What is a ransom note?¶
The practical answer¶
A ransom note is a communication demanding payment or another concession in connection with disruption, encryption, theft or threatened disclosure.
The key evidential caution¶
The dangerous assumption is that the note identifies the offender or proves every claim it contains.
It does not.
A ransom note may include:
Key points¶
- payment instructions
- contact details
- deadlines
- claims of encryption
- claims of data theft
- threats to publish
- technical instructions
- a group name
- a victim identifier
- links to communication services
Evidence to preserve¶
Investigators should preserve:
Key points¶
- the original file or message
- filename and path
- timestamps
- file hash
- content
- contact addresses
- payment details
- victim or case identifiers
- language and formatting
- where and how it appeared
Evidential limits¶
Do not resave or reformat the note unnecessarily.
A screenshot may preserve appearance but omit metadata.
The note may have been created automatically by malware, manually placed by an operator or copied from another campaign.
The group name or branding may be accurate, imitated or deliberately false.
Payment addresses and contact accounts may provide investigative leads, but they do not automatically identify the person controlling them.
The note can help establish extortion, timing, method and claimed impact.
It cannot alone prove that files were encrypted, data was stolen or the named group was responsible.
Also preserve any victim-specific identifier in the note. It may link the note to a negotiation portal, decryptor or server-side record. Do not publish or reuse live contact details unnecessarily, because interaction can alter infrastructure or alert the offender.
Operational takeaway¶
Preserve the ransom note as original evidence of the demand, but verify its technical claims, payment details and claimed attribution independently.