What evidence should be preserved from ransomware negotiations?¶
Preserve the complete native conversation and every identifier, file and payment route. Screenshots show appearance but often omit metadata and sequence.
Capture native records promptly¶
Retain messages, headers, IDs, portal URLs, accounts, victim codes, timestamps, contact details, cryptocurrency addresses, deadlines, attachments, samples, keys, decryptors and proof files. Export portal content before access expires and preserve screenshots as supplementary context.
Record who communicated, from which account and device, under what authority, and which representations were made for the organisation. If a third-party negotiator is used, obtain their native exports and notes rather than relying on forwarded transcripts.
Preserve changes and parallel channels¶
Deleted messages, failed logins, expired links and changed accounts may show infrastructure or control changes. Include voice, telephone and messaging records alongside the portal sequence.
Do not edit or reformat originals unnecessarily. Offender claims can be false or contradictory; retain them as statements and verify them separately. Negotiation style may support linkage but not personal identity alone.
Key takeaway
Preserve the full native negotiation, identifiers, files, authority and parallel communications, using screenshots only as supplements and treating every offender claim as unverified.