29.3%
Payment rate (71 of 242 chats)
$695K
Median initial demand (n=186)
$150K
Median final agreed (n=83)
60%
Median discount off demand
14.4 days
Median negotiation duration
14 min
Median operator reply time
Threat Frequency
Threat made during negotiationChats% of corpus
Data publication18074.4%
Data sale4418.2%
Media exposure4217.4%
GDPR / legal action177.0%
Regulator referral156.2%
Employee/family contact125.0%
DDoS52.1%

A single chat can carry multiple threats; percentages are share of 242 conversations.

Operator Tone
Dominant toneChats% of corpus
Professional10342.6%
Scripted7430.6%
Aggressive5020.7%
Mocking156.2%
Victim Stance
How the chat endedChats% of corpus
Negotiated9438.8%
Paid6627.3%
Ghosted4016.5%
Stalled3112.8%
Refused114.5%
Deletion-Promise Outcomes
OutcomeChats% of corpus
Deletion promised12150.0%
No deletion promise8033.1%
Proof of deletion shown4016.5%
Promise reneged10.4%
By Ransomware Group (groups with ≥5 conversations)
GroupChatsPayment rateMedian demandMedian agreedMedian discountTop tone
Akira6031.7%$390K$150K55%Professional
lockbit3.0429.5%$1.2M$50K38%Aggressive
Conti3240.6%$980K$290K68%Professional
REvil2045.0%$2.5M$190K76%Professional
Dragonforce140.0%$950K$112K81%Professional
trinity1421.4%$30K$28K85%Scripted
Hive812.5%$1.1M$170K45%Professional
Avaddon728.6%$300K$16K62%Professional
Nightspire7100.0%$125K$90K27%Professional
fog650.0%$245K$150K66%Professional
BlackBasta580.0%$650K$225K50%Professional
Darkside540.0%$1.5M$250K62%Professional

14 of 26 groups suppressed: with fewer than 5 conversations a “median” is one victim’s deal, not an aggregate.

Methodology

Corpus: 242 ransomware negotiation conversations (11,514 messages) across 26 groups, collected by the Bedrock negotiation-corpus pipeline from public leak-site negotiation chats.

Extraction: each chat is parsed by an LLM-assisted extraction pipeline into structured fields (demands, amounts, tone, threats, outcome); this page aggregates those fields. Figures are corpus-wide medians and rates.

Per-group rows require at least 5 conversations (small-n suppression); a dash (—) marks medians with no usable observations.

Timing figures (duration, reply times) cover only the 95 of 242 chats with parseable timestamps; 6,454 messages corpus-wide lacked parseable timestamps.

All figures are aggregates across the research corpus; no victim-identifying data appears on this page. Page regenerated by build_negotiation_stats.py from the corpus aggregate — figures update when the corpus is re-aggregated, not live.