• NordStellar finds many ransomware negotiations go unpaid, usually at steep discounts (median 57%, max 96.2%)
  • Attackers used varied tactics: bundling “services,” offering fake security audits, proof of data, press threats, GDPR violations, and price manipulation
  • Leaking stolen files remained the dominant pressure tactic (76.8%), but deadlines were often bluffs designed to push victims into paying

While threatening to leak stolen data is still the most effective negotiation strategy in ransomware attacks, it’s not the only one, as new research from NordStellar has found cybercriminals employ a whole range of tactics, from significant discounts, to providing “security audits and reports” to the victims.

The company recently analyzed 246 leaked conversations between ransomware groups and victim companies that took place between 2020 and 2026.



Source link