// Ransomware Negotiation Transcript
lockbit3.0 Ransomware Negotiation — Vitality Health Plan
// Context
About This Negotiation
This transcript documents a lockbit3.0 ransomware negotiation with Vitality Health Plan. The negotiation consisted of 73 messages exchanged over 24 days, beginning on 2022-09-16.
The initial ransom demand was $1,000.0M. The final outcome is not confirmed in the transcript.
// Primary Source
Full Transcript — Verbatim
Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.
Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[Chat started]
Hello
we ahve seen a note on our systems asking to contact you
how does this work?
we are destroyed
hello?
hi
to decrypt the data and avoid publication you need to pay us. we haven't published your name on our blog yet
we think your page is not working properly, we tried 2 first links and it got stuck on the logo and 3 items flipping around all time after some 5 minutes loading
is there some other way we canc omunicate?
use mirrors, we under ddos
and also, which data do you mean? can we know which data did you get from us?
You can reach us at any of these links using a Tor browser: [REDACTED URL] [REDACTED URL] [REDACTED URL] [REDACTED URL] [REDACTED URL] [REDACTED URL] [REDACTED URL] [REDACTED URL] [REDACTED URL]
now it looks like [REDACTED URL] its working
thanks god
well, tell me, what data do you mean?
data from your network
we have 150 computers
which data? so I can tell the bosses
we will give you this information after you pay the ransom
we dont know how all this thing works yet, our tech group is scheduled to come early tomorrow
if you tell us which data you got, we can say this on our meeting with our managers
understand our position, our ability to pay will depend on what our IT staff says tomorrow and which folders/files we risk being published
we are an small company which is already struggling to stand by, this has greatly affected our ability to give service to our customers
we will soon send you a tree of stolen data
ok
[REDACTED URL]
130k files, 122gb
Ok, I will check with the team and get back to you
how much money is this all going to cost us?
can we see those files?
\VITALITYHP\Vitality Health Plan\2019 Marketing Materials\Business Card [.] Biz Card Back.pdf Biz Card Front2-01.png [..] Biz Card Back2-01.png [redacted].pdf
Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf Vitality_[redacted].pdf
some of them, just to see that you really have the files
We'll send you the files in a moment
The price of decrypt and delete data 1.000.000$. we accept payment in BTC
[REDACTED URL]
1 million is absolutely out of range
however, thanks for all the informationa nd files, we will have a meeting on monday morning and tell you something
We studied your revenue data. we found information that the revenue is about $100 million. in addition, your site translates to the site of a large california company with $1 billion in revenue. based on this, the requested amount is quite real. pay and no one will ever know about the attack. we will return all your files and tell you about the attack, and delete your data from our servers forever. if you delay and do not negotiate actively, we will publish a post about you on our blog.
[REDACTED URL]
One company refused to pay the ransom. and suffered a lot. there is a lot of information about us on the internet. here is an example
our revenue isnt even close to $100 million, $1 mimllion is too much
bosses are willing to pay a much smaller sum
given that we have backups and the data you took is not sensitve at all
we know who you are, and we know you are at least reliable
bosses said they can pay $100k without need for additional requests/meetings, think about it
No, it's not enough!
we have finance dept, with its own CEO and he is not willing to give more than that.
we have your sensitive data, marketing data, financial data, passports, iti, transactions, and so on. so think about the damage that publishing data can do to you. think about the damage you will get.
we can negotiate, but anything above that is going to require a lot of paperwork, meetings, approvals and so on
yes, we know, thats why we are here trying to find a solution
if you are not ready to pay more than 100k, you can leave the chat room and wait for the publication of your data
100k is what we can pay now, 1 million we can never pay
anything between, will take time
for now, you have time to find money. but time will not last indefinitely. we need a deadline. if you drive unproductive talks, or don't come in for a chat, we will publish a post about your company on our blog. so far, we haven't done that
We know exactly who you are. don't start talking about limiting finances and so on. we know who you are and how much you can pay. so we will stand our ground and take tough measures in case of disobedience
you dont know who I am, otherwise you would not be here
tell your boss I dont throw him to the dogs because I respect him, his brother and what they say
I mean the real boss, not lockbitsupp
good luck
Put aside unnecessary talk. negotiate constructively.
just tell your boss and his brother that I appreciate them, thats all
tell lockbitsupp to send it to the real owners
that doesn't make sense. why are you coming in here?
your feud with the cats should be coming to an end, at least on the public domain
what is the point of giving away so much information in front of everyone who wants to read xss?
its good for none of you and very valuable for FEDs and their cheap dogs, researchers
If you're not interested, leave the chat room and don't come in.
nice honeypot that you locked
well, not even locked beacuse you just ran your locker and left, backups where there and esxi too
I will take your advice to not come back, take care my friend.
bye
// Analysis
Analyst Observations
- The initial demand of $1,000.0M places this in the upper tier of ransomware demands, typically reserved for large enterprises.
- LockBit 3.0 was the most prolific ransomware group of 2022-2023, responsible for more attacks than any other group. Their infrastructure was taken down by Operation Cronos in February 2024.
- → LockBit 3.0 threat actor profile — TTPs, ransom demands, and active campaigns.