lockbit3.0 Ransomware Negotiation — Redacted Organisation

137Messages
23 daysDuration
$70,000Initial Demand
UnknownOutcome

About This Negotiation

This transcript documents a lockbit3.0 ransomware negotiation with a redacted victim organisation. The negotiation consisted of 137 messages exchanged over 23 days, beginning on 2025-02-11.

The initial ransom demand was $70,000. The final outcome is not confirmed in the transcript.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[lockbit3.0] — 2025-02-11 05:00:25 — Message 1/137
You can attach a few files for test decryption by packing them into an archive with zip, rar, tar, 7zip, 7z, tar.gz extensions of no more than 10 megabytes using the attach button directly in the chat.\r\n\r\nIf your archive weighs more than 10 megabytes, please use our file sharing service.\r\n[REDACTED URL] security reasons we do not click on other links you send in chat.\r\nPlease wait for a reply, sometimes it takes several hours due to possible time zone differences.
[Victim] — 2025-02-11 13:04:40 — Message 2/137
Hi Lockbit, this is [redacted] and saw the post and may we ask to get the directory listing of all the files that you have. May we ask for more time so we can inform our stakeholders for them to assess and consider our next move? Thank you for understanding.\n
[lockbit3.0] — 2025-02-11 13:14:56 — Message 3/137
[REDACTED URL]
[lockbit3.0] — 2025-02-11 13:15:59 — Message 4/137
you can download all the files that we have and see for yourself
[lockbit3.0] — 2025-02-11 13:37:21 — Message 5/137
the blog was taken down for a while
[Victim] — 2025-02-11 13:40:00 — Message 6/137
Thank you for your consideration.
[Victim] — 2025-02-11 14:47:32 — Message 7/137
Good day, may we negotiate the amount you have in mind and what in turn would be Lockbit\'s end of the bargain.
[lockbit3.0] — 2025-02-11 15:08:14 — Message 8/137
120k$ in bitcoin
[lockbit3.0] — 2025-02-11 15:13:42 — Message 9/137
After payment, 100% of your files will be securely deleted and our team won\'t bother you again. You can trust us by reading about us on the global internet. We value our reputation
[lockbit3.0] — 2025-02-11 15:34:00 — Message 10/137
our deals run on a regular basis, client want to solve the problem before first posting information on the blog
[Victim] — 2025-02-11 15:34:41 — Message 11/137
Dear Lockbit, may we state that last year was the only time we were profitable and we only earned $200k. We have also notified the regulators and our clients as well as required by law since the encryption last January 25 caused a major outage. That said, we were able to restore operation with some backups, albeit with some data loss therefore decryption wont really be necessary. Please give as an amount that we can get back to our leaders to be considered.\n
[lockbit3.0] — 2025-02-11 15:51:36 — Message 12/137
maybe we can lower the amount, but not by much.
[lockbit3.0] — 2025-02-11 15:54:01 — Message 13/137
in the process of working with you, we thought about 100k.
[lockbit3.0] — 2025-02-11 16:04:05 — Message 14/137
our principles have become worth more than money. However, a discount can be negotiated.
[Victim] — 2025-02-11 16:06:15 — Message 15/137
Thank you for your consideration. 100k is still very steep for us as its half of our revenue which will be negated with the damage caused by the outage. May we respectfully ask to please significantly bring it down since we are only technically be requesting for the deletion of the data and we do understand that this is just business for you.\n
[lockbit3.0] — 2025-02-11 16:14:27 — Message 16/137
I don\'t know how much you\'d be willing to pay.
[lockbit3.0] — 2025-02-11 16:15:51 — Message 17/137
but I know it would be a big problems to you if we released your data in blog.
[lockbit3.0] — 2025-02-11 16:17:29 — Message 18/137
They often say they\'ve had a bad year, but they\'ll still have to pay.
[lockbit3.0] — 2025-02-11 16:28:29 — Message 19/137
If I give a price now, it will be the last one.
[Victim] — 2025-02-11 16:30:56 — Message 20/137
We understand, and we actually had a good year last year since thats the first time we were positive. But this incident wiped it off all away and will be spending more in recovery. Also, the directors are there just for name as a favor and add credibility which by the way is now in shambles, but they dont really contribute, otherwise they would have sent their army of IT to help us recover. I am looking at 10-20K to comeback to the heads and this will be coming from our own personal funds. While there will be some issues on publishing this, as we mentioned, we have already notified the clients and regulators about this breach.
[lockbit3.0] — 2025-02-11 16:32:44 — Message 21/137
by the way, you downloaded your backup files, which will help you as well.
[lockbit3.0] — 2025-02-11 16:33:48 — Message 22/137
20k is not possible and 50k is also not possible, companies much smaller than you pay us such amounts
[lockbit3.0] — 2025-02-11 16:35:32 — Message 23/137
We are not paid from IT team, they do not have that kind of money. We are paid by the heads of the companies
[lockbit3.0] — 2025-02-11 16:36:52 — Message 24/137
we don\'t need from yours own personal funds
[lockbit3.0] — 2025-02-11 16:37:25 — Message 25/137
we can\'t agree on this
[lockbit3.0] — 2025-02-11 16:38:37 — Message 26/137
we were already aiming to publish you, you may have noticed by the posting time of only 1 day.
[lockbit3.0] — 2025-02-11 16:39:18 — Message 27/137
you are lucky that you reacted quickly, we did not expect this
[lockbit3.0] — 2025-02-11 16:39:57 — Message 28/137
even though there was a warning on viber
[lockbit3.0] — 2025-02-11 16:40:36 — Message 29/137
why didn\'t you react immediately
[lockbit3.0] — 2025-02-11 16:40:58 — Message 30/137
it\'s your fault
[lockbit3.0] — 2025-02-11 16:48:03 — Message 31/137
I consulted and asked for another discount for you, our price will be 70k
[lockbit3.0] — 2025-02-11 16:48:40 — Message 32/137
and we will not rush you to pay
[lockbit3.0] — 2025-02-11 16:51:12 — Message 33/137
your office will allow you to pay that amount
[Victim] — 2025-02-11 16:55:20 — Message 34/137
Thank you for your concern and consideration, yes this funds will not be coming from IT. But we only have one owner, as we are a small private company, and he will have to cover everything. We were unsure of the viber message, but here we are. We will come back to you if we can convince him to pay 50k as this is still big for one person.
[lockbit3.0] — 2025-02-11 16:58:42 — Message 35/137
in the message in Viber there was a link to your archive to make sure
[lockbit3.0] — 2025-02-11 17:00:47 — Message 36/137
our price was 70k you write about 50k, let me talk to the team and agree on 60k for everyone
[Victim] — 2025-02-11 17:07:51 — Message 37/137
Ok, let us know. Thank you.\n
[lockbit3.0] — 2025-02-11 17:17:33 — Message 38/137
we agree to 60k, decision is yours
[Victim] — 2025-02-11 17:21:40 — Message 39/137
Will relay this and come back with a decision tomorrow morning as its 1am here. Do you have a code name or nickname so we know we are talking to the same customer support tomorrow?
[lockbit3.0] — 2025-02-11 17:27:16 — Message 40/137
ok, on your time 16-17 o clock, I\'ll be online in this chat, possibly earlier
[Victim] — 2025-02-11 17:29:11 — Message 41/137
Ok, thank you for your patience.
[lockbit3.0] — 2025-02-11 17:30:55 — Message 42/137
Thank you too, good luck.
[Victim] — 2025-02-12 08:30:58 — Message 43/137
Good day Lockbit, we have met and we have come up with our final offer of 30k. Please do consider that we are only asking for the deletion of the data as we have already notified the regulators and clients about the breach as mandated by law. So this is just to minimize exposure so we can concentrate in the restoration activities. Hoping for you kind consideration.
[lockbit3.0] — 2025-02-12 08:58:37 — Message 44/137
you know, if we publish your data, you will lose more than 30k
[lockbit3.0] — 2025-02-12 09:00:09 — Message 45/137
they will also end up with your competitors, and you will be on the verge of closing down
[lockbit3.0] — 2025-02-12 09:01:23 — Message 46/137
If your directors wants to get off easy, it won\'t work
[lockbit3.0] — 2025-02-12 09:02:32 — Message 47/137
30k doesn\'t mean anything to us.
[lockbit3.0] — 2025-02-12 09:05:00 — Message 48/137
We are waiting for another offer from you
[lockbit3.0] — 2025-02-12 09:11:23 — Message 49/137
our last successful data deal that we had was for 500k, clients pay well for their data, not for encryption
[lockbit3.0] — 2025-02-12 09:12:50 — Message 50/137
we made concessions to you, but you\'re upsetting us with your offer.
[Victim] — 2025-02-12 09:37:46 — Message 51/137
Let me get back to you.
[Victim] — 2025-02-12 10:42:09 — Message 52/137
Hi Lockbit, I\'ve talked to our heads and most of them are against of paying at all. We don\'t know much about your business and the heads are insistent that you would go against your word and sell the data nonetheless. We\'ve been transparent with our regulators and clients and have been working days and nights non-stop for restoration activities. And now, we just want to minimize the damage and hoping for peaceful restoration activities by deleting the data that you have. \n\nThe heads don\'t want to pay at all but I\'ve told them that you value your reputation as you said and have managed to convince them to pay 40k for the destruction of data. Kindly consider this offer.
[lockbit3.0] — 2025-02-12 11:14:22 — Message 53/137
We keep our word! only one person and me has your files, after your payment 40k, they will be securely removed by the program [redacted]
[lockbit3.0] — 2025-02-12 11:17:21 — Message 54/137
we were going to agree with you for 50k, but okay, I personally agree with you on 40k
[Victim] — 2025-02-12 11:17:46 — Message 55/137
Thank you for consideration. Do we have a deal at 40k?
[lockbit3.0] — 2025-02-12 11:18:16 — Message 56/137
you need to buy bitcoin, write to me when you are ready and I will give you a wallet
[lockbit3.0] — 2025-02-12 11:19:01 — Message 57/137
40k$ in bitcoin
[Victim] — 2025-02-12 11:33:29 — Message 58/137
I will relay the agreement and will get back to you tomorrow same time. Thank you for your consideration.
[lockbit3.0] — 2025-02-12 11:37:52 — Message 59/137
ok
[Victim] — 2025-02-13 10:00:20 — Message 60/137
Good day, we are now preparing the funds and should be ready by Monday. We need help in converting to bitcoin. Would you be able to point us to how any of your previous clients from the Philippines is able to acquire bitcoins for payment?
[lockbit3.0] — 2025-02-13 10:10:48 — Message 61/137
Hello, I can only give you a our bitcoin wallet
[lockbit3.0] — 2025-02-13 10:11:14 — Message 62/137
[REDACTED URL]
[lockbit3.0] — 2025-02-13 10:11:38 — Message 63/137
here you can see where to buy bitcoin
[Victim] — 2025-02-13 10:18:52 — Message 64/137
Thank you and will check this out.
[Victim] — 2025-02-18 11:05:51 — Message 65/137
Good day Lockbit, we are consolidating the funds and should be completed within the week. We have candidates on where to purchase bitcoin locally with minimal paperworks and will be talking to them on Thursday.
[lockbit3.0] — 2025-02-18 11:07:50 — Message 66/137
Good day, please don\'t delay for long time
[Victim] — 2025-02-18 12:14:02 — Message 67/137
Rest assured we are doing our best to process the funds immediately. Thank you for your patience.
[lockbit3.0] — 2025-02-18 12:20:34 — Message 68/137
fine, I\'m not hurry you
[lockbit3.0] — 2025-02-18 12:21:01 — Message 69/137
I\'m waiting for you on Thursday
[Victim] — 2025-02-18 13:07:35 — Message 70/137
Yes, will give update by then. We are really trying to get the money out and buy crypto but it\'s harder when we want less paper trail. This is also the first time we are doing this so thank you for your patience.
[Victim] — 2025-02-20 15:06:18 — Message 71/137
Good day Lockbit, we\'re expecting to get the cash out by Saturday or Monday then we can start purchasing the coins next week. Will update you again on Monday\n
[lockbit3.0] — 2025-02-21 08:53:11 — Message 72/137
Thanks, allright
[Victim] — 2025-02-24 11:07:43 — Message 73/137
Good day Lockbit, \n\nWe have finally acquired the funds and is now in the process of buying bitcoin. We are evaluating possible sources of bitcoins this week without KYC then it might take some time since we have to split the purchase under $8,000 to avoid being flagged. We\'ll give you our wallet address once we start purchasing so you could monitor then we\'ll do an initial test transfer to you after.\n\nWe could send you a picture for proof of our activities with your required instructions if needed. Thank you for understanding.
[lockbit3.0] — 2025-02-24 11:45:52 — Message 74/137
Hello, proofs not need, we\'ll wait
[Victim] — 2025-02-25 14:09:05 — Message 75/137
Thank you for the trust. One of us got a call from an unknown number in Lithuania, please give us time to purchase bitcoins.
[lockbit3.0] — 2025-02-25 14:25:34 — Message 76/137
I don\'t know who called, not us, we just waiting
[lockbit3.0] — 2025-02-25 14:32:39 — Message 77/137
how are you doing with buying bitcoin ?
[lockbit3.0] — 2025-02-25 14:33:17 — Message 78/137
how long do you think it will take ?
[Victim] — 2025-02-25 14:58:20 — Message 79/137
We will be splitting the purchase to avoid tripping regulatory limits, so once we have a seller, the estimate time is 2 weeks.
[lockbit3.0] — 2025-02-25 15:01:01 — Message 80/137
we have never waited so long, and the amount is not large
[lockbit3.0] — 2025-02-25 15:02:36 — Message 81/137
this is suspicious, why are you delaying time
[lockbit3.0] — 2025-02-25 15:04:13 — Message 82/137
anyone can register a personal account on the exchange and buy bitcoin in the moment
[lockbit3.0] — 2025-02-25 15:05:06 — Message 83/137
very long and it becomes strange
[Victim] — 2025-02-25 15:08:03 — Message 84/137
Apologies for the wait. We are doing precautionary measures to minimize our trail of buying bitcoins and paying for the ransom.
[Victim] — 2025-02-25 15:09:36 — Message 85/137
We can send you the picture of the cash with a marker you will request as proof. But we can\'t deposit this to a bank and use that account to buy crypto without paper trail. Hope you understand
[lockbit3.0] — 2025-02-25 15:16:21 — Message 86/137
you can put cash on a card of a person not from the company, and he will be able to buy bitcoin in one click on a popular exchange, for example, binance.com
[lockbit3.0] — 2025-02-25 15:17:52 — Message 87/137
do not use personal exchangers, they will have a bad rate bitcoin and they may scam you
[Victim] — 2025-02-25 15:23:17 — Message 88/137
Yes it was an option before but Binance is banned in the Philippines and can\'t get them from the app stores or create accounts. We are talking to 2 possible sellers. Please be patient, this is the first time we are doing this kind of transaction. We do have good progress.
[lockbit3.0] — 2025-02-25 15:26:26 — Message 89/137
ok, no problem
[Victim] — 2025-02-28 04:36:27 — Message 90/137
Good day Lockbit, we already got the crypto this morning. Could we do the transaction within today since the market is going down. Would like to conduct test transfer first before giving the full amount.
[lockbit3.0] — 2025-02-28 09:29:42 — Message 91/137
Hello, great
[lockbit3.0] — 2025-02-28 09:30:21 — Message 92/137
[redacted]
[lockbit3.0] — 2025-02-28 09:41:44 — Message 93/137
this is a btc wallet, you can send test transfer
[Victim] — 2025-02-28 09:51:24 — Message 94/137
Alright, will now start sending test transfer payment of $100.
[Victim] — 2025-02-28 10:03:13 — Message 95/137
We would like to mention that we bought 40k USD worth of bitcoin this morning but with the volatility and transaction fees it will be less. Hope this is okay with you as we want to complete the transaction. Rest assured that we will give you all the btc we were able to acquire.
[lockbit3.0] — 2025-02-28 10:04:41 — Message 96/137
ok
[Victim] — 2025-02-28 10:08:34 — Message 97/137
Test transfer of $100 worth of btc has been sent to your btc address and is now PENDING in status. Please confirm once received. Thank you.
[Victim] — 2025-02-28 10:32:34 — Message 98/137
The status of the test transfer is now COMPLETED, could you please check on your end?
[lockbit3.0] — 2025-02-28 10:36:40 — Message 99/137
+
[lockbit3.0] — 2025-02-28 10:37:12 — Message 100/137
test transfer came
[lockbit3.0] — 2025-02-28 10:38:34 — Message 101/137
0.00124505
[lockbit3.0] — 2025-02-28 10:49:29 — Message 102/137
you can send all amout
[Victim] — 2025-02-28 11:00:51 — Message 103/137
We would like to split the next transactions in case we make a mistake. We will next transfer 20k usd in btc first and then the rest of the amount. We hope you understand and this is okay with you.
[lockbit3.0] — 2025-02-28 11:05:06 — Message 104/137
yes of course, ok
[Victim] — 2025-02-28 11:08:46 — Message 105/137
Split transfer of $20k worth of btc has been sent to your btc address and is now PENDING in status. Please confirm once received. Thank you.
[Victim] — 2025-02-28 11:10:56 — Message 106/137
Could you help me a bit, may I ask the details of how you got access to our network? Did you exploit our public web app server or phish our users?
[lockbit3.0] — 2025-02-28 11:11:23 — Message 107/137
is fine, 20k confirm
[lockbit3.0] — 2025-02-28 11:13:45 — Message 108/137
remove the admin from the domain who controls infostructure, no matter what antivirus you install, the domain will always be vulnerable
[lockbit3.0] — 2025-02-28 11:16:19 — Message 109/137
got to you through phishing, but I don\'t remember the first host
[lockbit3.0] — 2025-02-28 11:17:38 — Message 110/137
and you had very easy passwords
[lockbit3.0] — 2025-02-28 11:19:18 — Message 111/137
I followed the work [redacted], and waited for him to log into Google Backup
[lockbit3.0] — 2025-02-28 11:19:41 — Message 112/137
about a month
[lockbit3.0] — 2025-02-28 11:22:44 — Message 113/137
sorry can you transfer the rest, i\'m very late now
[lockbit3.0] — 2025-02-28 11:23:28 — Message 114/137
I need to go and I\'ll be here in a few hours
[lockbit3.0] — 2025-02-28 11:26:03 — Message 115/137
Within 24 hours your archive will be deleted from the blog, also i use software [redacted] delete archive from physical pc\nI\'ll send you a screenshot, you don\'t have to worry, we won\'t bother you anymore and your data will be securely deleted
[Victim] — 2025-02-28 11:37:37 — Message 116/137
Sorry just wanted to clarify does this mean you were able to get glen moyo\'s account through phishing as well?
[Victim] — 2025-02-28 11:39:48 — Message 117/137
We are now sending the rest of the payment. Thank you for your response.
[Victim] — 2025-02-28 11:41:30 — Message 118/137
Rest of the payment has been sent to your btc address and is now PENDING in status
[lockbit3.0] — 2025-02-28 11:42:28 — Message 119/137
we got into the network through a manager with user priv, and dump ntlm local admin access on all the hosts in the domain.
[lockbit3.0] — 2025-02-28 11:43:02 — Message 120/137
then we found the admin in the domain
[lockbit3.0] — 2025-02-28 11:43:45 — Message 121/137
[login]:[password]
[lockbit3.0] — 2025-02-28 11:44:23 — Message 122/137
You have a Kaspersky server in your domain, remove it
[lockbit3.0] — 2025-02-28 11:45:48 — Message 123/137
thank you, the full amount has been received
[lockbit3.0] — 2025-02-28 11:46:23 — Message 124/137
I\'ll be back a little later and get to work on deleting your data
[lockbit3.0] — 2025-02-28 11:46:43 — Message 125/137
You can also ask what you need, I will answer
[lockbit3.0] — 2025-02-28 11:47:47 — Message 126/137
now sorry me, I need to go
[Victim] — 2025-02-28 11:48:06 — Message 127/137
Thank you and apologies for the questions, on the domain, could you expound a bit as we didn\'t have domain configured yet at the time of the incident.
[lockbit3.0] — 2025-02-28 11:48:52 — Message 128/137
Let me come back and of course I will answer
[Victim] — 2025-02-28 11:49:43 — Message 129/137
It\'s alright. Thank you. We\'ll get back on this chat to check in on the deletion as well.
[lockbit3.0] — 2025-02-28 11:49:46 — Message 130/137
I\'m expected, I have to leave now.
[lockbit3.0] — 2025-02-28 11:50:08 — Message 131/137
of course i will be here
[lockbit3.0] — 2025-02-28 11:50:12 — Message 132/137
thanks
[lockbit3.0] — 2025-03-01 15:28:31 — Message 133/137
Your data was deleted
[lockbit3.0] — 2025-03-01 15:29:18 — Message 134/137
[REDACTED URL]
[lockbit3.0] — 2025-03-01 15:29:22 — Message 135/137
proof
[Victim] — 2025-03-05 11:17:28 — Message 136/137
Thank you for this. May I ask another question, we\'ve read from reports that you often use Anydesk in your attacks, can you explain how it is relevant to you?
[lockbit3.0] — 2025-03-06 06:06:27 — Message 137/137
Hello, you had anydesk installed on many hosts, we just used it to get back

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.