Awareness

Ransomware Notes: Samples, Structure, and What They Reveal

Published  ·  13 min read

Ransomware Note

You come back to your desk, and every screen shows the same message, a black window with red text telling you that your files are encrypted and that you have seventy two hours to pay, and in that moment you are reading a document that was written specifically to make you panic.

Ransom notes are the primary communication channel between attackers and victims, and while every group has its own style, almost all of them follow the same structural pattern, because the pattern works, and because the people writing these notes are not artists, they are operators optimizing for payment rates.

Understanding what a ransom note contains, and why it contains it, is genuinely useful, because it tells you what the attacker wants you to believe, which is often different from what is actually true.

Important Disclaimer

This article is intended for educational and defensive purposes only, and the information shared here is meant to help security professionals and incident responders understand ransomware communication so they can respond more effectively.

The author assumes no liability for any damages, legal consequences, or other outcomes resulting from the use or misuse of this information, so always engage legal counsel and law enforcement before taking any action during a ransomware incident, and stay legal, stay ethical, stay responsible.

The Anatomy of a Ransom Note

Almost every ransom note, regardless of which group wrote it, contains the same six elements in roughly the same order, because each element addresses a specific question the victim will ask.

Element 1: Notification

The note begins by telling you what happened, usually in blunt terms.

Typical phrasing includes lines like your files have been encrypted, your network has been compromised, or all your important documents are now inaccessible, and the purpose is to remove any ambiguity about the situation.

This element is also where the group names itself, because branding matters in this economy, and a recognizable name carries more weight than an anonymous demand.

Element 2: The Demand

Now comes the demand, which consists of a particular amount of cryptocurrency and may also contain a note on how your price increases due to a delay in payment.

Typical phrasing includes lines like the price to recover your data is a specific figure in Bitcoin or Monero, and a warning that the amount doubles after the deadline.

The purpose here is to anchor your expectations and to make the first number feel like the cheapest option you will ever be offered.

Element 3: Payment Details

This is the section of instructions on how to pay for cryptocurrency, where the payment should be made, and how to show that the payment has been made.

Typical phrasing includes numbered steps, a wallet address, and instructions to contact a specific email or Telegram handle with proof of payment.

The purpose is to remove any friction between you and paying, because every additional step is an opportunity for you to reconsider.

Element 4: Threats

This is where the pressure comes from, and it is where modern notes differ most from older ones.

Older notes threatened only permanent data loss, and modern notes threaten publication, notification of customers, regulatory reporting, and sometimes direct contact with your clients or partners.

Typical phrasing includes lines like your data will be published on our leak site, we will notify your customers and regulators, or your competitors will receive your internal documents.

Element 5: Proof of Capability

Many notes include an offer to decrypt a small number of files for free, which serves as proof that the attackers possess the decryption key.

Typical phrasing includes lines like you may send us two small files and we will decrypt them at no cost to demonstrate that we can recover your data.

The purpose is to overcome the victim's skepticism, because if you believe the attacker cannot actually decrypt, you have no reason to pay.

Element 6: Unique Identifier

Finally, the note includes a unique string that identifies your specific infection.

Typical phrasing includes a label like your personal decryption ID followed by a long alphanumeric string, which also often appears as the file extension added to your encrypted files.

The purpose is operational, because the attackers run many infections simultaneously, and the identifier ensures they know which victim they are talking to.

Original Ransom Note Examples

The following examples are written to illustrate common patterns, and they are not reproductions of any specific group's actual note.

Example 1: The Direct Note

This style is short, blunt, and assumes the victim already understands what has happened.

Your files have been encrypted.

Every document, spreadsheet, database, and backup on this network is now inaccessible.

To recover your data, send 15,000 USD in Bitcoin to the address below.

After 72 hours, the price increases to 30,000 USD.

After 7 days, your decryption key is destroyed permanently.

We have also copied your files. If you do not pay, we will publish them on our leak site and notify your customers.

To prove we can decrypt, send us two small files and we will return them decrypted at no cost.

Your victim ID: A7K9-2MX4-88QP

Contact: recovery-team@example-domain.com

What this note tells you. The attackers are optimizing for speed, they expect you to pay quickly, and they are not interested in a long negotiation, which is also why the deadline is short and the price increase is steep.

Example 2: The Reassuring Note

This style tries to position the attacker as a professional service provider, and it is designed to overcome the moral hesitation some victims feel.

Hello.

Your network has been encrypted by our team.

We are not criminals in the traditional sense, we are a professional group that provides a service, and we honor every agreement we make.

If you pay, you will receive working decryption software, and your stolen data will be deleted from our servers.

We keep our word because our reputation is the foundation of our business, and we have hundreds of satisfied clients who can confirm this.

The price for full recovery is 25,000 USD in Monero.

You may send us three files for free decryption so you can verify our capability before paying.

Our negotiators are available at the contact address below, and we are open to discussing a payment plan if needed.

Your case reference: HC-4417-XM

Contact: negotiations@example-domain.com

What this note tells you. The victims targeted by the attackers would likely reject them otherwise, and the assurance is just a sales technique and not a guarantee, since there is no way of enforcing the promise to delete the stolen data.

Example 3: The Data-First Note

This style leads with the data theft rather than the encryption, which reflects the shift toward extortion based on publication rather than decryption.

We have your data.

Before encrypting your systems, we copied 340 gigabytes of your internal documents, customer records, and financial files.

Encryption is a secondary concern for us, and we are happy to leave your systems encrypted if that is your preference.

What matters is that your data does not become public.

If you do not pay, we will publish everything on our leak site, notify every customer in the database, and contact your regulators with a full report.

The price is 40,000 USD, and it is non-negotiable.

You have 96 hours.

Your reference: DX-9912-KL

Contact: data-team@example-domain.com

What this note tells you. The attackers believe the data is more valuable than the decryption key, and they may not even bother providing a decryptor, because the leverage is publication, not encryption.

Example 4: The Aggressive Note

This style uses hostility and profanity to intimidate, and it is designed to make victims want the interaction to end as quickly as possible.

Listen carefully.

We have your files and your data, and we are not here to be polite.

Pay 20,000 USD in Bitcoin, or we publish everything and your business is finished.

Do not contact law enforcement, do not contact recovery companies, and do not waste our time with excuses.

We have done this hundreds of times and we always win.

You have 48 hours.

If you do not pay, your data goes public and your customers find out before you do.

Your ID: ZX-3344-PL

Contact: fast-pay@example-domain.com

What this note tells you. The aggression is a pressure tactic rather than a reflection of sophistication, and it often indicates a smaller or less experienced operation trying to compensate with volume.

Example 5: The Clinical Note

This style is impersonal and procedural, and it is often used by groups that treat ransomware as a pure business process.

Notice of data encryption and exfiltration.

Your organization has been affected by an unauthorized access event.

All files on affected systems have been encrypted using AES-256 and RSA-4096.

A full copy of your data has been exfiltrated prior to encryption.

Terms:

  • Payment amount: 30,000 USD in Monero
  • Deadline: 120 hours from the timestamp of this notice
  • Post-deadline amount: 60,000 USD
  • Post-deadline action: publication of exfiltrated data

Verification:

  • You may submit two files for free decryption

Identification:

  • Case number: QT-7788-MN

Communication:

  • Contact: case-7788@example-domain.com

What this note tells you. The clinical tone is intentional and designed to signal competence, because a victim who believes the attacker is organized is more likely to believe the threats are real.

The Psychology Behind the Structure

Ransom notes are not written casually, and every element is there to produce a specific response.

  • The presence of the deadline creates pressure, reducing the cognitive capacity of the victim, preventing consultation of experts and alternative approaches, and deadlines that do not give enough time for proper reaction to the message are intentional, rather than a mistake.
  • The rise in prices creates loss aversion, because the victim is now afraid of losses that result from postponing the payment compared to mere non-payment of the initial fee, making them more willing to pay.
  • The option of decryption for free creates credibility, providing a basis for the victim to be sure that the attacker can keep his word and almost not costing the attacker anything.
  • The wording regarding reputation makes the message trustworthy, transforming the criminal act into a transaction and giving the victim a right to pay without looking like a fool.
  • The threat of data leak creates a secondary battlefield, because the victim now has to think not only about operational downtime but also about regulation, notification of customers and loss of reputation.
  • The aggressiveness creates compliance, because hostile tone makes victims want to end the conversation and paying seems like the most efficient way to do it.

What Ransom Notes Get Wrong

Ransom notes are not always accurate, and treating them as a reliable description of the situation is a mistake.

  • The deadline is rarely enforced. Groups routinely extend deadlines, and they do so because extended negotiations produce higher payments than abandoned ones, so the deadline is a negotiating position rather than a hard limit.
  • The decryption promise is not guaranteed. Some groups have taken payment and never delivered a working decryptor, and even when they do deliver, the decryptor often fails on a percentage of files.
  • The data deletion promise is unverifiable. There is no way to confirm that stolen data has been deleted, and in several documented cases, groups have retained data after payment and attempted to resell it.
  • The price is negotiable. First demands are opening offers, and negotiation routinely reduces the amount, which is why security professionals recommend involving experienced negotiators rather than paying immediately.
  • The threats may be exaggerated. Not every group that claims to have exfiltrated data actually did, and not every group that claims a leak site actually operates one.

What to Do When You Find One

The note is the beginning of an incident response process, not the end of one.

  • Preserve the note. Take screenshots, copy the text, and record the file hash, because the note contains identifiers and contact details that matter for attribution and for any later legal process.
  • Don’t react immediately. Avoid responding to the contact point right away, because that will show that you’re panicking and won’t be good for negotiations.
  • Contact your incident response team and legal counsel. The decision to negotiate, pay, or refuse involves legal, regulatory, financial, and ethical considerations that are not yours to make alone.
  • Engage law enforcement. Reporting is often required, and in some jurisdictions, paying a sanctioned entity is illegal, so the legal review comes before any payment discussion.
  • Check your backups before assuming the worst. The note claims your backups are encrypted, and that claim is sometimes false, so verify your offline and immutable backups before concluding that recovery is impossible.
  • Do not pay based on the note alone. Verify what was actually taken, what is actually recoverable, and what your regulatory obligations are before making any decision about payment.

Quick Reference: Ransom Note Analysis Checklist

Element

What to Record

Group name

For attribution and known tactics

Contact details

Email, Telegram, Tox, or other channels

Victim ID

Matches file extensions and negotiation references

Deadline

Stated time limit and any escalation terms

Demand amount

Initial figure and currency

Threats

Publication, notification, regulatory reporting

Proof offer

Free decryption terms

Tone

Clinical, aggressive, reassuring, or transactional

The Bottom Line

Ransom notes are a carefully constructed communication tool, and every element exists for a reason, because the deadline creates panic, the price increase creates loss aversion, the free decryption offer creates credibility, and the reputation language creates permission to pay.

Reading one is not the same as believing one, and the most important thing to remember is that the note describes the attacker's preferred version of events rather than the actual situation, which means your first job is to verify, not to react.

Preserve the note, contact your team and your lawyers, check your backups, and remember that the deadline is a negotiating position rather than a countdown, because the groups that write these notes are running a business, and businesses negotiate.

FAQ Section

What is a ransom note?

It is the message attackers leave after encrypting a victim's systems, containing the demand, payment instructions, threats, and contact details for negotiation.

Do all ransomware groups use the same note format?

No, the tone and wording vary widely, but almost all notes include the same six elements, notification, demand, instructions, threats, proof of capability, and a unique identifier.

Should I reply to the contact address in the note?

Not immediately and not without guidance, because rapid engagement signals panic, and the decision to negotiate should involve legal counsel and incident response professionals.

Is the deadline in a ransom note legitimate?

Almost never, since groups frequently extend deadlines while negotiations continue, and the deadline is used as a leverage tool.

Will they actually remove the data they stole from me if I pay them?

No, since there is no means by which deletion can be confirmed, and at times, they have kept data despite receiving payment and tried selling it again.

What is the first thing I need to do after finding a ransom note?

Preserve it, contact your incident response team and legal counsel, check your backups, and avoid engaging with the attacker until you have a plan.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067