Skip to content
CIM-189 Cyber Incidents & Offender Methods

What evidence should be preserved from ransomware negotiations?

The practical answer

Ransomware negotiations may contain important evidence about demands, infrastructure, payment routes, victim identifiers and offender behaviour.

The key evidential caution

The dangerous assumption is that screenshots of the final demand are enough.

They may omit:

Key points

  • message IDs
  • account identifiers
  • timestamps
  • portal URLs
  • headers
  • attachments
  • file metadata
  • version history
  • payment addresses
  • technical files
  • the full conversation sequence

Evidence to preserve

Preserve:

Key points

  • all messages
  • original files
  • portal and account identifiers
  • contact addresses
  • victim or case codes
  • cryptocurrency addresses
  • deadlines
  • payment instructions
  • samples
  • decryptors
  • keys
  • proof files
  • screenshots showing appearance
  • native exports where available

Record who communicated, under what authority and from which device or account.

Evidential limits

Do not edit or reformat the negotiation record unnecessarily.

Where a portal is used, preserve its content promptly because access may be revoked or the service may disappear.

The offender may make false, exaggerated or contradictory claims.

Preserve them as evidence without adopting them as fact.

Negotiation behaviour may support intelligence or linkage, but it should not be used alone to identify a person or group.

Where a third-party negotiator is involved, preserve their native records, notes, portal exports and account identifiers as well as the organisation’s copies. A forwarded transcript may omit metadata or attachments. Record what representations were made on the organisation’s behalf and which statements came from the offender.

Preserve unsuccessful login attempts, expired links and deleted messages where available. They may show changes in infrastructure or account control during negotiation. If telephone, voice or messaging contact occurs alongside the portal, preserve those records as part of the same communication sequence.

Operational takeaway

Preserve the complete native negotiation record, including identifiers, files, payment details and authorisation, and verify every offender claim independently.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.