// Context
About This Negotiation
This transcript documents a Akira ransomware negotiation with a redacted victim organisation.
The negotiation consisted of 170 messages exchanged over Unknown.
The initial ransom demand was $1.7M. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at
enquiries@binary-response.com — we will act promptly.
[Victim] — — Message 1/170
> Hello, I have seen your message that you left on our system.
[Victim] — — Message 2/170
> Hello are you there?
[Akira] — — Message 3/170
> Hello
[Akira] — — Message 4/170
> You've reached Akira support chat. Currently, we are preparing the list of data we took from your network. For now you have to know that dealing with us is the best possible way to settle this quick and cheap. Keep in touch and be patient with us. Do you have a permission to conduct a negotiation on behalf of your organization? Once we get a response you will be provided with all the details.
[Victim] — — Message 5/170
> Yes. I have the permission to handle this.
[Akira] — — Message 6/170
> Please wait for details.
[Akira] — — Message 7/170
> List.rar // 1.52 MB
[Akira] — — Message 8/170
> These files were taken from your network prior to encryption. You can pick 2-3 random files from the list and we will upload them to this chat as a proof of possession. To prove that we can properly decrypt your data you can upload 2-3 encrypted files to our chat and we will upload decrypted copies back.
[Victim] — — Message 9/170
> The rar file is password protected and cannot be extracted.
[Victim] — — Message 10/170
> However, we do not agree to send anything from us back to you. In order to prove that you have the decrypted key, you may send the key to us to partially decrypted them.
[Akira] — — Message 11/170
> Rar password is [redacted]
[Akira] — — Message 12/170
> We will send you the decryption key but payment first. If you want to test the tool send us a few non-significant files. Please do not complicate things.
[Victim] — — Message 13/170
> We are planning to do that. Could you let us know how to get those files safely while getting the files out?
[Victim] — — Message 14/170
> The correction to the above message is to planning to send you the files by tomorrow as all the folders are found with akira.txt
[Akira] — — Message 15/170
> We'll wait. Speed the things up.
[Victim] — — Message 16/170
> Hello, we had been trying to access the files on the list you provided, but it seems that the machine is not bootable and corrupted. Could you suggest an alternative file list for decryption?
[Akira] — — Message 17/170
> You can give us any encrypted files for a test decryption and ask for any files from the list as a proof.
[Victim] — — Message 18/170
> [redacted].jpg.akira // 192 KB
[Victim] — — Message 19/170
> [redacted].jpg.akira // 231 KB
[Victim] — — Message 20/170
> [redacted].jpg.akira // 119 KB
[Victim] — — Message 21/170
> [redacted].bmp.akira // 3.05 MB
[Victim] — — Message 22/170
> [redacted].bmp.akira // 3.05 MB
[Victim] — — Message 23/170
> [redacted].bmp.akira // 5.4 MB
[Victim] — — Message 24/170
> [redacted].bmp.akira // 2.29 MB
[Victim] — — Message 25/170
> We are submitting the above files.
[Akira] — — Message 26/170
> Please wait.
[Akira] — — Message 27/170
> decrypted.7z // 1.14 MB
[Akira] — — Message 28/170
> Please review.
[Victim] — — Message 29/170
> The files show the result correctly. Could you provide us the decrypted key?
[Akira] — — Message 30/170
> Do you need files for proof?
[Victim] — — Message 31/170
> If you could give us. Also let me know how to decrypted the rest of them.
[Akira] — — Message 32/170
> Give me a few paths to files you want to see from the list. After payment you will get the tool that will decrypt your systems.
[Victim] — — Message 33/170
> Are we talking about the list you sent in .rar file earlier? We believe you have the list of all files in your possession. Thus, letting us know the information is necessary as we unable to verify nothing much from our side as the files are encrypted.
[Akira] — — Message 34/170
> Let's move to payments discussion then. I'll let you know our demand shortly.
[Victim] — — Message 35/170
> You can send the evidence files for review; we'll naturally progress to discussing terms.
[Akira] — — Message 36/170
> Ok, we will send few random files.
[Akira] — — Message 37/170
> files.rar // 647 KB
[Victim] — — Message 38/170
> We think that the random files you sent us belong to us. What's next?
[Akira] — — Message 39/170
> We can proceed to payment options. I will let you know our demand shortly.
[Victim] — — Message 40/170
> Send details when they are ready.
[Akira] — — Message 41/170
> Wait a bit.
[Akira] — — Message 42/170
> So, we've gone through your files to define your financial abilities. We've been looking through your bank statements, net income, cyber liability limits, financial audits - all the info that might help us to calculate our demand to you. We're willing to set a $1,700,000 price for ALL the services we offer:
1) full decryption assistance;
2) evidence of data removal;
3) security report on vulnerabilities we found;
4) guarantees not to publish or sell your data;
5) guarantees not to attack you in the future.
Let me know whether you're interested in a whole deal or in parts. This will affect the final price.
[Victim] — — Message 43/170
> We've received your request. We are quite surprised by the figure you demand, having said the analysis on our financial data as we are running on a loss for several years. We sincerely hope to find a mutually understanding path forward.
[Akira] — — Message 44/170
> In case you of quick payment, we will be able to consider a discount. We are going to work with 7 figures though.
[Victim] — — Message 45/170
> We would like to inform you that our company doesn't have the means to meet your demand. We operate on a modest scale, and, like you, we have to provide for our people, especially in the post-COVID era. Thus making your request impossible for us. We would like to have our data back to resume our services. We kindly request your understanding and to consider the return of our data. We're open to discussing any feasible solutions.
[Akira] — — Message 46/170
> Our request is quite possible for a company like yours. We both know this. If you need our decryption services only, we can end this incident at $1,000,000. We won't go lower. This is a good price for getting back to business quick and without troubles.
[Victim] — — Message 47/170
> We acknowledge receipt of your message and understand the gravity of the situation you have placed us in. It is apparent from your communication that you believe our organization has the means to meet your demands. However, this assumption fails to reflect our current financial reality. We're reaching out under challenging circumstances that have perhaps not been fully visible from the outside. Despite our best efforts over the past five years, we've faced significant financial hurdles, reflected in our inability to issue dividends and our struggle to secure additional funding. Our financial avenues, unfortunately, are quite constrained. Given this perspective, complying with your request is comparable to trying to squeeze blood from a stone, which is why we have been unable to distribute dividends to our shareholders for the previous 5 years in a row. We are diligently striving to maintain our operations and assist our committed team amidst these challenging circumstances. With respect and understanding, we kindly ask if you could reconsider your current stance. Please restore our data so we can continue to provide our services. We greatly appreciate your understanding and kindly request that you consider restoring our data. We are eager to work through this situation with a positive outcome, and we sincerely hope to find a path forward that allows us to overcome this challenge.
[Akira] — — Message 48/170
> What do you have to offer?
[Akira] — — Message 49/170
> You have 24 hours to give us your decision regarding this deal. If you stay silent, we will announce the breach on our blog.
[Victim] — — Message 50/170
> We sincerely ask your understanding and a bit of additional time to resolve this. We will response back to you urgently as stated earlier we are sinceely request you to please advice on restoring our data to overcome this challenge.
[Akira] — — Message 51/170
> We can't and won't wait forever.
[Victim] — — Message 52/170
> Sorry to keep you waiting. We would like to request your understanding and empathy to guide us to a solution that has positive outcomes for both of us. We are dedicated to finding a way that minimizes damage to all parties involved.
[Victim] — — Message 53/170
> As stated earlier, we have continually run our business at a loss for many years, and we would like to address the issue in a manner that enables us to continue our business. To that end, we would like to suggest a $20,000 settlement offer, which reflects our genuine desire to handle this matter in a way that is both responsible and practical for us.
[Victim] — — Message 54/170
> Thank you in advance for considering our request to help us overcome this obstacle. We look forward to a positive response to support and help us.
[Akira] — — Message 55/170
> You can find your company name in our news column: [REDACTED URL] If you want this post to be removed, we have to agree on something.
[Akira] — — Message 56/170
> We will never accept such a small amount. You're offering us 20k against 1M. How do you think we will be able to agree? We will wait a bit more and then will cancel the deal. There is nothing to talk about at the moment.
[Victim] — — Message 57/170
> Hello and Good evening
[Akira] — — Message 58/170
> Hello. Have you managed to raise a decent amount?
[Victim] — — Message 59/170
> Good day, I was specifically appointed by the CEO to replace the colleague you were talking with and take the issue forward towards resolution. We understand the offer made to you was not respectful in view of your investment in this project. Having said that, a 7 figure sum is really beyond our possibilities. You are invited to look at our financial data ad see for yourself.
[Victim] — — Message 60/170
> Anyhow, we are willing to discuss your offer and build confidense in resolving the situation
[Akira] — — Message 61/170
> We are happy that you understand that the situations is serious. We are ready to work with you on the price in order to find a mutually profitable solution. Give us a renewed offer and I'll bring that to my leadership for a discussion.
[Victim] — — Message 62/170
> Thank you for your willingless to work on a mutually beneficial solution. I will promptly confer it to my boss. Meanwhile, it would help me in working with him if you could take us off your blog. It serves no one to have us there.
[Akira] — — Message 63/170
> The post will be removed after payment only. Give us an update from your boss today please. Thank you.
[Victim] — — Message 64/170
> It is a long weekend holiday in [redacted] and all banks are closed. You can check on Google. Apart from this, you are making it difficult. How does it hurt you to take us off the blog? I need to show some good faith on your side to make my boss follow. Believe me, it will make things much easier.
[Victim] — — Message 65/170
> We are willing to make the deal even though it is a significant effort, but to make it easier I need your assistance and consideration. You can always put us back on if things turn sour, which I don't think will happen as we want to make the deal.
[Victim] — — Message 66/170
> Thank you for your consideration
[Akira] — — Message 67/170
> We can remove the post after payment only. The faster you act, the sooner the post will be removed.
[Victim] — — Message 68/170
> Maybe this is a cultural difference between our cultures. But to strike a deal, which it seems both of us want we need some trust to exist. By not making this very small step towards us it makes my job more difficult. See, in the eyes of my boss you already caused us damage by putting us on. Anyhow, as I told you the full availability of management and bank opening is in 5 days. So we have time to work the deal out.
[Victim] — — Message 69/170
> Asking you to reconsider. Thank you.
[Akira] — — Message 70/170
> There are no cultural differences between us, it's just the way this business works. You were offering us pennies and was warned about publication.
[Victim] — — Message 71/170
> I suppose we are from different parts of the world and we are humans. So cultural difference are built in. But this is philosphy and we are here to do business. You were indeed offered a very modest amount by a colleague of mine. I was indeed unbecoming the situation. I am not him. Nevertheless I apologized and am showing significant will to reach a mutually liveable arrangement. To make it easier for me to make the deal and for you to get the money I respectfully asked you to make a mall step and show some good will towards us and me personally. Frankly, I do not understand your position. But again we are not here to philisophyze. I hope your position will not make the deal harder to reach. As I said before, the boss sees some damage as already done.I urge you to please rethink your position.
[Akira] — — Message 72/170
> I still do not see any decent offer from your side. We will take the post down later.
[Victim] — — Message 73/170
> Thank you. I take this as a positive sign. As mentioned before [redacted] is in holiday with most people out of reach. Doing my best to locate relevant stakeholders to get you a respectful offer. One thing I can say at this point is that you may have a mistake about our corporate identity. Maybe you think we are [redacted]. We are not. We are part of the group, but unfortunately for us a smaller and less successful part, at least financially. But again, I'm not running a bazaar here and will be back to you with an offer as soon as I get management approval. Looking forward to finalizing a deal.
[Akira] — — Message 74/170
> Standing by.
[Victim] — — Message 75/170
> Hello, despite the holiday, we were able to confer with the management and after going through some hurdles to secure an offer of $110,000 (one hundred and ten thousand US dollars). It seems respectable when you take into account that we are not the size and financial status you think we are. Hope for your understanding and looking forward to finalizing the deal. Thank you.
[Akira] — — Message 76/170
> Thank you for your offer. We're willing to accept $650,000 and get this over with you.
[Victim] — — Message 77/170
> Thank you. I will confer with the boss and be back to you as soon as I have his answer.
[Akira] — — Message 78/170
> We'll wait for your answer today.
[Victim] — — Message 79/170
> Thank you for the step you have made towards finding a liveable solution. Regretably, I must say that the number of $650,000 is waaaay above our capabilities. To illustarate my point, our financial results for the past years are of LOSS. If you allow me I can upload here the official financial reports, or youn simply Google them to see for yourself I am telling the truth.
[Victim] — — Message 80/170
> We do want to reach a deal both sides can live with. But $650,000 is a death sentence. In a matter of numbers my boss says he can add another $30,000 to make a total of $140,000. I hope you understand the true situation and the fact that to make it liveable for us and getting some payment for you the numbers have to be significnatly lower than you requested. Looking forward for your understamding of the true factual situation.
[Akira] — — Message 81/170
> Upload your reports, please. Meanwhile, I was able to get approval for an additional discount. We're ready to close this at $590,000.
[Akira] — — Message 82/170
> The post has been removed but it might be returned at any second. We hope to come to an agreement within 2-3 days and go our separate ways. We need a decent counter offer from your side to make a final step to finalization.
[Victim] — — Message 83/170
> Thank you for removing the post. AS for the numbers, Sorry, but it is not even close to our abilities. You are invited to see for yourself. Please look at line 21 from the top - Profit (loss) for the year.
[Victim] — — Message 84/170
> Balance_sheet_2023.jpeg // 200 KB
[Akira] — — Message 85/170
> Thank you for the report but it seems like a trick, we were waiting for verified signed documents. Anyway, even if it is true, we do not have real picture (your savings, your investments, your net assets etc.). We believe we're asking for a fair amount and are willing to close the deal.
[Victim] — — Message 86/170
> You are most invited to go online and check if it is a trick. It is certainly not. Your demand is not even close to what we are able to pay. I suppose you invested some funds into breaching us, your best chnace of having a return on your investment is by coming closer to what we actually are able to pay. My boss thinks he made a fair offer. We only ask for a feasible offer from you. The current one is not something we can live with.
[Akira] — — Message 87/170
> I simply do not know how to help you. You can sell some of your assets or something but my bosses can't go lower than $350,000.
[Victim] — — Message 88/170
> Thank you for your offer. I will go back to my boss and try to work it out. Eventually we want this deal to happen.
[Akira] — — Message 89/170
> Let me know asap.
[Victim] — — Message 90/170
> Hello and thank you for your patience. The Boss is seeking creative ways to raise additional funds. Complicated as there are no banks yet due to the holiday.We are into making this deal, as long as the required funds could be allocated.
[Akira] — — Message 91/170
> We have until Friday to get this over with. Please speed things up on your part.
[Victim] — — Message 92/170
> Hello and thank you for the significant step you have taken towards us and towards a mutually liveable solution to the situation. Unfortunately, the results of us scraping our finances come to a top of about $180,000. I know it is well below your last offer, but maybe if we only go for the part of securing our data and forget the decrypting part your bosses will accept it. I do afraid that if we don't reach an agreement both You and us stay with nothing. An agreement will let us alive and you still get money. If we agree the transfer could be made on a short schedule. Expecting your consideration to finally get ovet this. Thank You.
[Akira] — — Message 93/170
> We appreciate your efforts to end this with us. The lowest number we can accept for the case is $250,000. Not less. We can give you until Friday to make the payment, since our dialogue is long enough and we need to close the case.
[Victim] — — Message 94/170
> Understood. Just to make it clear, $250,000 for the full package. Decryption + data deletion. Right?
[Akira] — — Message 95/170
> Yes.
[Victim] — — Message 96/170
> Understood. Thank you. Will ge the fianl hopefully today. Meanwhile, and I apologize if this is a dumb question, how does the payment mechanism work? I understand we need to get bitcoin. What happens next?
[Akira] — — Message 97/170
> We need your decision today. To gain bitcoins you need to go to any exchange platform as binance or coinbase. Here are the guides: [REDACTED URL]
[REDACTED URL] You also can buy bitcoin from any local brokers. If you withdraw funds from your bank account, then you have to inform the bank that you need this money for investment purposes only. Once we get payment, we will provide the decryptors for each of your systems immediately.
[Victim] — — Message 98/170
> Got. it. The boss approved the deal. WE need now to better understand how it works. I understand you want the payment first and then you provide the decryptor. Would that be right?
[Victim] — — Message 99/170
> If so, how do I know we will actually get the decryptor after we send you the payment?
[Victim] — — Message 100/170
> Is there like a trusted third party we could send the funds to? Then they tell you they have the funds, you send the decryptor and after we confirm it works the third party sends you the money?
[Akira] — — Message 101/170
> We value our reputation and honor all agreements made. You will not find a single case where we have broken an agreement or failed to fulfill any of the clauses. After payment you will receive a decryptor for each of your systems and manual on how to use it for particular file/system. If you face any problems during decryption process, we will be here to support. You will receive a deletion log which means the raid drives that contained the only copy of your data are fully formatted and erased.
You will receive a security report that includes information about how we were able to penetrate your network, as well as exclusive first-hand information about the state of your network, the vulnerabilities that we found. What's more, you'll receive high-quality technical recommendations on eliminating any vulnerabilities and strengthening your network to secure your internal and external infrastructure. You will also receive written guarantees that we will not sell or publish your data, keep this conversation private, and delete this chat later. We won't come back for more money after payment and we won't attack you again.
[Victim] — — Message 102/170
> Understood. Thank you. Another question, do you accept only Bitcoin or is USDT is also an option. A friend told me it more stable than Bitcoin.
[Victim] — — Message 103/170
> Also Please mind that is is already evening in [redacted] and the banks are closed. They open tomorrow morning and as I understand that this size of a transaction could take 3-4 business days.
[Akira] — — Message 104/170
> We accept BTC only. We expect to get payment before the weekend.
[Victim] — — Message 105/170
> Will do Bitcoin, but payment can hardly be completed before weekend. Simply no physical time to reach this destination. We are a company, there is a procedure to get such a large amount of money moved.
[Victim] — — Message 106/170
> Also, the commissions on buying Bitcoin are simply shoking. For an amount of $250,000 it could get to $25,000. This is simply crazy. Please consider having $250,000 including the transaction fees. Otherwise the while deal might fall. WE ARE DOING OUR BEST, but no one considered these crazy fees. PLEASE...
[Akira] — — Message 107/170
> Come on, mates. If there is no payment by the weekend, we will have to raise the price to $275,000 on Monday. Please speed things up on your part.
[Victim] — — Message 108/170
> Sir, I am not joking. You and I worked hard to make a fir deal. Following the path you suggested of raising the price would only ruin everything and we all lose.
[Victim] — — Message 109/170
> Sorry, *a Fair deal
[Victim] — — Message 110/170
> If I may suggest another approach that might make us cut on some time would be for you to accept the price we agreed upon of $250,000 when it includes preset commission of let's say $25,000 and make the deal before Monday. Meaning you receive $225,000 bu on a much faster route. Otherwise, if we do it through the company, there is no chance to pay before Monday at the earliest. Maybe even Tuesday
[Victim] — — Message 111/170
> As it was mentioned before, we just had a long holiday and the system is just coming back to work. It takes time to move funds if this is done through the company.
[Victim] — — Message 112/170
> I urge your consideration to save this deal on which You and I worked so hard to achieve.
[Akira] — — Message 113/170
> I'll let you know a bit later.
[Victim] — — Message 114/170
> Thank you. We are ready to move on. Just say in what direction
[Akira] — — Message 115/170
> Are you able to send $225,000 today? If so, we're willing to accept.
[Victim] — — Message 116/170
> Thak you, this will help us save the deal. We are in the process of getting the bitcoin. As you know the transaction also take time. I would say we will be OK until tomorrow morning. Do we have a deal? If so, please send the wallet address so we could send you the first $1,000 to make sure it all works. Thank you.
[Akira] — — Message 117/170
> We do have a deal. Here is our BTC wallet [redacted] Let me know when you are ready to make a test transaction.
[Victim] — — Message 118/170
> Thank you. Test transaction to wallet [redacted] to be initiated in the next 40 minutes. Will come back to confirm sending the payment and expect you confirming.
[Akira] — — Message 119/170
> 0.016 BTC unconfirmed. You can proceed with the rest.
[Victim] — — Message 120/170
> Ok. This is about $1030. remaining $223,970
[Victim] — — Message 121/170
> Do you mind if we start moving the payment in parts as the bitcoin is purchased? Thank you.
[Akira] — — Message 122/170
> We don't mind. Anyway, you will receive everything once we get payment in full.
[Victim] — — Message 123/170
> Understood. Didn't think a seaoned businessman like you will say otherwise ;-)
[Victim] — — Message 124/170
> My mother says that in Russian there is a term called TERTIY KALACH to describe a seasoned man. Isn't it?
[Victim] — — Message 125/170
> Transfer made. Please confirm.
[Victim] — — Message 126/170
> Confirmation of second batch? Thank you
[Akira] — — Message 127/170
> 0.57 Received. Proceed please.
[Victim] — — Message 128/170
> A total of 0.5873577 bitcoin which is $37,713 transferred. Reamaining $187,287. To be followed as agreed, though the broker says blockchain is very busy today and delays are to be expected. Not up to us.
[Akira] — — Message 129/170
> Ok. Keep me posted.
[Victim] — — Message 130/170
> Hello. I know things are running late, but it is not us. We have made the purchases of the coins but the broker says there is a crazy traffic jam in the blockchain what ever it means. WE are waiting for it to come through. We've been on this most of the night but this is totally out of our control. Doing all in our control to see the deal through. Asking for your understanding on the issue.
[Victim] — — Message 131/170
> I also understand that there is some USDT in our posession that could account for a significant percent of the deal if you could accept USDT instead of the bitcoin. I know that for some reason you do not like USDT bu this seems to be a way to get you more funds on a shoorter schedule. Awaiting your word. Thank you.
[Victim] — — Message 132/170
> OK. It seems t eh traffic is easing. Reay to send you additional funds. Please confirm it is received.
[Victim] — — Message 133/170
> Funds sent to wallet [redacted]
[Victim] — — Message 134/170
> Please disregard message that money was sent. Clisked "submit" by mistake. Please confirm the wallet address is still valid.
[Victim] — — Message 135/170
> I dont want to cause any delays in making our deal. Making the transfer to the wallet you have sent yesterday. Please confirm receiving the funds. Thank you
[Victim] — — Message 136/170
> Funds sent to wallet [redacted]
[Victim] — — Message 137/170
> Waiting to make another bitcoin transfer. Please confirm the previous one. Thank you
[Akira] — — Message 138/170
> We have received 2.66385307 BTC in total. Please proceed further.
[Victim] — — Message 139/170
> That means you have about $172,229 and we still need to pay $52771 which is about 0.828613 or roughly 0.83 btc. And then the deal is paid. Please confirm. Thank you
[Victim] — — Message 140/170
> We are ready to make the last payment. Just confirm the numbers. Thank you.
[Akira] — — Message 141/170
> The balance is 2.66385307 btc or $169,553 at this moment. So you need to send 55,447. We are waiting. Thank you.
[Victim] — — Message 142/170
> Payment on its way. Please confirm arrival. Thank you.
[Akira] — — Message 143/170
> Received. Please wait.
[Akira] — — Message 144/170
> unlocker.7z // 1.79 MB
[Akira] — — Message 145/170
> unlocker.exe -p="path_to_unlock"
unlocker.exe -s="C:\paths.txt"
where "paths.txt" is a list of paths for the decryptor, each path on a new line
ESXi commands
1) chmod +x unlocker
2) ./unlocker -p="/vmfs/volumes"
[Victim] — — Message 146/170
> Git it. That answers for the decryptor. I understand we are also entitled to a proof of data deletion and a breach report. Thank you
[Victim] — — Message 147/170
> *Got it
[Victim] — — Message 148/170
> What about the things I mentioned? Thank you.
[Akira] — — Message 149/170
> We will provide within 24 hours. Thank you for your patience.
[Victim] — — Message 150/170
> OK. Standing by.
[Victim] — — Message 151/170
> Hello. There seems to be a problem with operating the tool you have sent. Our IT guys say that to run it they need to log in to the main ESX server. The problem is that they say you have changed the password of the server so they cannot log in. What is the new password you have set? Thank you.
[Akira] — — Message 152/170
> I'll let you know soon.
[Victim] — — Message 153/170
> Thank you. Our IT guys were eventually able to login, but when running the unlocker file they say it does not decrypt. The files stay with the .akira extension. Could it be that by mistake you sent an ENCRYPTOR and ot a DECRYPTOR?
[Akira] — — Message 154/170
> Wait a bit.
[Akira] — — Message 155/170
> There was a little mistake here. Here is the correct unlocker.
[Akira] — — Message 156/170
> win_unlocker.ex_ // 759 KB
[Akira] — — Message 157/170
> Let me know if you have troubles.
[Victim] — — Message 158/170
> Thank you. Hope it works...
[Victim] — — Message 159/170
> Hello. You promised proof of data deletion within 24 hours. When will we have it? Thank you?
[Victim] — — Message 160/170
> Also, please check with your tech people, it seems you have changed the root password to the Esxi server. Could you please send the new password?
[Victim] — — Message 161/170
> By the way, the unlocker you sent the second time works.
[Akira] — — Message 162/170
> Please try this password: [redacted]
[Victim] — — Message 163/170
> Thank you
[Victim] — — Message 164/170
> And proof of deletion?
[Akira] — — Message 165/170
> log.rar // 3.45 MB
[Akira] — — Message 166/170
> Our apologies for delay. The archive pass is: [redacted]
[Akira] — — Message 167/170
> Initial access to your network was purchased on the dark web. Then kerberoasting was carried out and we got passwords hashes. Then we just bruted these and got domain admin password. Spending weeks inside of your network we've managed to detect some fails we highly recommend to eliminate:
1. None of your employees should open suspicious emails, suspicious links or download any files, much less run them on their computer.
2. Use strong passwords, change them as often as possible (1-2 times per month at least). Passwords should not match or be repeated on different resources.
3. Install 2FA wherever possible.
4. Use the latest versions of operating systems, as they are less vulnerable to attacks.
5. Update all software versions.
6. Use antivirus solutions and traffic monitoring tools.
7. Create a jump host for your VPN. Use unique credentials on it that differ from domain one.
8. Use backup software with cloud storage which supports a token key.
9. Instruct your employees as often as possible about online safety precautions. The most vulnerable point is the human factor and the irresponsibility of your employees, system administrators, etc.
We guarantee that we will not sell or publish your data, keep this conversation private, and delete this chat later. We won't come back for more money after payment and we won't attack you again.
We wish you safety, calmness and lots of benefits in the future. Thank you for working with us and your careful attitude to your security.
[Victim] — — Message 168/170
> Thank you, must say the breach report looks quite generic and not specific to us.
[Victim] — — Message 169/170
> Also the root password you provided earlier didn't work.
[Akira] — — Message 170/170
> Try this one [redacted]