
Tech • AI • Robotics • Game
A small global niche of cyber negotiators helps companies and public bodies cut ransomware demands, verify what attackers actually stole, and navigate the legal and moral risks of paying.
The negotiator described entering the field after helping a relative whose computer had been encrypted and unlocked only after a payment of roughly 800 to 900 euros in Bitcoin. Since then, he said he has handled more than 600 cases over about 10 years, moving from simple consumer incidents to complex negotiations for businesses and governments.
Most assignments now come through cyber insurance providers rather than directly from victims. In insured incidents, companies are typically expected to alert their insurer within the first 24 hours, after which the negotiator is brought in to assess the demand, contact the victim, and start discussions with the attackers.
Negotiations usually happen either by email with less sophisticated attackers or through dedicated chat portals run by ransomware groups. Well-known names in this ecosystem include DragonForce, Play and Lynx. Professional groups tend to use a restrained, businesslike tone, while less experienced operators are often more erratic and aggressive.
The negotiator said hostile messages are not always met with appeasement. His approach is to push back until the attackers stop trying to dominate the exchange, then regain control of the discussion. He said many deals now close in three to four days, compared with 10 to 14 days several years ago, because attackers have less time to hold an exclusive grip on a victim.
A key early request is the file tree, the directory list showing what data was taken. That can give victims a clearer picture than their own logs, especially when systems are encrypted. The negotiator also asks for proof that attackers can decrypt files by sending them a few encrypted samples and requesting recovery, a step used to test whether a working decryptor exists.
Contrary to common fears, attackers do not always take entire email systems or full databases. Typical exfiltration is said to range between 50 GB and 600 GB, with a focus on Word, PDF, Excel and PowerPoint documents, especially contracts, customer lists and HR records such as payroll data. Larger thefts increase the chance of detection, which limits what attackers usually attempt to remove.
One of the most damaging mistakes is leaving cyber insurance policies on accessible servers. If attackers find coverage limits, they can calibrate demands accordingly. A claim near 4.5 million dollars against a firm insured up to 5 million dollars is a strong sign that the criminals know exactly how far they can push.
Public attention often centers on multimillion-dollar extortion, but the negotiator said most payments are much smaller. For SMEs with up to around 150 users, demands commonly settle between 30,000 and 100,000 dollars. Larger companies may face 250,000 to 300,000 dollars, while deals above 500,000 to 600,000 dollars are described as relatively rare.
Attackers often open at around 10 to 12 percent of a company’s revenue, then test how much liquidity is available. In one recent case involving a 50-person company, an initial demand of 700,000 dollars was reduced to 150,000 dollars after its financial limits were laid out. The victim usually has to advance the payment before any insurer reimburses it.
Paying a criminal is not automatically illegal in itself, but paying a sanctioned or terrorist entity may be. Before any transfer, negotiators run a sanctions check using indicators such as wallet addresses and other technical traces. A response can arrive in about four hours. If a group is linked to a banned organization, payment is typically ruled out.
The negotiator estimated there are only about 50 official negotiators worldwide. He argued the work should not be paid as a percentage of savings, because that would create a conflict of interest. Instead, fees are generally fixed, from roughly 3,000 to 4,000 euros for small cases to 15,000 to 20,000 euros for larger ones, often covered by insurance.
The standard public advice remains not to pay, because every payment funds future attacks. Yet for a company employing 2,000 or 3,000 people, with operations frozen and invoices halted, the decision is rarely abstract. The practical aim of negotiation is to minimize the payment while helping the victim restore operations and limit broader damage.
Ransomware negotiations have become a structured, high-stakes service sitting between criminal extortion, corporate survival and public policy. The central tension remains unresolved: every payment may strengthen the market, but for some victims the alternative can be operational collapse.
Explain this