24/7 ransomware incident response - Dubai & United Arab Emirates +971 52 758 9336
Decision making

Why contacting the attackers is the weakest option

Paying is presented as the quick way out. The data from organisations that did pay says otherwise.

A-Lab briefing · 7 minute read · For owners, boards and counsel

When the ransom note appears, the negotiation portal is one click away and the clock is visibly counting down. The offer looks simple: pay and receive a decryptor. In practice, contacting the attackers converts a technical problem into a transaction with an anonymous criminal enterprise whose only leverage is your uncertainty. This briefing sets out what actually happens.

1. Paying is strongly associated with being attacked again

A survey of UAE organisations that suffered a ransomware attack found that around nine in ten of those who paid were hit a second time. Most of the second attacks came within a month, and in most cases the new demand was higher. The mechanism is simple: a paid victim is a proven buyer, the entry point that was used is often still open, and affiliate lists of paying companies are traded between groups.

2. The decryptor may not work, and often works badly

Attackers write encryptors, not recovery software. The decryptors they hand over are frequently slow, single-threaded, crash on large files and corrupt databases and virtual disks that were encrypted with intermittent modes. Incident responders routinely report that a paid-for decryptor recovers only part of the environment, and that the remaining data still needs laboratory reconstruction. Some groups simply never deliver: BlackCat's operators disappeared with a 22 million dollar payment in 2024, and Medusa victims have reported a second actor demanding payment again after the first.

3. Stolen data is leaked anyway

Three quarters of attacks now include data theft before encryption. Paying buys a promise to delete the copy. There is no way to verify that promise, and published cases show data from paying victims appearing on leak sites or being sold months later. If the data is the concern, the answer lies in legal, regulatory and communications handling, not in a payment.

4. Legal and regulatory exposure

Many ransomware groups are subject to international sanctions, and payment to a sanctioned entity can be an offence regardless of intent. Cyber insurers increasingly restrict or exclude ransom reimbursement. UAE regulators expect organisations to report incidents and to demonstrate that recovery options were assessed. A payment made under pressure, without that assessment, is difficult to defend afterwards.

5. Contact itself has a cost

Opening the negotiation portal tells the attackers that you are engaged. They learn your insurance coverage, your revenue, your urgency and who is speaking for you. Deadlines shorten, pressure tactics begin, and executives and customers may receive calls. None of that happens if you never open the portal.

The alternative: treat it as a forensic engineering problem

Ransomware is software with versions, bugs and known behaviours. The encryptor that hit you can be identified from the note and the samples. Its implementation can be analysed. Partial encryption leaves large parts of databases, backups and virtual disks untouched. Storage-level recovery restores what the malware deleted. In A-Lab's experience this approach returns usable data in the large majority of cases, and the client verifies the data before paying anything.

What we recommend. Before any decision about payment, obtain a recovery assessment. It is free, it takes hours, and it replaces the attackers' narrative with facts about what is actually recoverable.
A note on wording. A-Lab does not "negotiate" and does not act as an intermediary. We do not need to contact the attackers because our method does not depend on them.