Ransomware negotiation(s) with  lockbit3



Avatar

[Chat started]

29.06.2022 18:43:54 UTC
Avatar

Hello. Thank you for your message. My bosses have said that they are taking this very seriously and want to work with you to find a solution.

29.06.2022 19:07:39 UTC

Hi. Ok.

29.06.2022 19:08:08 UTC
Avatar
Avatar

Hi, what are the next steps please so that we can move forward with you?

29.06.2022 19:08:13 UTC

Here is the scheme. You pay us $5,000,000. We give you decryptor and remove your company from our blog and never publish stolen files as well delete them.

29.06.2022 19:08:17 UTC
Avatar
Avatar

That is a tremendous amount of money that you are asking for and a figure that we can’t possibly offer to you. We know we have a 2022 negative cashflow situation. This is causing a considerable issue. We have passed your message to senior management who will consider your request.

29.06.2022 19:08:26 UTC
Avatar

We have spoken with the senior management. They have confirmed what we thought and told you earlier. The business has a negative cashflow situation at the end of this financial year in two weeks' time that is causing real difficulties. You can read our 2022 interim results announcement and confirm this fact for yourselves: http://www.genusplc.com/media/1991/interim-report-1h22-final.pdf. We had a cash outflow of £16.1M in the first half of our financial year and the second half has been equally challenging as the business focuses on conserving cash. This cyber-attack could not have come at a worse time for us as you can see from the market report we have linked to. We do want to work with you to reach a solution. Is there anything you can do?

29.06.2022 19:08:37 UTC

you had an oppotunity to secure your network at a better time then. misfortune never comes alone. price is $5M.

29.06.2022 19:08:45 UTC
Avatar
Avatar

Thank you for your response, we are taking this very seriously. There are a number of important considerations that we need to undertake as a public company, as I'm sure you can appreciate. What reassurances do we have that making a payment to you is not unlawful?

29.06.2022 19:08:53 UTC

We are receiving payments from companies including public ones almost every day. Everything went good with all of them.

29.06.2022 19:08:57 UTC
Avatar
Avatar

Thank you for your response, and to confirm, we remain committed to resolving this situation with you. As a public company we need to ensure that our operating protocols are followed, therefore please confirm the file listing of data you have taken from us in order that we can proceed.

29.06.2022 19:09:05 UTC

hi. ok. we send data listing after payment. these are the terms.

29.06.2022 19:09:12 UTC
Avatar
Avatar

Thank you for your response. In order for us to justify making a payment to you, which will benefit us both, we need to justify this action to our company stakeholders. We understand that it is normal practice for companies in our situation to be provided with details of the files in your possession. Once you have given us this, we will pick a file of our choosing for you to prove that you have the data concerned. When we have completed these steps we can move forward towards a resolution with you.

29.06.2022 19:09:18 UTC

hi! we do not provide a list of data without payment

29.06.2022 19:09:25 UTC
Avatar

u must pay. or u will soon have the ability too see files on blog as countdown ends.

29.06.2022 19:09:28 UTC
Avatar
Avatar

We have demonstrated throughout our conversations with you that we are absolutely committed to resolving this situation with you, both to your benefit and ours. However, how can we do this when you have not provided proof of possession of our data?

29.06.2022 19:09:31 UTC

the best we can afford is to send you partial list of files.

29.06.2022 19:09:36 UTC
Avatar

https://temp.sh/XcaBs/genus.7z 2568256782468248428245724582452457245

29.06.2022 19:09:39 UTC
Avatar

very small part

29.06.2022 19:09:43 UTC
Avatar
Avatar

Thank you for your response and update regarding the partial data reveal. Clearly it is within your interests to share as much detail as possible on files that you hold so we can value the information accordingly and reach a suitable settlement with you that we are both in agreement with. The partial data that you have now provided will be categorised by our IT team in the morning on their return to work. We will update you as soon as this process has taken place.

29.06.2022 19:09:48 UTC

You will get complete file tree after payment. As we have told before these are the terms of the deal. If you want to review the file tree for free - wait until your data is published.

29.06.2022 19:10:00 UTC
Avatar
Avatar

Thank you for your response which we will respond to shortly. Please note that we remain fully committed to resolving the situation with you to the benefit of us both.

29.06.2022 19:10:04 UTC

https://temp.sh/LJPJj/genus_part2.7z

29.06.2022 19:10:15 UTC
Avatar

password 71366489127846894278

29.06.2022 19:10:19 UTC
Avatar
Avatar

Thank you for your response and the additional link to our data currently in your possession. We can confirm that we will be making a payment to you and therefore to proceed, please verify the following points: - You have now revealed all of our data file trees currently in your possession, there is nothing else that you have not shown us? - On payment you will destroy all of our data immediately? - You will not attack our organisation again in the future?

29.06.2022 19:10:22 UTC

We can confirm we have now revealed all of your data, your data will be destroyed right after you make a payment of $5,000,000 to our cryptowallet, we will never attack you anywhere in the future.

29.06.2022 19:10:28 UTC
Avatar

Are you going to pay? We've been waiting.

11.07.2022 14:44:36 UTC
Avatar
Avatar

Thank you for your response. We have now assessed the value of our data that you hold and are willing to make a payment of USD 105,000 based on our previously agreed conditions with you; On payment you will destroy all of our data immediately and confirm that this has taken place; You will not attack our organisation again in the future. Please confirm how we should make the payment.

12.07.2022 07:19:37 UTC

Though the amount you have offered is far away from our demanded amount, we can provide you a 25% discount as a goodwill gesture. 3750000$ for tool and data. BTC wallet for payment: bc1qh98g7cu0wnrf7awuqyjjs8uzc0sx7knp4d78kj.

12.07.2022 09:23:09 UTC
Avatar
Avatar

Thank you for your response and updated request. Our offer is based accurately on the value of the data that you hold, which has been calculated after meticulous review by us. Please note that we do not require decryption keys from you either. We have been committed to dialogue with you, and have remained open and transparent throughout our conversations, therefore as a sign of good faith and good will gesture, we are prepared to make a very generous offer of USD 155,000 which is significantly beyond the value of the information you hold. We trust that this will conclude our business today in agreement.

12.07.2022 15:05:02 UTC

It doesn't work this way. We will not accept 155,000. Your data will be posted if you do not pay within 24 hours.

12.07.2022 17:02:50 UTC
Avatar
Avatar

Hello. We have considered our position very carefully and have fully assessed the limited value of the data that you hold. Whilst we would prefer that you do not make our information publicly available, we have prepared for this eventuality should you choose this route. As it is not in either of our interests for our information to be made public, we are prepared to make a final settlement offer of USD 200k to reach agreement today, based on you not publishing any of our data and agreeing to destroy it immediately after payment. This figure is extremely generous and is a win-win scenario for both of us. Your money is ready now. Please advise how you wish to proceed?

13.07.2022 15:54:44 UTC

There's a difference between us in how we estimate value of information and cost of our postpaid pentest service. The price is far bigger than your offered amount. However we offer a final discount if you pay us today. Final price is $3,3kk.

13.07.2022 16:12:44 UTC
Avatar

http://lockbitapt2d73krlbewgv27tquljgxr33xbwwsp6rkyieto7u4ncead.onion/post/UH9CN38uu4tIdmMe62d0116b7c5f8

14.07.2022 12:57:54 UTC
Avatar

This information is provided by Valéry Marchive & Julien Mousqueton