Ransomware negotiation(s) with  lockbit3



Avatar

[Chat started]

25.07.2022 00:47:51 UTC
Avatar

We got your note. Can we chat?

25.07.2022 00:52:51 UTC

yes

25.07.2022 06:34:59 UTC
Avatar

The price of the decryptor and deletion of your data is $1,000,000 in bitcoins. 285gb of data was stolen. At the moment we haven't published your name to the blog to keep the attack secret, but if you don't pay we will fix it! We know who you are and how much you earn.

25.07.2022 07:14:09 UTC
Avatar

Soon we will send you a tree of stolen data

25.07.2022 07:14:24 UTC
Avatar

https://www.sendspace.com/filegroup/D3EEdan6%2FdiyCXs%2FnsDKr36E%2Bln%2B7ZqLrVELTtZeNCoC4nKryX7M8RCdOtsKYSYu

25.07.2022 11:14:25 UTC
Avatar
Avatar

Are you kidding me?!?! That's a crazy amount of money. What is the 285GB of data? Can you send it to me so I can review?

25.07.2022 13:48:30 UTC

No, we're not laughing. Here you can download the stolen data tree. And screenshots of files and folders

25.07.2022 13:58:11 UTC
Avatar

Looked?

25.07.2022 16:13:09 UTC
Avatar
Avatar

we have the list and we are looking, we will have an answer soon.

26.07.2022 13:24:59 UTC

What list are we talking about?! Hurry up! When will you pay??

26.07.2022 13:26:49 UTC
Avatar

If within 24 hours you do not clarify the negotiations, we will post about your company on our blog! And the attack will no longer be secret

26.07.2022 13:28:25 UTC
Avatar
Avatar

We're referring to the data tree and screenshots you sent us. Please have some patience here. There are a lot of moving parts right now and we need time to review, assess and bring our board up to speed on these matters. Please do not post us anywhere. We have a meeting coming up and your questions will be addressed soon.

27.07.2022 14:32:29 UTC

How long will it take you?

27.07.2022 15:23:55 UTC
Avatar

We'll wait until the end of this week. If there is no progress in the negotiations, we will make a post about the attack

27.07.2022 15:26:40 UTC
Avatar

???

28.07.2022 18:15:42 UTC
Avatar
Avatar

Progress is being made. This is not something we encounter everyday and are just making sure we are doing our due diligence. Please have patience. We likely wont be able to reach any agreements with you if you make a post about the attack.

28.07.2022 20:13:45 UTC
Avatar

Please show us the following files from the list you sent us

28.07.2022 20:16:17 UTC

You have to be more precise! We will not wait for you indefinitely. Since you yourself do not talk about deadlines, we have announced deadlines, and you must meet them! You have time until the end of this week. If there is no clear information on Monday, the post will be published!

28.07.2022 20:16:31 UTC
Avatar
Avatar

Budget$\2020.12.09 - Athletic Discount and Profitability Analysis by CFO Dave McConnell.pdf.....HResources\Faculty Sabbatical Tracking Sheet.xlsx.....HR-PayrollShare\Payroll Metrics_Planning 2021.xlsx.....Security\Supervisors\City Mutual Aid Agreement\OCU-OCPD Memo.pdf.....General Counsel\2019 Series Bonds\2021 S&P Ratings Call\S&P\Executive Committee Update 8-24-21.docx..... busoffice\Audit\2020-2021\000-FY2021 Audit Folder\Financial Stmts\OCU_21 FS_Final.pdf

28.07.2022 20:16:56 UTC

OK. Now let's send!

28.07.2022 20:17:15 UTC
Avatar

https://www.sendspace.com/file/u288dg

28.07.2022 20:25:24 UTC
Avatar

Looked?

29.07.2022 12:17:53 UTC
Avatar
Avatar

Yes we have looked. We were skeptical at first but we now see that you have what you say you do. We want to meet to discuss, however, two of our senior members are on personal leaves of absence today. We will have our meeting Monday morning to catch them up and will contact you afterwards.

29.07.2022 15:46:11 UTC

If you bring clarity to the negotiations on Monday, we will act more radically!

29.07.2022 21:27:45 UTC
Avatar

Time is running out. What did you decide?!

01.08.2022 09:06:24 UTC
Avatar

When will you pay?

01.08.2022 16:28:48 UTC
Avatar
Avatar

How are we suppose to get $1M? That isn't a fair amount here, it's not reasonable on our end. Our revenue doesn't reflect the amount of cash we have access to. Can you go to your boss and see if their is a discount?

01.08.2022 22:18:19 UTC

I'm the boss. Pay! The price is not determined by chance, we have deliberately approved the redemption amount, and it is not discussed.

01.08.2022 23:33:22 UTC
Avatar

You ask us for a discount, but don't tell us how much you're willing to pay. Maybe we're talking about different amounts.

02.08.2022 14:52:50 UTC
Avatar
Avatar

We don't want this to take a long time. But we don't have that much money. We need a better price and then we can get this done.

02.08.2022 17:39:21 UTC

Offer your price

02.08.2022 18:11:11 UTC
Avatar

???

03.08.2022 20:03:20 UTC
Avatar
Avatar

We have been dealing with so much over here and are a little short-staffed right now. We went to the bank with your $1M demand and they pretty much laughed in our faces. They want us to come back on Monday with a lower number. We haven't offered anything because we truly don't know how much we can get in total. What is the biggest discount you can give us based on that and what we have said to you in the past? You seem to be in a rush here so let's please help each other.

03.08.2022 21:51:55 UTC

There is no minimum and maximum discount. Start with how much money you're willing to pay! If our negotiations drag on, we will speed them up with the publication of a post about the attack.

03.08.2022 21:57:14 UTC
Avatar

And if you're also inactively carrying out negotiations, we can also speed them up by publishing them! Or doubling the price! Don't play games with us, we don't like it

03.08.2022 21:58:44 UTC
Avatar

It's in your best interest to bring active negotiations and prevent publication in the first place! So far, you're doing the opposite.

03.08.2022 22:00:58 UTC
Avatar

If payment is not received by the end of the week, we will publish a post on our blog!

04.08.2022 01:05:07 UTC
Avatar
Avatar

By the end of the week is when you want payment?! Based on how this is going no payment will be made if you publish our data tomorrow. The board has decided, as a whole, that we won't be paying anything if our name ends up on your blog. We've been working with you this whole time to make some progress so let's please not start making threats. At the top of the chat, it says we still have 16 days left. Please work with us not against us here.

04.08.2022 18:47:27 UTC

Throughout the negotiations, we did not come to anything! A post will be published tomorrow as a timer, not the data. You negotiate for a very long time and not productively. You don't even try to negotiate a price, and you don't pay the price of the descript and deletion of the data! Speaking of the date at the top of the chat, after 16 days your decryptor will be deleted and you will never decrypt your data. And the stolen data will also be published! Keep in mind, these aren't just threats, we're keeping our promises.

04.08.2022 19:52:29 UTC
Avatar

When will you pay?

04.08.2022 22:40:23 UTC
Avatar
Avatar

We're waiting to hear from the bank, we're hoping they will be able to help us out here. Please remain calm, we want this over with as much as you do. I'm not sure what they will think of all this. So please, do not publish anything, not even our name tomorrow or else my boss won't want to pay anything. We need to see what the bank says about a loan as we don't have anything close to your demand on hand. If it were up to me you'd already have your money, but there are other factors in play here. It's not just a one man operation, similar to yours. We will give you an update after we hear from the bank. We're hoping they will give us an answer Monday. I'm sorry but not all the decisions are up to me.

05.08.2022 18:05:35 UTC

ok

05.08.2022 18:19:56 UTC
Avatar

Ok, we'll wait until Monday.

05.08.2022 20:43:23 UTC
Avatar

???

08.08.2022 22:12:51 UTC
Avatar

If today we do not hear from you a profitable offer - we will reveal the attack

09.08.2022 10:05:23 UTC
Avatar
Avatar

Hello, sorry for the delay. We got some responses and our meeting is happening tonight. We will be able to get you an decent offer tomorrow, so please keep an eye out for our response then.

09.08.2022 20:52:29 UTC

OK. If this does not happen, the post will be published

09.08.2022 20:59:54 UTC
Avatar

Please pay attention to the date above the chat. On this day, your decryptor will be deleted and data recovery will be impossible!

10.08.2022 11:54:05 UTC
Avatar
Avatar

We are here. We apologize for not giving you an update yesterday but we already short staffed and could not make to the chat. Please do not reveal anything related to the attack to the public. We're working and juggling a lot to get everyone to get on board with a payment here. It has been tough for us to scramble funds together, but at this moment we have $25k on hand that we can send your way. Unfortunately the bank never got back to us about a loan amount, so we're still waiting to see if they will give us any amount. They aren't too happy about sending money to hackers. Is this something you would make a profit from? How much does it cost you to hack a company?

10.08.2022 15:57:55 UTC

Do you seriously think that this is a decent amount? Is your data worth 25k? Our patience snapped. Wait for the blog post!

10.08.2022 18:07:33 UTC
Avatar
Avatar

$25K is what we have right now. We're just letting you know and trying to be transparent with you. Can you come down on your demand at all? This would help me convince some people to try and get more money. It would also show everyone that you're willing to work with us. We're not trying to upset you here, that's not our intention. Any post about us and we won't get approval to pay any amount so let's please work together.

10.08.2022 18:24:16 UTC

We have already listened enough to your empty words. Post published

10.08.2022 18:32:18 UTC
Avatar

Why do you go to the chat? You said you wouldn't pay if the post ended up on a blog. So what is the purpose of the visit?

12.08.2022 17:46:25 UTC
Avatar

?

15.08.2022 16:40:10 UTC
Avatar

Have you looked at the stolen data?

22.08.2022 11:23:34 UTC
Avatar

This information is provided by Valéry Marchive