For a company with a digital infrastructure, a serious cyber incident is not an abstract threat. An attack can begin with an API key leak, phishing, the exploitation of a vulnerability, the compromise of a contractor, or the use of stolen credentials. But the situation becomes particularly complex when, after gaining access, the attackers demand a ransom for restoring systems or a promise not to publish the information.
At this point, the company faces more than just a technical problem. Extortionists exploit fear, tight deadlines, excessive demands, and uncertainty regarding the scope of the stolen data. The main task is to regain control over decision-making and separate confirmed facts from threats.
What PWN-ALL Incidents Reveal
According to PWN-ALL’s internal analytics, the identified causes of compromise included leaks of API keys and other access keys from third parties (28.3%), weak or default passwords (18%), and the exploitation of software vulnerabilities (7%). Other scenarios included phishing, infostealers, and account compromise.
1. “You have 72 hours”: Manipulating a Sense of Urgency
In a letter to management or the information security department, the extortionists may set a deadline of 72–120 hours. After that, they promise to publish the data, increase the ransom amount, or contact customers and journalists. These threats are usually accompanied by a description of the alleged financial, reputational, and legal consequences.
Such a timer is a tool for applying pressure, not independent evidence of the attack’s scale. It should be taken into account when responding, but it should not override the decision-making process. Furthermore, the attacker may publish the information before their own deadline.
Initial Communication: Verification, Not Acknowledgment
Receiving a demand does not oblige the company to immediately engage in correspondence. If contact is necessary, it is advisable to conduct it through a trained Incident Response specialist or negotiator, with the involvement of the legal team. The CEO’s personal email inbox or unsupervised responses from employees are a poor foundation for a controlled process.
“We have received your message and are verifying the claims made. Supporting evidence is required to assess the alleged scope of access and the nature of the data. Receipt of this message does not constitute an acknowledgment of the alleged extent of the breach or an agreement to pay.”
This is an illustration of a possible position, not a universal response template. The decision on whether to send a message—and in what form—must take into account the circumstances of the incident, legal advice, and the insurer’s requirements.
Communication can sometimes buy additional time, but it does not guarantee a delay in disclosure and does not suspend mandatory legal deadlines. At the same time, it is necessary to restrict the attacker’s access, preserve evidence, and verify backups.
2. “We’ve stolen everything”: Manipulating the Volume of Data
Attackers often claim to have stolen all documentation, source code, customer databases, or tens of terabytes of information. As proof, they show directory structures, project names, and a few files. However, a list of files does not prove the existence of their contents.
Access, reading, and exfiltration are different scenarios
A compromised account or API key may have limited permissions. For example, list some services allow users to view object names and metadata without access to the actual content. An operation read may return the data itself and thereby allow it to be copied. Certain operations download or export are not available in all systems.
There is no universal hierarchy of permissions such as list → read → download. You need to evaluate the specific platform, the assigned permissions, and the actual requests made. The ability to read a file does not necessarily mean it has actually been downloaded, and the absence of a separate download permission does not preclude copying via the read operation.
Verifying Evidence When Logs Are Incomplete
First and foremost, the IR team should use independent sources: authentication and API logs, cloud audits, EDR/XDR, network connection events, changes in access permissions, and information about potential data preparation and exfiltration. It is necessary to determine which resources were accessible, what was actually read, and what signs of exfiltration remain.
If the logs are incomplete, one cannot automatically conclude either that no leak occurred or that the extortionist’s claims are true. This uncertainty must be explicitly stated in the risk assessment.
An additional verification method could be a controlled sample drawn from the set of files already claimed by the attacker. For example, the IR team selects random files from several projects specified by the attacker and verifies whether the attacker can prove ownership of their actual contents, not just their filenames. The procedure should be agreed upon in advance: do not reveal a directory structure unknown to the attacker, send additional secrets, or provoke a new data breach.
Such a verification has its limits. Demonstrating five selected files does not confirm ownership of five million files. Conversely, a refusal or inability to produce a single sample does not prove that other data was not copied.
For the analysis, it is helpful to distinguish between four conclusions:
- The attacker gained access to the system.
- They were able to view specific objects or their metadata.
- They actually obtained the contents of specific files.
- They have a copy of the entire claimed data set.
Additional evidence is required for each subsequent claim. The attacker should not be both the sole provider of evidence and the primary assessor of the damage.
3. The millions of dollars mentioned in the letter are not the final amount
The initial demand reflects the extortionist’s position. It is not a fixed price nor an objective recovery cost. In known anonymized PWN-ALL cases, there was a significant difference between the amount demanded and the amount actually paid:
| Initial demand | Actual payment | Reduction |
|---|---|---|
| $50,000,000 | $15,000,000 | 70% |
| $1,000,000 | $75,000 | 92.5% |
In the third example provided, the company transferred $10,000 in exchange for a promise to delete the data. The mere fact of payment does not constitute confirmation of actual deletion.
These are individual, anonymized examples provided by our company. They do not allow for calculating an average negotiation outcome, the probability of a payment, or a guaranteed “discount.”
For comparison: in the 2026 Unit 42 Global Incident Response Report, the median reduction in the initial demand in cases involving negotiations in 2025 was 61%. This result is based on a different sample and cannot be directly compared to individual PWN-ALL cases.
A significant reduction in the demand does not make payment safe. The decision should be based on the organization’s ability to recover on its own, the actual value of the compromised information, the cost of downtime, potential consequences for customers, and available legal alternatives. The less an organization relies on the attacker’s promises, the stronger its position.
4. Legal Risks: Penalties, Insurance, and Legal Support
The statement “paying extortionists is permitted” is not universally true. Applicable rules depend on the company’s jurisdictions, the affected divisions, the industry, the recipient of the funds, the payment route, and applicable restrictions. For certain organizations or recipients, the payment may be prohibited.
In particular, the U.S. Office of Foreign Assets Control (OFAC) warns of sanctions risks associated with ransomware payments. The U.K.’s Office of Sanctions Implementation (OFSI) also notes that transferring funds or crypto-assets to a sanctioned entity can lead to serious consequences. The status of a crime victim does not automatically exempt an organization from sanctions requirements.
Before any payment is considered, a legal review of known addresses, the intended recipient, associated entities, and restrictions is required. Verifying a single cryptocurrency wallet does not, in and of itself, guarantee that the transfer is permissible.
Lawyers must be involved from day one
The legal team supports the incident at every stage: it identifies obligations to regulators and clients, coordinates external communications, assists in preserving evidence, verifies sanctions restrictions, and documents the rationale for decisions. Bringing in lawyers only immediately before payment is too late.
The procedures for preparing technical reports, accessing internal correspondence, and sharing materials with third parties should be established in advance. In some jurisdictions, certain communications may be protected by attorney-client privilege or legal privilege. However, engaging a lawyer does not automatically render all documents and investigation findings confidential: the applicability of such protections requires a separate legal assessment. See the American Bar Association’s guidance.
If you have cyber insurance—review your policy immediately
You should promptly notify your insurer or broker of the incident in accordance with the terms of the policy. Some policies specify approved incident response (IR) contractors, legal counsel, and requirements for notification and prior approval of certain expenses or actions.
Do not independently promise a ransom, engage a negotiator, or incur significant expenses without first verifying whether the insurer’s approval is required. However, the need for such approval should not prevent you from taking urgent measures to contain the attack and preserve evidence. The NCSC emphasizes the importance of notifying the insurer early.
Law Enforcement and I-GRIP
The legal department, together with management and the Incident Response team, must promptly coordinate a report to the appropriate law enforcement agencies. If funds have already been transferred, it is especially important to preserve transaction details, transaction IDs, wallet addresses, amounts, timestamps, and correspondence.
One mechanism for international cooperation is INTERPOL’s Global Rapid Intervention on Payments (I-GRIP). It helps law enforcement agencies quickly coordinate actions to curb illicit financial flows, including those related to virtual assets. However, I-GRIP is primarily used in cases of financial fraud; the possibility of using it in a specific ransomware incident is assessed by the competent authorities.
The company does not initiate I-GRIP directly, and its use does not guarantee that the ransom will be blocked or refunded. You should not delay contacting them until negotiations are complete. For more details, see the INTERPOL article dated July 9, 2026.
5. Correspondence and Contacts with Customers as Additional Leverage
Extortionists may demand that an employee admit to the data breach before the investigation is complete, and then use that admission to threaten to contact regulators, partners, or journalists. They may also write directly to customers, call employees, or threaten to publish internal correspondence.
In the 2026 Unit 42 report, such harassment tactics were noted in 10% of extortion cases from 2025 in the sample studied. This is not an estimate for all cyber incidents worldwide.
A company should use an agreed-upon channel for negotiations, document the timing and content of communications, limit the number of authorized representatives, and prepare a communication plan in advance for employees, customers, and the press. Assumptions should not be presented as confirmed facts, but a confirmed incident should not be concealed for the sake of a negotiating position.
The attacker’s deadline is not the same as the statutory deadline
For example, under the GDPR, a data controller is required to notify the competent supervisory authority without undue delay and, if possible, no later than 72 hours after becoming aware of a personal data breach, unless such a breach is unlikely to pose a risk to the rights and freedoms of individuals.
If there is a likely high risk, there is a separate obligation to notify the affected individuals without undue delay, subject to statutory exceptions. The point at which the organization becomes aware is determined by a reasonable degree of certainty regarding the breach, not by the wording of the response to the extortionist. If all details have not yet been established, the notification—where such an obligation exists—may be supplemented in stages. See the guidance from the European Data Protection Board.
Different requirements and timeframes may apply in other countries, industries, and contractual relationships. Negotiations with the attacker do not, in and of themselves, suspend the notification obligation.
6. Even after payment, there are no guarantees
Payment does not guarantee that the data will be deleted, that a working decryption key will be provided, or that the threats will cease. The attacker may retain copies, share them with partners, demand additional money, or publish the information despite any promises.
This has been confirmed by other real-world investigations. Following an operation against LockBit, the UK’s National Crime Agency reported that it had discovered data belonging to victims who had already paid the ransom on the group’s infrastructure. In other words, the payment did not ensure the promised destruction of the information. Source: NCA, February 20, 2024.
Paying in installments does not protect against publication
Splitting the ransom into installments does not provide any additional technical guarantees. The data may be published after the first payment, before the next one, or even after the full amount has been transferred. Even a demonstration of the “deletion” of files does not prove that other group members or other storage media do not have copies.
Therefore, it is more accurate to refer to payment in exchange for a promise to delete the data, rather than a confirmed purchase of “complete deletion.” Similarly, a decryption key—even if it works—does not prove that the original vulnerability has been fixed or that the attacker’s access to the infrastructure has been blocked.
7. An Alternative to Paying the Ransom: Recovery and Independent Assessment
Before discussing payment, you should assess the possibility of recovery from verified backups, system reconstruction, and the use of available decryption tools. For example, No More Ransom publishes free decryptors for specific families of ransomware. The tool’s compatibility must be verified in a secure environment; decryption alone does not replace addressing the root causes of the compromise.
According to the company’s internal assessment published on the PWN-ALL Ransomware Recovery page, in approximately 94% of ransomware incidents in which PWN-ALL was involved between 2024 and 2026, full or partial recovery was achieved without paying the ransom—through backups, research into decryption methods, or partial data reconstruction.
This is a metric reported by PWN-ALL based on its own experience and is not an independently audited statistic. The metric does not guarantee identical results for future clients and does not indicate the likelihood of already stolen information being published.
In another PWN-ALL article on incident response, we described a situation in which an attacker began downloading data from an AWS storage bucket just six minutes after obtaining the key. This specific case illustrates why log retention, rapid access restriction, and the coordinated efforts of the incident response (IR) team, legal counsel, and management are critical.
However, restoring system availability does not negate a potential privacy breach. Issues related to recovery, exfiltration, notifications, and ongoing protection must be addressed separately.
So, is it safe to pay the extortionists?
No. Paying the ransom may be considered one of several scenarios in a complex incident, if it is legally permissible, but it cannot be regarded as a safe way to “close the matter.”
You must take action on multiple fronts simultaneously: verify the claims, contain the compromise, preserve evidence, assess the damage, involve legal counsel and your insurer, fulfill notification obligations, contact law enforcement if warranted, and explore recovery options. The decision regarding a potential payout is made separately, based on an agreed-upon risk assessment.
The strongest negotiating position arises not when a company knows how to bargain, but when it can afford not to pay.
The key question is not “how much can the claim be reduced?” but “what risks will remain after payment, and is there a less risky alternative?”
This material is for informational purposes only and does not constitute legal advice or a recommendation to make a payment. The legality of payment, notification obligations, insurance coverage terms, and reporting to law enforcement must be evaluated with qualified consultants specializing in applicable law.
Have you received a ransom demand? Do not make a decision under pressure.
If your company is facing a cyber extortion attack, a threat of data disclosure, or infrastructure compromise, the PWN-ALL team can help verify the attackers’ claims, determine the scope of the incident, preserve evidence, evaluate recovery options, and organize a managed incident response.
Rely on verified facts, not on the attacker’s deadlines and promises.