/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

[Thread] A look at the correspondence between a hacked US travel management firm, CWT, and the ransomware attackers, who were paid $4.5M in BTC to decrypt files

Jack Stubbs / @jc_stubbs : Tweets: @jc_stubbs , @jc_stubbs , @codybrown , and @jc_stubbs Tweets: Jack Stubbs / @jc_stubbs : After the ransom was paid, the attackers even provided some bonus security advice! https://twitter.com/... Jack Stubbs / @jc_stubbs : But the online chat room where the ransom negotiations took place was left online, giving a rare and *incredibly* interesting insight into how these things actually go down https://twitter.com/... Codyb / @codybrown : this is amazing. if you've ever wondered how a ransomware hacking negotiation really goes down, here are the screenshots https://twitter.com/... Jack Stubbs / @jc_stubbs : Personally I was surprised at how professional and collegial the whole conversation was. From beginning to end, this was treated a business transaction for both parties https://twitter.com/...

@jc_stubbs Jack Stubbs

Context & Ripple Effects

In 2020, security journalist Jack Stubbs surfaced screenshots from an online chatroom that ransomware attackers left accessible after extorting travel management firm CWT — a rare primary-source record of how a corporate ransom settlement is actually negotiated, down to CWT paying $4.5M in bitcoin for decryption and even receiving unsolicited 'bonus security advice.'

That leak seeded a whole research thread: a researcher later tricked operators into exposing their payout and cash-out schemes, and by 2021 ransomware negotiation had become a profession in its own right. What made this document valuable was that it showed extortion functioning as a priced, bargained commercial exchange rather than an opaque crime.

First-order effects

  • CWT regained access to its files after paying $4.5M in BTC, while the exposed chat simultaneously gave the security community an unfiltered transcript of attacker tactics, tone, and pricing behavior.

Second-order effects

  • The visibility of real negotiation dynamics helped professionalize the response side — specialists like Kurtis Minder now manage these discussions for victim companies as a distinct service layer between firms and gangs.
  • Every published transcript becomes price intelligence: victims and their negotiators can anchor against documented settlements instead of negotiating blind.

Third-order effects

  • The pattern points toward ransomware consolidating into a structured underground economy with intermediaries on both sides — and with investigators following the money, as when US tracing tied payments to companies in Moscow's Federation Tower East, pressuring the state tolerance that shelters operators.
  • As gangs industrialize, their own operational slips — a left-open chatroom here, an alleged BlackCat exit scam after a major payment there — become the main windows regulators and researchers have into the market's internals.

The trend: Ransomware is maturing from opportunistic extortion into a negotiated, intermediated commercial market whose economics researchers and investigators are progressively mapping.

Discussion

  • @jc_stubbs Jack Stubbs on x
    After the ransom was paid, the attackers even provided some bonus security advice! https://twitter.com/...
  • @jc_stubbs Jack Stubbs on x
    But the online chat room where the ransom negotiations took place was left online, giving a rare and *incredibly* interesting insight into how these things actually go down https://twitter.com/...
  • @codybrown Codyb on x
    this is amazing. if you've ever wondered how a ransomware hacking negotiation really goes down, here are the screenshots https://twitter.com/...
  • @jc_stubbs Jack Stubbs on x
    Personally I was surprised at how professional and collegial the whole conversation was. From beginning to end, this was treated a business transaction for both parties https://twitter.com/...