Darkside Ransomware Negotiation — Redacted Organisation

10Messages
UnknownDuration
UnknownInitial Demand
UnknownOutcome

About This Negotiation

This transcript documents a Darkside ransomware negotiation with a redacted victim organisation. The negotiation consisted of 10 messages exchanged over Unknown.

The initial demand is not clearly stated in the transcript. The final outcome is not confirmed in the transcript.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[Darkside] — 12 days ago, — Message 1/10
Hello, [redacted]. We downloaded more then 500 GB of sensitive data from your network, if you don't pay, we will publish them. We know that you have 3 million cyber insurance police from Response Limit, you must contact Beazley Group to take money for payment. Also, we know about your 45 millions credit line. So, please, don't say us that you haven't money or etc. Shares of your company ([redacted]) are traded on NASDAQ. If you don't contact us, we will notify all the biggest mass media about your company hack and data leak, what will lead to the fall of the price of your shares. And you can be sure, we always do that was promised.
[Darkside] — 10 days ago, — Message 2/10
Since you ignore us, we prepare the data to publication. We are confident that your company will be a good example for others and create us good advertising.
[Darkside] — 9 days ago, — Message 3/10
We will start publish your data after 6 days 14 hours. We also prepare the list of the press that we will notify about your leakage, we will soon provide you with a list.
[Darkside] — 9 days ago, — Message 4/10
In the case of payment, we guarantee: - Non-disclosure of information about your hacking. - Providing you windows and linux decryptors. - Help with the recovery your data.
[Darkside] — 7 days ago, — Message 5/10
List of the press who will be sent links to your data after the publication: - [REDACTED URL] - [REDACTED URL] - [REDACTED URL] - [REDACTED URL] - [REDACTED URL] - [REDACTED URL] We also found several traders who want to earn on the fall of your shares. Are you ready for what will happen after the publication?
[Darkside] — 6 days ago, — Message 6/10
2 days left.
[Darkside] — 6 days ago, — Message 7/10
In 2 days your post will become public, we will notify traders in advance, in 3 days we will publish your data.
[Darkside] — 5 days ago, — Message 8/10
You have the last day to resolve this. We are ready for a dialog, you should write.
[Darkside] — 4 days ago, — Message 9/10
Tomorrow we will begin to fulfill all our promises. Good luck.
[Darkside] — 1 day ago, — Message 10/10
Are you ready for a dialog?

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.