Inside Ransomware Negotiations: Trust Criminals or Walk Away?

Inside Ransomware Negotiations: Trust Criminals or Walk Away?

March 19, 2026 · 30 min · Season 9 · Episode 109

About this episode

Jeremy D. Brown discusses the intricacies of negotiating with ransomware gangs and shares critical insights for organizations facing such threats.

What happens when you're face-to-face with a ransomware gang demanding millions—and every decision could determine whether your company survives? Jeremy D. Brown, Consulting Director at Palo Alto Networks Unit 42 with nearly seven years negotiating with cyber criminals, reveals the hidden world of ransomware negotiations. With hundreds of negotiations under his belt, Jeremy knows which groups honor their promises, which ones to never pay, and exactly what mistakes can cost you everything. You'll learn: - Why contacting a threat actor doesn't mean you have to pay (the #1 misconception that paralyzes victims) - How to extract critical forensic intelligence from attackers during initial contact - The fatal mistakes organizations make that destroy their negotiation leverage - Which ransomware groups are sanctioned entities that will land you in legal trouble if you pay - Why being polite to criminals actually gets you better outcomes than hostility Jeremy has negotiated with everyone from aggressive groups who email your executives to methodical operators following strict playbooks. He's seen organizations with backups walk away and others pay millions for decryption keys. Managing…

More episodes of Threat Vector by Palo Alto Networks

Explore listener stats, chart rankings, contacts and more on the Threat Vector by Palo Alto Networks podcast page.