these strategies manifest in ransomware negotiations. This paper provides key insights into the dynamics between threat actors and victim companies by outlining negotiation strategies and stages. Understanding these dynamics better prepares decision-makers and cybersecurity experts for the negotiation communication process with the threat actors following ransomware attacks. • Identifies three phases in ransomware negotiations: proof of life, bargaining, and support. • Examines influence strategies used by both threat actors and victims. • Shows strategic shifts across negotiation phases, adapting to evolving dynamics. • Highlights similarities between ransomware, hostage, and business negotiations. • Provides actionable insights for cybersecurity professionals to enhance resilience.
Georgiou et al. (Sun,) studied this question.