Dealing with Shadows

No ratings

Presented at BSidesAugusta 2026 by

Ransomware negotiations are rarely just about money. They are high-pressure engagements shaped by psychology, leverage, timing, and uncertainty, all while organizations are still assessing the scope of compromise. This talk offers a practitioner’s perspective on negotiating with threat actors during live extortion events. Drawing on real-world cases, it examines how threat actors communicate, what their behavior signals, and how disciplined negotiation strategy can influence outcomes beyond the final payment amount. Attendees will learn how pacing, message control, and delay are used to buy time, reduce risk, and preserve decision-making authority under crisis conditions. The session also addresses common misconceptions about ransom negotiations, frequent mistakes that increase cost and exposure, and how negotiation fits into a broader incident response strategy that balances technical, legal, financial, and human factors. This presentation is about what works, and what doesn’t. What you should do, and maybe more importantly, what you should never do.