
Ransomware Negotiator Reveals Inside Details of Cybercrime Negotiations and Attack Methods
Girt is a ransomware negotiator who has handled over 600 cases in 10 years, working primarily with insurance companies whose clients have been victims of cyberattacks. He negotiates with cybercriminals through encrypted chat platforms or email, typically dealing with ransom demands ranging from 30,000 to 300,000 dollars for SMEs, with amounts above 500,000-600,000 dollars being very rare. Criminals typically exfiltrate between 50GB and 600GB of data, targeting contracts, Excel files with client lists, HR documents, and payroll information rather than entire databases. Before payment, Girt conducts a sanctions check to ensure the criminal group is not classified as a terrorist organization, as paying terrorists is illegal while paying criminals is not. The negotiation process has shortened from 10-14 days to 3-4 days due to changes in the initial access market, where access brokers now sell the same network access to multiple ransomware groups simultaneously, creating competition. Girt charges fixed fees between 3,000-20,000 euros depending on company size, paid by insurance companies, and never takes a percentage of the ransom amount. He revealed that the two main entry vectors are password stealers embedded in VPN software and zero-day vulnerabilities in firewalls, SSL VPNs, and Exchange servers, with phishing being less common than victims claim.