Nice to meet you! That will be 20 million please
David Décary-Hétu (Professor · University of Montreal)
NorthSec 2025 · Day 1 · Salle de bal · Conference
Overview
David Décary-Hétu, criminologist at the University of Montreal, presents the first large-scale qualitative analysis of ransomware negotiation transcripts: 195 conversations comprising roughly 6,300 messages exchanged between 23 ransomware groups and their victims, sourced from the RansomwareLive dataset. His analysis maps the rhetorical strategies, psychological pressure tactics, and pricing mechanics that ransomware operators deploy — and pairs this with a logistic regression identifying the variables that predict whether a ransom is ultimately paid. The findings have direct implications for incident response planning and negotiation strategy. ---

Key moments
- 4:40 Ransomware evolved to triple extortion: DDoS plus reputation
- 8:54 Average ransom: $3M asked, only $520K paid—83% discount
- 12:39 Attackers actively search files for your cyber insurance limit
- 19:09 Ransomware groups release victims with Russian branch offices
- 13:20 Initial ransom drops 80% instantly; pay over 50% is overpaying
- 25:10 Dark web leak threat hollow: files take weeks to download
- 24:09 Group reputation and conversation length predict ransom payment
- 13:14 Plant fake financial docs to lower attacker ransom demands
Nice to Meet You! That Will Be 20 Million Please
Speaker: David Décary-Hétu (University of Montreal)
Conference: NorthSec 2025 — May 15–16, 2025, Marché Bonsecours, Montreal
Watch on YouTube: https://www.youtube.com/watch?v=l9_m6t7WAOc
Reading time: ~9 minutes
TL;DR
David Décary-Hétu, criminologist at the University of Montreal, presents the first large-scale qualitative analysis of ransomware negotiation transcripts: 195 conversations comprising roughly 6,300 messages exchanged between 23 ransomware groups and their victims, sourced from the RansomwareLive dataset. His analysis maps the rhetorical strategies, psychological pressure tactics, and pricing mechanics that ransomware operators deploy — and pairs this with a logistic regression identifying the variables that predict whether a ransom is ultimately paid. The findings have direct implications for incident response planning and negotiation strategy.
Introduction
Ransomware operators are not just technical adversaries — they are negotiators operating within a structured, if criminal, service economy. Despite the scale of the ransomware problem, the mechanics of how these negotiations actually unfold have been poorly understood outside of practitioner communities. Press releases from victimized organizations reveal almost nothing. Leaked internal communications from groups like Conti illuminate organizational structure but not the buyer-seller dynamic.
David Décary-Hétu's talk fills this gap with empirical data. A criminologist by training, Décary-Hétu approaches ransomware as a market phenomenon: the operator has a product (decryption, data deletion, non-publication of exfiltrated material), the victim has capital (insurance coverage, cash reserves, reputational exposure), and the negotiation is the mechanism by which these parties reach a transaction price. Understanding that mechanism — the price anchoring, the urgency pressure, the threat sequencing, and the variables that actually predict payment — is directly actionable for organizations preparing for an incident.
The dataset comes from RansomwareLive, a site that aggregates and sanitizes ransom negotiation transcripts submitted from across the threat intelligence community. Décary-Hétu is explicit that he did not collect this data himself — "we kind of stole it, like the ransomware groups do" — and that RansomwareLive makes a reasonable effort to redact identifiable information, though wallet addresses and names occasionally slip through.
The Evolution from Single to Triple Extortion
Ransomware began as a straightforward proposition: encrypted files, pay the decryption key, recover operations. Early ransoms were modest — Décary-Hétu cites $800 as a representative early figure — and the model was sustainable until backup practices improved sufficiently to make encryption alone an inadequate coercive lever.
▶ Watch: Evolution of ransomware extortion models (4:32)
Operators responded by developing double extortion: exfiltrate data before encrypting it, then threaten to publish on dark web leak sites if payment is not made. When victims began credibly calling this bluff — either because the data was not sensitive enough to matter or because public disclosure was preferable to payment — groups escalated to triple extortion: persistent DDoS against the victim's infrastructure, repeated re-compromise of cleaned environments, and targeted harassment of the victim's customers and suppliers.
The progression is not merely tactical — it reflects a strategic shift toward multi-vector coercion where the cost of non-payment extends well beyond data loss to include operational disruption, regulatory exposure, and reputational damage across the victim's entire stakeholder network. By the time a ransomware incident is fully developed, the victim is not simply deciding whether to pay for a decryption key; they are deciding whether to engage with an adversary who has conducted detailed reconnaissance on their finances, their insurance coverage, and their regulatory obligations.
The Dataset: Scale, Structure, and Pricing Economics
The RansomwareLive dataset analyzed by Décary-Hétu encompasses 23 ransomware groups, 195 recorded negotiation conversations, and approximately 6,300 messages. Groups in the dataset averaged 75 victims each and had been active for roughly 245 days (approximately 8 months). These are not the largest known ransomware operations — the largest groups tend to have less publicly available negotiation data — but the sample is sufficient to identify consistent patterns.
▶ Watch: Dataset overview and pricing gap analysis (8:00)
The pricing data is striking. Groups asked for an average of approximately $3 million per victim; the average amount actually paid was approximately $1.4 million — a 53% reduction from the initial demand. This discount is not exceptional or hard-won; it is structural. Décary-Hétu's analysis shows that ransomware operators are volume-focused, not margin-focused: they have so many victims in negotiation simultaneously that accepting half the initial demand on any given case is economically rational. His recommendation, stated without irony: always ask for a discount. The initial demand is deliberately inflated as an anchor, and the operator expects negotiation.
The data also shows examples of initial demands being reduced by 80% — from $1 million to $200,000 — through straightforward negotiation. Décary-Hétu estimates that paying more than 50% of the initial demand is likely overpaying, based on the distribution of actual settlement amounts in the dataset.
Pre-Negotiation Intelligence: What Operators Know Before They Make Contact
One of the most consequential findings in the dataset concerns the intelligence-gathering that precedes the first negotiation message. Ransomware operators do not open with a demand and wait to see how the victim responds; they conduct research first.
▶ Watch: Attacker reconnaissance and financial targeting (12:00)
When victims attempt to claim poverty — presenting themselves as small organizations unable to afford the demand — operators have frequently already reviewed the victim's financial statements, bank account information, and corporate filings extracted during the exfiltration phase. Transcript examples show operators responding to poverty claims with specific figures: "We've looked at everything you have, and you clearly have enough money in your bank account to pay us this amount."
Insurance coverage is a specific intelligence target. Operators search exfiltrated documents for evidence of cyber insurance policies, and they explicitly negotiate on the assumption that it is the insurer paying, not the victim. The psychological dynamic this creates is significant: from the operator's perspective, extracting money from an insurance pool is less morally freighted than extracting it from a human being, making them less susceptible to victim sympathy narratives. Décary-Hétu's wry suggestion — embedding fake documents in corporate file systems claiming a $1,000 maximum cyber insurance policy — is presented half in jest, but the underlying point is serious: operators calibrate their demands to what they believe the victim can and will pay, and that calibration happens before the first message is sent.
Psychological Pressure Tactics: Carrot, Stick, and Urgency
The negotiation dynamics Décary-Hétu describes follow a recognizable pattern: extended politeness early in the conversation, escalating to threats when victims delay or indicate they will not pay, with consistent urgency pressure throughout.
▶ Watch: Threat escalation and urgency mechanics (16:00)
Early-stage messages are formally polite — operators address victims as "sir," use "please" and "thank you," and frame themselves as professional service providers whose decryptor represents genuine value. When victims assert they have backups or otherwise signal non-payment intent, the register shifts. Operators threaten repeat encryption cycles: "We'll give you two weeks for your backups to come back up, and then we'll go back in and wipe your data again." They threaten customer and supplier notification: "We're going to call your customers and tell them everything we learned from their files because of you." In some cases, they threaten to surface regulatory violations found during the exfiltration phase: "We know you've been doing some insider trading. We've got the traces."
Urgency pressure is applied continuously and follows sales-oriented framing. Décary-Hétu compares the dynamic explicitly to a high-pressure car dealership negotiation: "What's the number? How can we close this today?" Timers are frequently deployed; operators cite internal deadlines, claim competing victim cases are consuming their attention, and frame delay as the victim's financial loss rather than their own.
The "vulnerability assessment" offered as a premium service is a consistent finding across groups and a consistent disappointment: the remediation advice is generic, often boilerplate, and focused on basic hygiene (MFA, software updates, not using Ivanti for VPN access) that bears no specific relationship to the actual entry vector used in the attack. Décary-Hétu does not recommend paying for it.
What Actually Predicts Payment: The Logistic Regression
The quantitative component of the analysis applies logistic regression to predict ransom payment outcomes across six variables: group payment rate (historical), group operational longevity, negotiation conversation length, group relative market size, discount offered, and victim organizational size (estimated from self-presentation and negotiator sophistication).
▶ Watch: Logistic regression and payment predictors (10:00)
The analysis identifies that larger victims — those with resources sufficient to hire professional negotiators — are more likely to pay, consistent with the hypothesis that ransomware operators preferentially target and invest negotiation effort in organizations with the financial capacity to settle. Groups with higher historical payment rates command more credibility in negotiations: the implicit threat that non-payment leads to data publication is more credible when the operator has demonstrated willingness to follow through in previous cases.
Conversation length is a notable predictor: longer negotiations correlate with eventual payment, which is consistent with operators investing more time in victims they assess as convertible. This has a defensive implication — sustained engagement without payment commitment may signal to the operator that the victim is a viable target worth continued pressure.
Notable Quotes
"You already see that from the start you get about a fifty percent discount just for showing up and asking for a discount. You should always ask for a discount if they attack you."
"Before they even reach out and talk with the people, they're actually gonna do their own research and find out what would be the best ransom to ask."
"They'll look into the documents and try to find evidence if you have money to pay, how much money you have, and if you have insurance."
"If you pay anything over fifty percent of what they first asked, it's probably way too much."
"The vulnerability assessment they provide is very bad. I would not pay for it."
Key Takeaways
- Initial demands are anchors, not floors. The average ransomware settlement is approximately 53% of the initial ask. Accepting the initial demand or settling above 50% of it is, based on this dataset, statistically unusual and probably unnecessary.
- Operators know the victim's finances before the first message. Reconnaissance during the exfiltration phase includes financial statements, insurance documentation, and bank account data. Victim poverty narratives unsupported by actual documentation are likely to be rebutted with specific figures.
- Insurance coverage is an active intelligence target. Operators specifically seek cyber insurance policies to calibrate demands and to frame payment as an institutional rather than personal transaction.
- Triple extortion is the current baseline. Encryption alone is no longer the primary coercive tool. Operators hold exfiltrated data publication, persistent DDoS, and repeat compromise as additional levers, and they threaten customer and supplier notification to extend pressure beyond the victim organization.
- The "vulnerability assessment" add-on is worthless. The post-payment remediation advice provided by ransomware groups is boilerplate, generic, and bears no documented relationship to the actual attack vector. It is not a legitimate forensic deliverable.
- Conversation length predicts payment. Sustained negotiation without commitment signals victim convertibility to the operator and invites continued pressure. Organizations should consider what negotiation posture they intend to adopt before an incident, not during it.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Criminologist David Décary-Hétu (University of Montreal) presents the first large-scale empirical analysis of ransomware negotiation dynamics: 195 transcripts, ~6,300 messages, 23 groups. Core findings: initial demands average ~3x final settlements (50%+ discount is structural, not exceptional), operators conduct financial/insurance reconnaissance before first contact, conversation length predicts eventual payment, and the post-payment 'vulnerability assessment' add-on is boilerplate worthless.
Heather Calloway (CISO) — MUST SEE
David Décary-Hétu analyzed 195 actual ransomware negotiation transcripts and produced empirical findings that most incident response guidance ignores. The initial demand is an anchor. The operators have already reviewed the victim's financials and insurance policy. Sustained engagement without commitment signals that you are a convertible target. Every organization that has a ransomware response plan that does not address negotiation posture is operating with incomplete preparation.