The morning goes by uneventfully. An employee steps away from their desk for lunch and closes their laptop. Half an hour later, when they come back, their heart sinks: every file on the desktop is gone, no documents, no spreadsheets, just empty space. Suddenly a window they've never seen before pops up.
What sounds like a bad joke is a real case: the so-called PUBG ransomware actually encrypted its victims' files back in 2018. Instead of money, the attackers simply demanded that victims play a popular video game for a set amount of time, after which the data was automatically released again.
A curious one-off, sure. But it points to something fundamental: ransomware groups depend on negotiation.
What ransomware is, and how the extortion has escalated
Ransomware is a type of malicious software, or malware, that restricts or completely blocks access to data and systems. Such a program either locks down access to the entire system, or it specifically encrypts user data.
Over the past few years, this simple basic idea has grown into a tiered extortion model:
The business model behind it: Ransomware-as-a-Service (RaaS)
Ransomware-as-a-Service is a cybercriminal business model in which developers sell or lease their malicious code to so-called "affiliates." These affiliates use the ready-made code to launch their own attacks. Anyone who outsources the technical development work to a RaaS provider needs almost no expertise of their own and can still get into cybercrime quickly.
When extortionists sound like a support team
At first glance, extortion in cyberspace looks purely destructive. But real negotiation chats often reveal surprisingly organized processes. Many groups behave like a service provider, complete with their own support teams and a noticeably deliberate way of handling the victim.
Disclaimer: Out of respect for the victims of cyberattacks, all of the chats below have been anonymized, unless the victim in question has already been named publicly by the attackers themselves or in the media.
Excessive friendliness
Despite their criminal intent, many actors maintain a deliberately professional, sometimes exaggeratedly friendly tone, aimed at defusing the victim's panic. Their greetings mirror those of an ordinary software helpdesk, while also trying to build trust in the "payment and decryption process."
Technical support for Bitcoin and Tor
Not every company is familiar with crypto exchanges or the Tor network. So groups offer step-by-step guides or chat-based technical support, in case victims simply don't know how to buy Bitcoin or use Tor.
Security advice after payment
Particularly bizarre: some groups treat their own hack, ironically, as a consulting service rendered. After payment, they hand over a detailed list of IT security shortcomings. For a moment, the extortionists slip into the role of a consulting firm.
A code of honor of their own
Some extortion groups distinguish themselves from other criminals through a supposed moral code, in order to polish their own image. Off-limits areas are usually critical infrastructure such as healthcare, orphanages, or educational institutions, since attacking these puts lives at risk or generates massive public pressure.
CLOP also announced that, should it accidentally encrypt such an organization, it would provide a free decryptor. The same moral line surfaced when LockBit accidentally encrypted the systems of a hospital for sick children. The group publicly apologized and likewise offered a free decryptor for recovery.
Friendliness, support, and a code of honor are all part of the strategy. A victim who feels they're in good hands pays faster and negotiates less.
Containing ransomware: the kill chain as a roadmap
Prevention is best planned along the typical attack chain: from the initial compromise to incident response, there are six phases, each with concrete countermeasures.
| Measure | Target phase | Core idea |
|---|---|---|
| Patch management | Initial breach | Exploited software vulnerabilities are among the three most common entry vectors used by ransomware groups. |
| Secured remote access | Initial breach | External access only via VPN, combined with two-factor authentication. |
| Email settings | Initial breach | Emails should be displayed as plain text rather than rendered as HTML, to avoid obfuscated links. In addition, execution of active content in HTML emails should be suppressed so that malicious scripts embedded in emails cannot run. |
| Program execution controls | Initial breach | Application whitelisting prevents unwanted software by only allowing approved programs to run. |
| Separate admin accounts | Privilege escalation | Privileged accounts reserved solely for administrative tasks, secured with their own 2FA. |
| Network segmentation | Limits ransomware's reach to immediately adjacent systems, containing the damage. This relies on secure use of administrator accounts. | |
| Active Directory hardening | After the initial compromise, the central authentication and authorization service is usually the target. Making Active Directory harder to compromise can be guided by the IT-Grundschutz module APP2.2 Active Directory Domain Services. | |
| Offline backups | Encryption | Physically or logically disconnected from the network after being created: the only reliable insurance against data loss. |
| Incident response plan | Incident response | Regularly rehearsed processes for responding to and restoring business-critical systems. |
Pay or not? A dilemma with no clean answer
Preventive measures are worthwhile but offer no 100 percent protection against ransomware attacks. That's why it's crucial to be clear in advance about whether you'll even engage in negotiations with attackers, and whether you would pay a demanded ransom if it came to that.
Without backups, and facing the threatened publication of sensitive customer data, a company's own reputation is also on the line: a massive breach of trust with customers that businesses rarely walk away from unscathed.
What the authorities recommend:
The FBI generally advises against paying ransom in a ransomware attack. Payment doesn't guarantee that data will be returned, and it encourages attackers to target further victims.
Europol: don't pay the ransom. A payment directly funds criminals and encourages them to continue their illegal activities.
The myth of the nice extortionist
The world of ransomware has long since evolved from flashy curiosities like the PUBG software into a billion-dollar shadow industry with its own corporate-style structures. Ransomware-as-a-Service shows how cybercriminals have adopted corporate structures to push victims, under extreme stress, toward paying quickly, while faking trust where none exists.
From an official standpoint, the question of whether to negotiate has a clear answer: don't pay. Every ransom paid funds the next wave of attacks and strengthens the criminal ecosystem. In practice, though, companies facing multi-extortion scenarios are often caught in a genuine dilemma, weighing the threat of data loss and reputational damage against their very survival. If negotiations are considered at all, they should never be entered into carelessly or treated as the primary option, but only as a tactical tool for gathering evidence and buying time.
The best protection against the "friendly" extortionist in the chat window remains uncompromising prevention: robust multi-factor authentication, airtight backup strategies, and regular employee training ensure that you never end up in a position of having to haggle with criminals over the price of your own data in the first place.
- Customer service, accounting, HR: welcome to the cybercrime corporation
- What a breach really costs: lost production, IR costs, lost customers, and personal liability
- From phishing email to domain admin: the complete attack path
How well is your company prepared for a real-world scenario like ransomware and ransom extortion?
We find the security gaps in your software before criminals can use them as an entry point. Free initial consultation.
Request a consultation →