Data as of 2026-07-31 · 242 conversations · 11,514 messages · 26 groups
| Threat made during negotiation | Chats | % of corpus |
|---|---|---|
| Data publication | 180 | 74.4% |
| Data sale | 44 | 18.2% |
| Media exposure | 42 | 17.4% |
| GDPR / legal action | 17 | 7.0% |
| Regulator referral | 15 | 6.2% |
| Employee/family contact | 12 | 5.0% |
| DDoS | 5 | 2.1% |
A single chat can carry multiple threats; percentages are share of 242 conversations.
| Dominant tone | Chats | % of corpus |
|---|---|---|
| Professional | 103 | 42.6% |
| Scripted | 74 | 30.6% |
| Aggressive | 50 | 20.7% |
| Mocking | 15 | 6.2% |
| How the chat ended | Chats | % of corpus |
|---|---|---|
| Negotiated | 94 | 38.8% |
| Paid | 66 | 27.3% |
| Ghosted | 40 | 16.5% |
| Stalled | 31 | 12.8% |
| Refused | 11 | 4.5% |
| Outcome | Chats | % of corpus |
|---|---|---|
| Deletion promised | 121 | 50.0% |
| No deletion promise | 80 | 33.1% |
| Proof of deletion shown | 40 | 16.5% |
| Promise reneged | 1 | 0.4% |
| Group | Chats | Payment rate | Median demand | Median agreed | Median discount | Top tone |
|---|---|---|---|---|---|---|
| Akira | 60 | 31.7% | $390K | $150K | 55% | Professional |
| lockbit3.0 | 42 | 9.5% | $1.2M | $50K | 38% | Aggressive |
| Conti | 32 | 40.6% | $980K | $290K | 68% | Professional |
| REvil | 20 | 45.0% | $2.5M | $190K | 76% | Professional |
| Dragonforce | 14 | 0.0% | $950K | $112K | 81% | Professional |
| trinity | 14 | 21.4% | $30K | $28K | 85% | Scripted |
| Hive | 8 | 12.5% | $1.1M | $170K | 45% | Professional |
| Avaddon | 7 | 28.6% | $300K | $16K | 62% | Professional |
| Nightspire | 7 | 100.0% | $125K | $90K | 27% | Professional |
| fog | 6 | 50.0% | $245K | $150K | 66% | Professional |
| BlackBasta | 5 | 80.0% | $650K | $225K | 50% | Professional |
| Darkside | 5 | 40.0% | $1.5M | $250K | 62% | Professional |
14 of 26 groups suppressed: with fewer than 5 conversations a “median” is one victim’s deal, not an aggregate.
Corpus: 242 ransomware negotiation conversations (11,514 messages) across 26 groups, collected by the Bedrock negotiation-corpus pipeline from public leak-site negotiation chats.
Extraction: each chat is parsed by an LLM-assisted extraction pipeline into structured fields (demands, amounts, tone, threats, outcome); this page aggregates those fields. Figures are corpus-wide medians and rates.
Per-group rows require at least 5 conversations (small-n suppression); a dash (—) marks medians with no usable observations.
Timing figures (duration, reply times) cover only the 95 of 242 chats with parseable timestamps; 6,454 messages corpus-wide lacked parseable timestamps.
All figures are aggregates across the research corpus; no victim-identifying data appears on this page. Page regenerated by build_negotiation_stats.py from the corpus aggregate — figures update when the corpus is re-aggregated, not live.