What is ransomware negotiation?
Ransomware negotiation is the bargaining between a victim organization and an extortion group over the size and terms of a payment. It covers the opening demand, the exchanges that follow, and any settlement reached, whether for a decryption key, for a promise to delete stolen data, or for both. It is conducted through a channel the attacker controls, usually a chat portal reached over Tor, and in most cases by an incident response or specialist negotiation firm acting for the victim rather than by the victim directly.
How a ransomware negotiation unfolds
A study of 41 authentic ransomware chat logs, drawn from 16 private and 25 open-source incidents, identifies three phases: a proof-of-life phase, a bargaining phase, and a support phase (Georgiou, Giebels, Oostinga and Spithoven, Computers in Human Behavior, 2026).
Contact does not always begin with a demand. The joint CISA and FBI advisory on Akira records that its operators "do not leave an initial ransom demand or payment instructions on compromised networks and do not relay this information until contacted by the victim," who must reach them through a .onion address. The opening move belongs to the organization that was attacked.
In the proof-of-life phase the attacker is asked to demonstrate that a working decryptor exists, typically by decrypting two or three test files. Intel 471 characterizes this as "a validation checkpoint, not a reassurance". It establishes that the key functions on the sample, and nothing beyond that. Bargaining follows, and Intel 471 puts its usual duration at several days to a week or two. In the support phase, groups that have been paid often provide sustained technical help with the decryptor, because a reputation for working tooling is what makes the next victim pay.
What sets the price
Opening demands are usually sized against the victim's finances rather than against the damage done. Intel 471 reports that operators "commonly ask for amounts roughly in the 1% to 5% range of a victim's revenue."
The state of the victim's backups moves the number further than anything said at the table. In a Sophos survey of 2,974 organizations, median demands ran $2.3M where backups had been compromised against $1M where they had not. Those organizations were nearly twice as likely to pay, 67% against 36%, and they settled far closer to the asking price, paying an average of 98% of the demand where organizations with intact backups negotiated down to 82%. The attacker is pricing the victim's alternative to paying, and has usually established what that alternative is worth before the conversation starts.
Headline averages are a poor guide to any individual case. Coveware by Veeam put the average payment in Q2 2026 at $1,880,612 and the median at $150,000. The average rose 176% over the quarter while the median fell 50%, a divergence driven by a small number of very large settlements.
What paying does not buy
Payment settles a transaction with a counterparty whose obligations end when the cryptocurrency clears. When the National Crime Agency took control of LockBit's infrastructure in February 2024, it found that "some of the data on LockBit's systems belonged to victims who had paid a ransom to the threat actors, evidencing that even when a ransom is paid, it does not guarantee that data will be deleted". A later NCA statement added that investigators found numerous cases where the decryptor supplied to paying victims did not work.
That has changed how the exfiltration-only case is treated. Where the attacker holds stolen data but has encrypted nothing, Coveware recorded the payment rate falling from 19% in Q3 2025 to 15% in Q2 2026, observing that paying to suppress the spread of stolen data has "de minimis to zero utility".
Nor does a settlement close the route the attacker used. Black Kite rescanned organizations drawn from publicly disclosed ransomware cases and found 43.5% still carrying critical vulnerabilities after their incident was public. The FBI and CISA position, stated in the Akira advisory, is that they "do not encourage paying ransom as payment does not guarantee victim files will be recovered."
Why recovery capability decides the outcome
Negotiating leverage is established before the first message is sent, and attackers work to remove it deliberately. Mandiant's M-Trends 2026, drawn from more than 500,000 hours of incident response during 2025, describes the shift plainly: "Ransomware groups are no longer just encrypting data; they are actively destroying the ability to recover," targeting backup infrastructure, identity services and virtualization management planes.
The attempt is close to universal. Sophos found 94% of ransomware-hit organizations said attackers tried to compromise their backups, with success rates running from 30% in IT, technology and telecoms to 79% in energy, oil, gas and utilities. Where the attempt succeeded, median recovery costs reached $3M against $375K, and 26% were fully recovered within a week against 46% of those whose backups came through intact.
Time is on the attacker's side in the approach as well. Mandiant reports global median dwell time rising to 14 days in 2025 from 11 the year before, and the median interval between initial access and handoff to a second threat group collapsing to 22 seconds. Encryption remains the dominant form of leverage even as data theft grows around it, present in 78% of the extortion cases Unit 42 handled in 2025.
The sanctions and reporting position
A payment is a transaction that may be regulated. The operative US guidance remains OFAC's September 2021 advisory, which applies strict liability: a person subject to US jurisdiction "may be held civilly liable even if such person did not know or have reason to know that it was engaging in a transaction that was prohibited." The same advisory states that steps taken before an attack to reduce extortion risk, "such as those highlighted in the Cybersecurity and Infrastructure Security Agency's (CISA) September 2020 Ransomware Guide, will be considered a significant mitigating factor in any OFAC enforcement response," and treats a complete self-initiated report to law enforcement as a further mitigating factor. Backup posture therefore bears on the sanctions position as well as the negotiating one.
Statutory restrictions on payment are narrower than they are often described. In the United States, states including North Carolina, Florida and Tennessee restrict ransom payment by public-sector entities, and no state restricts payment by private organizations. North Carolina's statute also bars communicating with the attacker. The reporting obligations under CIRCIA are not in force as of August 2026, the final rule being unpublished. The United Kingdom has committed to developing a targeted ban on public-sector payment through the Cyber Security and Resilience Bill, which has not been enacted. Obligations differ by jurisdiction, sector and insurance position, and the applicable ones are a matter for an organization's own counsel.
Ransomware negotiation and ARTESCA
Where backup data is held on storage the attacker cannot alter, the leverage described above does not accumulate. Scality ARTESCA implements S3 Object Lock in both governance and compliance modes, with retention periods and legal holds. Object Lock requires S3 Versioning and protects individual object versions, so a delete request naming a locked version is refused.
The mode determines what an attacker holding credentials can undo. Compliance mode admits no exception before the retain-until date, including for the account root. Governance mode leaves a deliberate escape hatch: an identity holding the s3:BypassGovernanceRetention permission that sends x-amz-bypass-governance-retention:true can shorten retention or delete the protected version. Compliance mode is the configuration that removes the option.
Scality's ARTESCA Cyber Guarantee commits a one-time $100,000 payment where an external cyberattack encrypts or deletes ARTESCA-held data, subject to defined conditions including at least 50 TB licensed in production, ARTESCA 4.1.3 or later on a supported release, Object Lock in compliance mode, and written notice within 48 hours. It excludes exfiltration unaccompanied by encryption or deletion, and credentials compromised outside ARTESCA.
Related terms
- Backup tampering: unauthorized alteration, encryption or deletion of backup data, catalogs or configuration.
- S3 Object Lock: the API mechanism that applies WORM retention to individual object versions.
- Safe copy isolation: keeping a known-good copy separated from the environment it protects.
- Clean room recovery: restoring into a known-clean environment rather than back into a compromised one.
- Administrative blast radius: how much infrastructure and data a single administrative identity can reach or destroy.
