Exploring Victim-Offender Interactions During a Ransomware Attack Using LockBit Chat Negotiations
Abstract
This study explores interactions between ransomware victims and offenders through a qualitative analysis of chat negotiations of the LockBit ransomware group (n=147), providing insight into data exfiltration, extortion, communication and negotiation, payment, and post-payment outcomes. The findings show that both offenders and victims employ bounded rational decision-making. For offenders, this is exemplified by aspects such as tailor-made ransom demands for each victim and balancing between trust signals and pressure tactics. For victims, this includes aspects such as the reasoning behind the decision to negotiate and pay a ransom demand, considering for example, the financial situation of their company, value of the data, and time and effort required to recover without a decryptor. However, both parties also have to deal with information asymmetry, including offenders having incomplete information on the victim’s finances or the value of the data, or victims being unsure about the credibility of the ransomware group. The findings also illustrate the interplay between both parties in shaping the outcome of the ransomware attack, and the professional aspects and imperfections of LockBit’s ransomware operations. The study highlights the importance of understanding victim-offender interactions during ransomware attacks, while also providing practical implications for the support of victims.
// Source
Authors: Sifra R. Matthijsse, M. Susanne van ‘t Hoff-de Goede, Rutger Leukfeldt
Institutions: Leiden University, The Hague University of Applied Sciences, Netherlands Institute for the Study of Crime and Law Enforcement