Sources: in 2019, major labor union Teamsters refused a ransomware demand of $2.5M, against the FBI's advice, and instead rebuilt its systems from scratch
some of it from hard copies. Records mgmt ++ Jonathan Allen / @jonallendc : When the Teamsters called the FBI to report they were being extorted for $2.5 million in a ransomware attack, the FBI told the union to “just pay it,” sources said. https://www.nbcnews.com/... Jonathan Allen / @jonallendc : SCOOP: Teamsters were hit by ransomware attack in 2019. The FBI advised them to pay the $2.5M demand. Their insurance company said not to do it. Here's what happened. W/@kevincollier https://www.nbcnews.com/... John FitzGerald / @thetweetofjohn : The FBI advised the union to “just pay” the ransom, according to sources. Union officials chose to rebuild their computer network instead. https://www.nbcnews.com/... Charlie J. Johnson / @charliemagne : “Union officials in Washington were divided over whether to pay the ransom — going so far as to bargain the number down to $1.1 million” https://www.nbcnews.com/...
Context & Ripple Effects
This report lands amid a string of ransomware payment stories with mixed outcomes: CWT handed over $4.5M in BTC to unlock files, and Colonial paid ~$5M within hours only to find the hackers' decryption tool so slow it fell back on its own backups anyway. The Teamsters case is the counterfactual — a refusal, taken against FBI guidance, that still ended in recovery.
It also exposes a three-way split among the advisers victims actually call first: sources say the FBI told the union to 'just pay,' while its insurance company said not to. That echoes earlier reporting where intermediaries who promised hi-tech recovery were themselves just quietly paying attackers — as ProPublica found with two US data recovery firms in 2019 (link) — making the pay-or-rebuild decision one victims must make without a trusted referee.
First-order effects
- The Teamsters absorbed the cost of rebuilding its network from scratch — partly from hard copies — rather than transferring $2.5M, meaning its recovery timeline and expense were self-chosen rather than hostage to an attacker's decryptor.
- Victims now have visibly contradictory official guidance: the FBI's reported 'just pay it' advice puts it on the opposite side of the decision from the insurers who underwrite these events.
Second-order effects
- Colonial's experience strengthens the insurers' position: even after paying ~$5M, it had to restore from backups, so the marginal value of paying shrinks for any victim with usable backups — pricing leverage shifts toward cyber-insurance terms that penalize weak recovery posture.
- Attackers lose negotiating power against hardened targets like the Teamsters, pushing ransomware groups toward organizations they can assume lack offline backups — the pattern Baltimore's $10M-plus cleanup bill illustrates for underprepared public institutions.
Third-order effects
- If paying increasingly doesn't spare you the rebuild, ransomware defense structurally migrates from incident response to resilience — offline backups and records management become the real insurance, and payment becomes a last resort rather than a default.
- A gap between law enforcement's public anti-payment stance and agents' field advice invites formal policy reckoning — whether the government should standardize guidance or leave the call to insurers, whose financial exposure already makes them the de facto decision-makers.
The trend: Ransomware outcomes are splitting along a preparedness line — victims with real backups can refuse demands like the Teamsters did, while unprepared ones like Colonial pay and still rebuild — shifting the decision from negotiators to insurers.