ZeroHour
Help Net Securitypublished ()ingested Help Net Security

Ransomware negotiation tactics have turned into a business process

infoRansomwareimportance 32
AI summary · glm-5.3-flash

Intel 471's Dave Ross details ransomware negotiation tactics, with demands typically set at 1-5% of annual revenue and specialized criminal service roles.

In a Help Net Security video, Intel 471 Senior Director Dave Ross explains how ransomware groups research a victim's revenue and insurance coverage, run test decryptions to prove they hold a working key, and set demands at roughly 1% to 5% of annual revenue. He describes negotiation dynamics with shifting deadlines and a criminal service economy supplying language skills, data review, and legal analysis. Multi-extortion methods include data theft, DDoS attacks, and direct contact with customers and journalists.

  • Groups stage test decryptions to demonstrate working keys before settlement.
  • Negotiation deadlines move depending on how victims respond during talks.
  • Specialized roles split work between researchers, negotiators, and public-pressure staff.
  • Pre-incident preparation should define authorized negotiators and involved stakeholders.
Full article155 words · extracted from helpnetsecurity.com · click to collapse

In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations.

Ross walks through the tactics groups use once an attack begins, from research on a victim’s revenue and insurance coverage to test decryptions that prove they hold a working key.

He describes how demands are often set at roughly 1% to 5% of annual revenue, why deadlines move depending on how a victim responds, and how some groups split work between researchers, negotiators, and staff who apply public pressure.

He also covers the criminal service economy supplying language skills, data review, and legal analysis, along with multi-extortion methods such as data theft, DDoS attacks, and contact with customers and journalists. He outlines the preparation that should happen before an incident, including who is authorized to speak and which stakeholders to involve.

Download: 2026 Credential Risk Report

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/