Ransomware Negotiation Tactics Evolve into Business Process

Ransomware Negotiation Tactics Evolve into Business Process

First seen 8 Sep 2026, 08:02 UTC HelpnetsecurityGround.Newswww.itsecuritynews.infocybernoz.comnationalcybersecurity.com 51.9

Article Content

Browse articles
ThreatCluster

In a recent video, Dave Ross from Intel 471 discusses the evolving tactics of ransomware negotiations. He explains that attackers conduct thorough research on victims' financials and insurance to set ransom demands typically between 1% to 5% of annual revenue. The negotiation process has become systematic, with roles divided among researchers, negotiators, and public pressure teams. Multi-extortion strategies are also employed, including data theft and DDoS attacks. Preparation before an incident is crucial, involving clear communication protocols and stakeholder engagement. This shift indicates a growing sophistication in ransomware operations, impacting organizations across various sectors.

Key Points: • Ransom demands are set at 1% to 5% of annual revenue. • Ransomware negotiations now involve specialized roles and tactics. • Preparation and stakeholder involvement are critical before a ransomware incident.

Ask AI about this cluster

Timeline

2026-09-08
Dave Ross discusses ransomware tactics
In a Help Net Security video, Ross outlines the business-like approach to ransomware negotiations, highlighting systematic tactics used by attackers.
cybernoz.com
2026-09-08
Multi-extortion methods detailed
Ross explains how ransomware groups employ various extortion methods, including data theft and DDoS attacks, to pressure victims.
Helpnetsecurity