Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What is a ransom note?

A ransom note is a communication demanding payment or another concession in connection with alleged encryption, disruption, theft or disclosure. It proves the demand and its claims, not their technical truth or the offender's identity.

Preserve the original communication

Retain the original file or message, path, filename, timestamps, hash, formatting, contact and payment details, deadlines, links and victim-specific identifiers. A screenshot preserves appearance but can omit metadata; avoid unnecessary resaving or reformatting.

The note may be generated automatically, placed manually or copied from another campaign. Branding and language can be genuine, imitated or deliberately false.

Use its identifiers as leads

Victim IDs may link to a negotiation portal, decryptor or server-side record. Payment addresses and contact accounts can support further investigation but do not identify their controller alone.

Verify encryption, data theft and claimed group responsibility using device, network, provider, communication and financial evidence. Avoid publishing or testing live contact details without a justified plan because interaction can alter infrastructure or alert an operator.

Key takeaway

Preserve the note in its original form as evidence of the demand, then verify every technical and attribution claim independently.

Reference: CIM-175Cyber Incidents & Offender Methods