// Ransomware Negotiation Transcript
lockbit3.0 Ransomware Negotiation — Oklahoma City University
// Context
About This Negotiation
This transcript documents a lockbit3.0 ransomware negotiation with Oklahoma City University. The negotiation consisted of 56 messages exchanged over 28 days, beginning on 2022-07-25.
The initial ransom demand was $1.0M. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[Chat started]
We got your note. Can we chat?
yes
The price of the decryptor and deletion of your data is $1,000,000 in bitcoins. 285gb of data was stolen. At the moment we haven't published your name to the blog to keep the attack secret, but if you don't pay we will fix it! We know who you are and how much you earn.
Soon we will send you a tree of stolen data
[REDACTED URL]
Are you kidding me?!?! That's a crazy amount of money. What is the 285GB of data? Can you send it to me so I can review?
No, we're not laughing. Here you can download the stolen data tree. And screenshots of files and folders
Looked?
we have the list and we are looking, we will have an answer soon.
What list are we talking about?! Hurry up! When will you pay??
If within 24 hours you do not clarify the negotiations, we will post about your company on our blog! And the attack will no longer be secret
We're referring to the data tree and screenshots you sent us. Please have some patience here. There are a lot of moving parts right now and we need time to review, assess and bring our board up to speed on these matters. Please do not post us anywhere. We have a meeting coming up and your questions will be addressed soon.
How long will it take you?
We'll wait until the end of this week. If there is no progress in the negotiations, we will make a post about the attack
???
Progress is being made. This is not something we encounter everyday and are just making sure we are doing our due diligence. Please have patience. We likely wont be able to reach any agreements with you if you make a post about the attack.
Please show us the following files from the list you sent us
You have to be more precise! We will not wait for you indefinitely. Since you yourself do not talk about deadlines, we have announced deadlines, and you must meet them! You have time until the end of this week. If there is no clear information on Monday, the post will be published!
Budget$\2020.12.09 - Athletic Discount and Profitability Analysis by CFO Dave McConnell.pdf.....HResources\Faculty Sabbatical Tracking Sheet.xlsx.....HR-PayrollShare\Payroll Metrics_Planning 2021.xlsx.....Security\Supervisors\City Mutual Aid Agreement\OCU-OCPD Memo.pdf.....General Counsel\2019 Series Bonds\2021 S&P Ratings Call\S&P\Executive Committee Update 8-24-21.docx..... busoffice\Audit\2020-2021\000-FY2021 Audit Folder\Financial Stmts\OCU_21 FS_Final.pdf
OK. Now let's send!
[REDACTED URL]
Looked?
Yes we have looked. We were skeptical at first but we now see that you have what you say you do. We want to meet to discuss, however, two of our senior members are on personal leaves of absence today. We will have our meeting Monday morning to catch them up and will contact you afterwards.
If you bring clarity to the negotiations on Monday, we will act more radically!
Time is running out. What did you decide?!
When will you pay?
How are we suppose to get $1M? That isn't a fair amount here, it's not reasonable on our end. Our revenue doesn't reflect the amount of cash we have access to. Can you go to your boss and see if their is a discount?
I'm the boss. Pay! The price is not determined by chance, we have deliberately approved the redemption amount, and it is not discussed.
You ask us for a discount, but don't tell us how much you're willing to pay. Maybe we're talking about different amounts.
We don't want this to take a long time. But we don't have that much money. We need a better price and then we can get this done.
Offer your price
???
We have been dealing with so much over here and are a little short-staffed right now. We went to the bank with your $1M demand and they pretty much laughed in our faces. They want us to come back on Monday with a lower number. We haven't offered anything because we truly don't know how much we can get in total. What is the biggest discount you can give us based on that and what we have said to you in the past? You seem to be in a rush here so let's please help each other.
There is no minimum and maximum discount. Start with how much money you're willing to pay! If our negotiations drag on, we will speed them up with the publication of a post about the attack.
And if you're also inactively carrying out negotiations, we can also speed them up by publishing them! Or doubling the price! Don't play games with us, we don't like it
It's in your best interest to bring active negotiations and prevent publication in the first place! So far, you're doing the opposite.
If payment is not received by the end of the week, we will publish a post on our blog!
By the end of the week is when you want payment?! Based on how this is going no payment will be made if you publish our data tomorrow. The board has decided, as a whole, that we won't be paying anything if our name ends up on your blog. We've been working with you this whole time to make some progress so let's please not start making threats. At the top of the chat, it says we still have 16 days left. Please work with us not against us here.
Throughout the negotiations, we did not come to anything! A post will be published tomorrow as a timer, not the data. You negotiate for a very long time and not productively. You don't even try to negotiate a price, and you don't pay the price of the descript and deletion of the data! Speaking of the date at the top of the chat, after 16 days your decryptor will be deleted and you will never decrypt your data. And the stolen data will also be published! Keep in mind, these aren't just threats, we're keeping our promises.
When will you pay?
We're waiting to hear from the bank, we're hoping they will be able to help us out here. Please remain calm, we want this over with as much as you do. I'm not sure what they will think of all this. So please, do not publish anything, not even our name tomorrow or else my boss won't want to pay anything. We need to see what the bank says about a loan as we don't have anything close to your demand on hand. If it were up to me you'd already have your money, but there are other factors in play here. It's not just a one man operation, similar to yours. We will give you an update after we hear from the bank. We're hoping they will give us an answer Monday. I'm sorry but not all the decisions are up to me.
ok
Ok, we'll wait until Monday.
???
If today we do not hear from you a profitable offer - we will reveal the attack
Hello, sorry for the delay. We got some responses and our meeting is happening tonight. We will be able to get you an decent offer tomorrow, so please keep an eye out for our response then.
OK. If this does not happen, the post will be published
Please pay attention to the date above the chat. On this day, your decryptor will be deleted and data recovery will be impossible!
We are here. We apologize for not giving you an update yesterday but we already short staffed and could not make to the chat. Please do not reveal anything related to the attack to the public. We're working and juggling a lot to get everyone to get on board with a payment here. It has been tough for us to scramble funds together, but at this moment we have $25k on hand that we can send your way. Unfortunately the bank never got back to us about a loan amount, so we're still waiting to see if they will give us any amount. They aren't too happy about sending money to hackers. Is this something you would make a profit from? How much does it cost you to hack a company?
Do you seriously think that this is a decent amount? Is your data worth 25k? Our patience snapped. Wait for the blog post!
$25K is what we have right now. We're just letting you know and trying to be transparent with you. Can you come down on your demand at all? This would help me convince some people to try and get more money. It would also show everyone that you're willing to work with us. We're not trying to upset you here, that's not our intention. Any post about us and we won't get approval to pay any amount so let's please work together.
We have already listened enough to your empty words. Post published
Why do you go to the chat? You said you wouldn't pay if the post ended up on a blog. So what is the purpose of the visit?
?
Have you looked at the stolen data?
// Analysis
Analyst Observations
- LockBit 3.0 was the most prolific ransomware group of 2022-2023, responsible for more attacks than any other group. Their infrastructure was taken down by Operation Cronos in February 2024.
- → LockBit 3.0 threat actor profile — TTPs, ransom demands, and active campaigns.