lockbit3.0 Ransomware Negotiation — Entrust

29Messages
26 daysDuration
$8.0MInitial Demand
UnknownOutcome

About This Negotiation

This transcript documents a lockbit3.0 ransomware negotiation with Entrust. The negotiation consisted of 29 messages exchanged over 26 days, beginning on 2022-06-29.

The initial ransom demand was $8.0M. The final outcome is not confirmed in the transcript.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[Entrust] — 29.06.2022 19:01:25 UTC — Message 1/29
[Chat started]
[Entrust] — 29.06.2022 19:05:01 UTC — Message 2/29
Greetings, I recieved a note and need to know next steps. How can you help me?
[lockbit3.0] — 29.06.2022 19:05:09 UTC — Message 3/29
hello! pay for key! after payment you will be able to restore your operations.
[Entrust] — 29.06.2022 19:05:16 UTC — Message 4/29
Greetings, Thank you for your response. We have not done this before and need help. What is the process?
[lockbit3.0] — 29.06.2022 19:05:28 UTC — Message 5/29
You pay the amount we ask to our cryptowallet. We give you the tool and data listing of stolen files and confirmation that we deleted files.
[Entrust] — 29.06.2022 19:05:34 UTC — Message 6/29
What is the price for the decryption key? How can we be sure this will all work?
[lockbit3.0] — 29.06.2022 19:05:41 UTC — Message 7/29
$8,000,000 is the price. Do google "lockbit" to ensure.
[Entrust] — 29.06.2022 19:05:48 UTC — Message 8/29
This is a very high amount that we can not afford. What can you do to bring the price down?
[lockbit3.0] — 29.06.2022 19:05:56 UTC — Message 9/29
You can afford. The amount is fair for your company.
[lockbit3.0] — 29.06.2022 19:06:01 UTC — Message 10/29
As a company who offers "high-assurance digital security solutions" the only thing you can not afford is such intrusion.
[Entrust] — 29.06.2022 19:06:06 UTC — Message 11/29
My boss would like to know why the stolen data is so valuable. What details can you provide on the data taken from our network?
[lockbit3.0] — 29.06.2022 19:06:12 UTC — Message 12/29
We can provide listing of 10% of files we took from you.
[Entrust] — 29.06.2022 19:06:24 UTC — Message 13/29
Ok, thanks. Please send us that file listing. Would you also provide a sample of files for us to review?
[lockbit3.0] — 29.06.2022 19:06:29 UTC — Message 14/29
password 8978724368901249897827902878412
[lockbit3.0] — 29.06.2022 19:06:33 UTC — Message 15/29
[REDACTED URL]
[Entrust] — 29.06.2022 19:06:42 UTC — Message 16/29
Our management wants to bring this matter to a close, we are ready to pay $1 million if we can agree to close this matter.
[lockbit3.0] — 29.06.2022 19:06:51 UTC — Message 17/29
$1 million is not acceptable.
[Entrust] — 29.06.2022 19:06:58 UTC — Message 18/29
Please understand that we want to work with you but we are not able to pay the full price. What discount can you offer?
[lockbit3.0] — 29.06.2022 19:07:06 UTC — Message 19/29
We can offer 15% off. The price is $US 6 800 000.
[Entrust] — 30.06.2022 13:50:14 UTC — Message 20/29
Thank you for your help. We are still evaluating the file names you provided.
[Entrust] — 05.07.2022 17:32:51 UTC — Message 21/29
Hi,The price is still too high for us to get authorized. Our team needs additional information to verify the data. Will you please provide another sample of files for us to review?
[lockbit3.0] — 06.07.2022 14:37:28 UTC — Message 22/29
You have to find a solution. Rest of data after payment.
[lockbit3.0] — 12.07.2022 09:25:39 UTC — Message 23/29
Are you going to pay? We've been waiting.
[lockbit3.0] — 12.07.2022 17:56:24 UTC — Message 24/29
Time is running out. We are going to start posting your files.
[Entrust] — 13.07.2022 14:11:43 UTC — Message 25/29
Hi, we discussed this with our management. They will authorize a new offer if we can get another data sample to review. Please help us and we will try to get this resolved soon.
[lockbit3.0] — 13.07.2022 14:59:28 UTC — Message 26/29
You must pay before we give you anything. In the worst case you as well other people will be able to review the files for free on our DLC.
[lockbit3.0] — 15.07.2022 12:18:13 UTC — Message 27/29
Are you going to pay?
[lockbit3.0] — 22.07.2022 14:02:28 UTC — Message 28/29
We haven't received reply from you for a long time. We are preparing blog post.
[lockbit3.0] — 25.07.2022 11:02:36 UTC — Message 29/29
We have prepared the blog post. We'll give you last chance and wait a bit more for your reply.

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.