Ransomware negotiation(s) with  lockbit3



Avatar

[Chat started]

24.12.2022 13:32:17 UTC
Avatar

Hello, do you have my data?

24.12.2022 13:33:50 UTC

Hi,yes

24.12.2022 13:49:53 UTC
Avatar

Your servers have been blocked. We also downloaded 178 GB of critical information in advance, which we will process and distribute to your customers and competitors if you don't comply with our conditions. The amount of your payout is $150...000 in BTC.

24.12.2022 13:50:30 UTC
Avatar
Avatar

Can you provide a list of the data or a sample

24.12.2022 13:50:38 UTC

Sure, wait pls

24.12.2022 13:50:46 UTC
Avatar

Stay in chat, we will send you the file tree soon...

24.12.2022 13:53:15 UTC
Avatar
Avatar

Okay

24.12.2022 13:54:48 UTC
Avatar

Is the amount $150,000 dollars?

24.12.2022 13:57:42 UTC

Apart from the files we downloaded, the rest of your files are encrypted if you haven't figured it out yet.Wait for us.

24.12.2022 13:58:07 UTC
Avatar

$150,000, Yes.

24.12.2022 13:59:06 UTC
Avatar
Avatar

Please send me the file tree.

24.12.2022 14:02:08 UTC

You can also use the test unlocker of any one file to make sure that you can get your data back.

24.12.2022 14:02:12 UTC
Avatar

Okay, wait, you will get file tree.

24.12.2022 14:02:32 UTC
Avatar
Avatar

Hi are you there?

24.12.2022 14:30:20 UTC

Yes, Wait a little more.

24.12.2022 14:37:14 UTC
Avatar
Avatar

Okay

24.12.2022 14:37:29 UTC

http://lockbitfile2tcudkcqqt2ve6btssyvqwlizbpv5vz337lslmhff2uad.onion/r/v1UfFE6UTG#IRNh78aAu+Nu+Cs1JZTbKNhPltLyYpVoEstJJ878owc=

24.12.2022 14:44:28 UTC
Avatar

This is not all the data that we have on hand.Among them there is a lot of confidential data.

24.12.2022 14:45:57 UTC
Avatar
Avatar

That is what my boss wants to know. Can you please provide a sample or listing of that data.

24.12.2022 14:47:19 UTC

We've already exposed some of your data, what else do you need?

24.12.2022 14:50:04 UTC
Avatar
Avatar

Have you already exposed our data? What site?

24.12.2022 14:52:46 UTC
Avatar

I just want to show my boss why we need to pay.

24.12.2022 14:55:16 UTC

No. we didn't do that.

24.12.2022 14:55:17 UTC
Avatar

http://lockbitfile2tcudkcqqt2ve6btssyvqwlizbpv5vz337lslmhff2uad.onion/r/v1UfFE6UTG#IRNh78aAu+Nu+Cs1JZTbKNhPltLyYpVoEstJJ878owc=

24.12.2022 14:59:02 UTC
Avatar

open the link, there's a list of your files, it's not a complete list

24.12.2022 14:59:45 UTC
Avatar

after payment, all your data will be deleted from our server

24.12.2022 15:03:07 UTC
Avatar
Avatar

Sorry my connection dropped. I will look now.

24.12.2022 15:13:59 UTC

ok

24.12.2022 15:15:49 UTC
Avatar
Avatar

We will need time. It is a big holiday here in the US.

24.12.2022 15:16:31 UTC
Avatar

Can you share at least one confidential data file please.

24.12.2022 15:18:00 UTC

Wait a little while. Selecting a file

24.12.2022 15:32:40 UTC
Avatar

File: [Screenshot_2.png]

24.12.2022 15:54:29 UTC
Avatar

We did not have much time to study your documents in depth. We are sending you a screenshot of the scanned documents, which also contain confidential information.

24.12.2022 15:54:42 UTC
Avatar

And this is just one of the many folders

24.12.2022 15:55:25 UTC
Avatar

You can also use the test decryptor to decrypt one of the files. This way you can make sure that you get a fully working server after the payment.

24.12.2022 15:57:22 UTC
Avatar

You are also warned that you have 7 days to settle this issue. We will post your files on December 31st. --On shady forums where they can be used by hackers, carders, bank specialists, technology spies, and other specialists. -Send them to all your contacts, customers and partners. After that, in our experience, the business comes to an end and multimillion dollar lawsuits from affected employees, customers and competitors begin. --Competitors. They will be able to find a lot of the information they need from your files. -Controlling government agencies. We doubt you have perfect accounting and record keeping. We look forward to a timely and correct decision on your part.

24.12.2022 16:47:58 UTC
Avatar

BTC Wallet 14mwyF23z3NMaWumKcP6P2yEeiZsjFpS7J

24.12.2022 18:29:13 UTC
Avatar
Avatar

Thank you. We will work on this.

24.12.2022 21:48:54 UTC

4 days left.

26.12.2022 22:19:21 UTC
Avatar

1 day left

29.12.2022 14:19:00 UTC
Avatar
Avatar

Hello! We are working hard to meet your demands. We need more time. We are trying to setup the wallet an transfer the money. As a professional, you know this takes time and the banks are slow around the holidays. Also, can you please reduce the price a little. We don't have that kind of money.

30.12.2022 00:45:24 UTC
Avatar

Will you tell us how you got in so we can fix the systems?

30.12.2022 00:47:10 UTC

Hello.

30.12.2022 12:24:23 UTC
Avatar

We believe that your business is insured against such situations, and we also don't believe that you can make a BTC wallet for 1.5 weeks and transfer money to it. Further delay will only increase the cost. As for how we got into the system, of course we can tell you, but for a separate fee of $10,000.

30.12.2022 13:04:15 UTC
Avatar
Avatar

Hello, we do not have insurance and Bitcoin will not allow a transfer that large for a new wallet. We are doing all we can.

30.12.2022 13:26:02 UTC

We don't see any problems in replenishing the BTC wallet.If you delay the solution of this issue, the price will increase.

30.12.2022 15:46:18 UTC
Avatar

We advise to use non-custodial crypto wallets

30.12.2022 19:54:44 UTC
Avatar
Avatar

We are working on it.

03.01.2023 00:12:54 UTC

We understand that it was a great holiday in the USA. however, we have been doing this business for a long time and cannot give you much time to solve this problem. Another 2 days, and the price will increase by 50k.

03.01.2023 00:34:47 UTC
Avatar
Avatar

Thank you. We are working as fast as we can.

03.01.2023 16:33:06 UTC
Avatar

Hi, did you call our office? Someone keeps calling?

03.01.2023 21:36:42 UTC
Avatar

I want to confirm you are now giving us until Jan 15 for 200k. Is that correct?

03.01.2023 21:44:33 UTC

Hi.

03.01.2023 21:48:45 UTC
Avatar
Avatar

Hi, did you call our office?

03.01.2023 21:52:01 UTC

Yes, we call your office.

03.01.2023 21:52:16 UTC
Avatar
Avatar

I want to confirm you are now giving us until Jan 15 for 200k. Is that correct?

03.01.2023 21:55:18 UTC

We called to show you our capabilities. The price of 200k will be in 2 days and will only grow with 50k every extra week .

03.01.2023 21:55:22 UTC
Avatar
Avatar

Thanks.

03.01.2023 21:56:02 UTC

Now the price is $200.000.

05.01.2023 17:48:42 UTC
Avatar
Avatar

Hi, You told us you would give us till Jan 15 for 200K. Someone called us today and said the price is now $350.000.00. Why has the price changed?

07.01.2023 22:41:15 UTC

Hello. We told you that on January 15 our decryptor will stop working and your servers will remain encrypted forever. We didn't promise you anything about a price increase. Your employees made a mistake - the price is not 350.000 but 250.000 and will increase every two days. The next increase of 50,000 will be January 9. This is payment for your slowness. And on January 15 we will begin to publish your confidential information on the shadow forums, as well as send it to your clients, competitors and regulatory agencies in the United States. For now, the solution to the problem is entirely in your hands.

08.01.2023 03:21:56 UTC
Avatar

http://lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead.onion/post/mdmHYFTbYU3oSJ4P63bd7fb7214ee

10.01.2023 15:04:18 UTC
Avatar

Your negotiator obviously already got the operating money to solve this situation, but since now there is a slight upward trend in BTC - apparently he wants to make a little more money on this growth. No need to play with us. You have a deadline of January 15. Then we publish and send your data everywhere we can (and we can do a lot). Change the recovery, or pay the final price of $250,000 by January 15.

10.01.2023 19:07:23 UTC
Avatar

We are starting to publish and distribute data.

03.02.2023 14:39:37 UTC
Avatar
Avatar

Hello. I am the new person in charge of talking with you. Can you please provide proof that you have our data. I would like to see some of the acutal files. Once you do that, we can chat about your demands.

12.02.2023 22:49:16 UTC

Hello, wait

13.02.2023 16:12:39 UTC
Avatar
Avatar

Hello

13.02.2023 19:50:38 UTC

You have a lot of confidential data and correspondence. What are your suggestions and options?

13.02.2023 21:28:59 UTC
Avatar

Also recall that the spreading of correspondence is punishable by huge fines, as well as administrative penalties up to the liquidation of the company. https://en.wikipedia.org/wiki/Electronic_Communications_Privacy_Act

13.02.2023 21:43:42 UTC
Avatar

Hello. Since you are a new person, we will repeat it again for you. We have a huge number of critical files for you. Even a small number of your files will not only put an end to your business and the career of your employees, but will also lead to a large number of lawsuits for the distribution of confidential information of your customers and partners. A bonus for you will be sending all of your documentation (including accounting) - to the relevant regulatory agencies, which will be interested in the fact of the spread of your critical data, and someone may want to take the chance and improve their career. You understand that the law in any country is an extremely subjective thing, which can be turned either in your direction or against you. We have not published your data just because we have a lot of work to do right now, and we are very creative in spreading client information - we want as many people connected with you as possible to know that you have allowed a situation where their finances and safety are in danger due to your fault. We are attaching some screenshots of the most interesting, from our point of view, files. This is not everything, just a small part of what we have. Think about it.

14.02.2023 19:06:03 UTC
Avatar

File: [01.PNG]

14.02.2023 19:07:45 UTC
Avatar

File: [04.PNG]

14.02.2023 19:07:47 UTC
Avatar

File: [06.PNG]

14.02.2023 19:07:48 UTC
Avatar

File: [05.PNG]

14.02.2023 19:07:51 UTC
Avatar

File: [02.PNG]

14.02.2023 19:07:57 UTC
Avatar

File: [08.png]

14.02.2023 19:08:01 UTC
Avatar

File: [07.PNG]

14.02.2023 19:08:31 UTC
Avatar
Avatar

I need a few files so show to my team. Screen shots are not good enough. Also, we will need to know how our systems were compromised.

14.02.2023 19:22:01 UTC

You can use the instruction and decrypt any 2 files on your own

14.02.2023 19:27:37 UTC
Avatar

We will provide any information you are interested in after payment. I think you will be extremely surprised.

14.02.2023 19:28:42 UTC
Avatar
Avatar

I need to show my executive team actual files not screenshots in order to move forward. Please upload a few files.

14.02.2023 19:46:43 UTC

Are you in doubt about the availability of your files with us?

14.02.2023 20:02:05 UTC
Avatar

File: [September 2018 Statements.pdf]

14.02.2023 22:21:01 UTC
Avatar

File: [September 2018 Statements.pdf]

14.02.2023 22:22:00 UTC
Avatar

File: [001.PNG]

14.02.2023 22:26:34 UTC
Avatar

more?

14.02.2023 22:27:07 UTC
Avatar
Avatar

Yes please.

15.02.2023 15:22:41 UTC

We will send you two more files and that will be all. We are waiting for your decision

15.02.2023 17:32:43 UTC
Avatar

File: [0006contract-4.pdf]

15.02.2023 17:42:49 UTC
Avatar

File: [email list 11'22 PR.xls]

15.02.2023 17:43:31 UTC
Avatar
Avatar

Thanks we will be in touch.

15.02.2023 19:22:51 UTC

We hope for your discretion.

16.02.2023 04:06:07 UTC
Avatar

Do we understand correctly that your company isn't interested in solving this problem?

20.02.2023 20:24:24 UTC
Avatar
Avatar

We are, but are still in discussions. We need more time. Thanks

21.02.2023 16:36:01 UTC

While you are stalling for some reason, we will publish and distribute some of the data. You'll like it. You're welcome.

21.02.2023 21:53:48 UTC
Avatar

Let's start with corporate correspondence. Since we have your confidential files, we have access to your correspondence. The first people to receive your shared correspondence are: 1.Anne Vandeveer ABV Retirement Plan Advisors, Inc. anne@abvadvisors.com (855) 550-0228 2.Van Shelton Actuaries & Associates (Amarillo) van@actuariesandassociates.com (806) 373-3624 3.Lorraine Dorsa Aegis Pension Services LDorsa@AegisPension.com (904) 686-1835

21.02.2023 22:49:31 UTC
Avatar

Hello. This is the Lockbit team. We see that you relaxed and thought that we had forgotten about you? Don't worry - we have enough time and energy for everyone. Your data is quite interesting because you did all the work for us. For example, the Active Clients folder in the Scanned Client Info folder is just ready to be delivered to your clients, don't you think? How will your life and financial well-being (not to mention your reputation and credibility) change when all the documents are in the public domain? Let's not hide it - we have partners who would love to buy all your data from us. But we want to help you first and save, first of all, the fate of you and your employees. It's not very pleasant to find yourself on the street with huge debts from lawsuits and to be blacklisted by employees who allowed leaks and damage to the businesses of partners who trusted you. You still have the option to settle with us, and we are committed to removing all of your files and pointing out cybersecurity issues. The choice is yours...

31.03.2023 06:39:22 UTC
Avatar

Hello. This is Lockbit. We have prepared files that we will send to the people who signed them describing the whole situation and your attitude to their security and trade secrets. We are sending you some of the screenshots for your review. Recipients: Pension Advisory Group, Ltd. -pag@pagltd.com -dennis@pagltd.com -melody@pagltd.com Frost, PLLC -drichardson@frostpllc.com -dcooper@frostpllc.com -erachal@frostpllc.com We will send out tomorrow, so you have 24 hours to go to tor chat and start solving the problem.

19.04.2023 03:59:04 UTC
Avatar

File: [1.png]

19.04.2023 03:59:28 UTC
Avatar

File: [4.png]

19.04.2023 03:59:28 UTC
Avatar

File: [3.png]

19.04.2023 03:59:28 UTC
Avatar

File: [2.png]

19.04.2023 03:59:29 UTC
Avatar

Hello. Tomorrow it's CJK Group's turn - there are also some documents for them, some of which we will send. Not ready to negotiate yet?

20.04.2023 15:38:34 UTC
Avatar

We have plenty of time and materials to send. That's why we don't have to rush. But you will lose more and more clients and partners every day.

20.04.2023 15:39:28 UTC
Avatar

Hello. Since you are not responding to messages, we will be sending out messages to your customers for another week, and then we will start publishing these documents on social networks.

01.05.2023 10:44:59 UTC
Avatar

This information is provided by Valéry Marchive