trinity Ransomware Negotiation — 0001

2Messages
UnknownDuration
UnknownInitial Demand
UnknownOutcome

About This Negotiation

This transcript documents a trinity ransomware negotiation with 0001. The negotiation consisted of 2 messages exchanged over Unknown.

The initial ransom demand was Unknown. The final outcome is not confirmed in the transcript.

Full Transcript — Verbatim

Reproduced from Casualtek's Ransomchats archive. URLs have been redacted.

Victim names are shown only where the breach was publicly reported in mainstream media. Any organisation wishing their name redacted can contact us at enquiries@binary-response.com — we will act promptly.
[0001] — — Message 1/2
.
[trinity] — — Message 2/2
We downloaded to our servers and encrypted all your databases and personal information! to start chatting with us write "hello" IMPORTANT INFORMATION! If you do not write to us within 24 hours, we will start publishing and selling your data on the darknet on hacker sites and offer the information to your competitors Guarantee:If we don't provide you with a decryptor or delete your data after you pay,no one will pay us in the future. We value our reputation. Guarantee key:To prove that the decryption key exists, we can test the file (not the database and backup) for free. Do not try to decrypt your data using third party software, it may cause permanent data loss. Don't go to recovery companies - they are essentially just middlemen.Decryption of your files with the help of third parties may cause increased price (they add their fee to our) we're the only ones who have the decryption keys.

Analyst Observations

Facing a Ransomware Demand?

Whether you choose to negotiate or refuse — having specialists in the room changes the outcome.