// Ransomware Negotiation Transcript
Conti Ransomware Negotiation — Redacted Organisation
// Context
About This Negotiation
This transcript documents a Conti ransomware negotiation with a redacted victim organisation. The negotiation consisted of 27 messages exchanged.
The initial demand is not clearly stated in the transcript. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
Hi
I want to make sure if you can recovery my data
this is my id [redacted]
How much data did you already have?
hello
hello
before we start dialog send me name of your domain and random names of few servers
My files encrypted with .[redacted] extension
and the name of server is [redacted]
ok
can you give some file from the server ?
can I request name of file
yes, i can do it, but later
about requesting the name you can try, but i' m not sure that it will be in our listing
How long do I ave to wait for decrypted file ?
Can I get ticket number so I can contact you later with my previous request
what do you mean? after you pay you get decryption software
I request two files name that mention below
[redacted] Assessment.docx
Template_OWASPv4_Checklist.xlsx
show me if you can recovery the file
send me here encrypted files and i' ll do decrypt
I' ve not pay decryption software yet, but You said give us free for two files
I just want to make sure if you can decrypt it
Template_OWASPv4_Checklist.xlsx.[redacted] [ 408.02 KB ]
not the files , just wait , I' ve problem with my connection
I cannot upload others file
maybe it' s big, try some smaller file
it just 10MB
it' s too big for this chat
oh , okay just try to decrypt file that I upload before
ok, wait
Template_OWASPv4_Checklist.xlsx [ 407.50 KB ]
you checked file?
in 2 days i' ll start publish your data
// Analysis
Analyst Observations
- Conti was a major ransomware operation that effectively shut down in May 2022 after internal chat logs were leaked. Members dispersed to other groups including Royal, BlackBasta, and Karakurt.