PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 28, 2026Computers in Human Behavior2 citationsOpen Access

Engaging with cybercriminals: phases and influence strategies in ransomware negotiations.

View Full Paper
MGMichail GeorgiouEGEllen GiebelsMOMiriam S. D. Oostinga

Key Points

  • The aim is to analyze the phases and influence strategies used in ransomware negotiations between threat actors and victims.
  • Analysis of 41 chat logs from 16 private and 25 open-source ransomware incidents.
  • Identification of three negotiation phases: proof-of-life, bargaining, and support.
  • Qualitative exploration of strategies employed by both parties during negotiations.
  • Identified three distinct phases in ransomware negotiations: proof-of-life, bargaining, and support.
  • Threat actors primarily used credibility and direct pressure, while victims relied on rational persuasion and kindness.
  • Outlined shifts in strategies as negotiations progressed, highlighting the adaptive nature of both parties.

Abstract

Ransomware is a cybersecurity threat that holds organizations' data hostage until a ransom is paid. Past research has mainly focused on the technical aspects of prevention or the ransom payment when an attack occurs. Little attention has been devoted to the strategies of organizations that lead to this payment. In this study, we analyze 41 authentic chat logs from 16 private and 25 open-source ransomware incidents, focusing on the phases of ransomware negotiations and the influence strategies employed by both threat actors and victims. The analysis identifies three distinct phases in ransomware negotiations: the proof-of-life phase, the bargaining phase, and the support phase. Across these stages, threat actors predominantly use being credible and direct pressure, while victims rely on rational persuasion and kindness to secure favorable terms. Both parties adapt their strategies as the negotiation progresses and phases change, moving from establishing what data is stolen to exchanging offers about the ransom amount. This analysis was complemented by a qualitative exploration of how these strategies manifest in ransomware negotiations. This paper provides key insights into the dynamics between threat actors and victim companies by outlining negotiation strategies and stages. Understanding these dynamics better prepares decision-makers and cybersecurity experts for the negotiation communication process with the threat actors following ransomware attacks. • Identifies three phases in ransomware negotiations: proof of life, bargaining, and support. • Examines influence strategies used by both threat actors and victims. • Shows strategic shifts across negotiation phases, adapting to evolving dynamics. • Highlights similarities between ransomware, hostage, and business negotiations. • Provides actionable insights for cybersecurity professionals to enhance resilience.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Georgiou et al. (2026) studied this question.

synapsesocial.com/papers/69a287010a974eb0d3c02699https://doi.org/10.1016/j.chb.2026.108953
Ask AI
Helpful
Bookmark
Share
View Full Paper