"You Paid Them, Not Us": The Second Ransom for the Same Stolen Data

"You Paid Them, Not Us": The Second Ransom for the Same Stolen Data

When a ransomware negotiation does end in payment, the closing messages follow a ritual. The attacker confirms the transaction, delivers the decryptor, and makes a promise: the stolen data has been deleted. A short video of files being wiped, a screenshot of an empty folder, sometimes just a one-line assurance. The chat closes, and everyone involved agrees to believe it.

This transcript is about what happens seven months later, when a different group opens a new chat with the same victim, and the first file they share as proof of access is one the victim already paid to have destroyed.


The Opening: A Familiar File

The victim, a regional healthcare billing company, had been through this before. The previous spring, they were hit by a well-known ransomware operation, negotiated a $400,000 payment down from $1.1 million, and received the full package: decryptor, deletion video, even a closing message wishing them "good luck with your security."

This time there is no encryption, no ransom note, no locked systems. The contact arrives as an email sent directly to the CFO and two board members; a short message with a link to a chat and an attachment. The first message in that chat wastes no time:

"Hello. We are in possession of 380 GB of your patient billing records, SSNs, insurance claims. Sample attached. Price for deletion: $600,000. You have paid for this data before. You know it is worth it."

The attached sample was a spreadsheet of claims data; one the incident response team recognized immediately, because it had appeared in the first group's proof pack seven months earlier. Same file, same hash.

The victim's negotiator opens with the obvious objection:

"We already paid for the deletion of this data. We have the confirmation and the video. If you obtained it from [the first group], your quarrel is with them, not us. We will not pay twice for the same files."

The reply is the line this post takes its title from:

"You paid them. You did not pay us. The video shows a folder being deleted. It does not show every copy being deleted. Data is not a hostage you can buy back. It is a product, and products get resold."

The Middle: Negotiating Against a Copy

What makes this negotiation structurally different from every other one in this series is that the victim has already recovered. Systems are running. Backups were rebuilt after the first incident. There is no decryptor to buy, no downtime bleeding money by the hour. The only thing for sale is silence, and silence is the one product the seller can sell an unlimited number of times.

The negotiator makes exactly this argument, and it is the strongest message in the transcript:

"Understand our position. If we pay you, we have no reason to believe a third group will not appear next year with the same spreadsheet. Payment does not close this risk. It advertises that we pay. The only rational move for us is to treat this data as permanently public and act accordingly."

This reframing matters. In a first-time extortion, the victim is buying an outcome: systems back, data suppressed, incident contained. In a re-extortion, the victim is being asked to buy a promise from a stranger about an asset that has already demonstrably escaped containment once. The negotiator's message converts that logic into leverage: we are not refusing out of poverty; we are refusing because your product is defective.

The attacker's counter is telling. Rather than defending the value of the deletion promise, they pivot immediately to regulatory pain:

"Fine. Do not pay for deletion. Pay so that we do not send this to HHS, to journalists, and to every patient in the file. You know what a notification event costs. $600k is a discount on your lawyers alone."

The threat is real, but it contains an admission the negotiator does not miss: the attacker has stopped selling deletion and started selling delay. And a delay of a breach the victim already knew about; and had already partially disclosed after the first incident; is worth far less than the attacker thinks.


The End: The Cheapest Settlement in This Series

The victim's final position is short:

"The data you hold was compromised in an incident we disclosed in [month]. Our regulator has the incident report. Our affected patients were notified. You are threatening to publish something we have already admitted. Our answer is no. This channel will not be monitored after today."

Then they leave. No counter-offer, no staged concessions, no final deadline drama. The attacker sends three more messages over the following week; a price drop to $300,000, then $150,000, then a bare "last chance"; each one to an empty room.

The data was eventually posted to a leak site. According to the case notes accompanying the transcript, the operational impact was minimal: the notifications had gone out months earlier, the regulator was already engaged, and the leak generated a single trade-press article that focused mostly on the re-extortion attempt itself.

Total amount paid the second time: zero.


What This Transcript Teaches

Deletion promises are theater, and this is the proof. The deletion video from the first group was, by every visible measure, convincing. The data survived anyway; sold, shared, or stolen from the original thieves. Every payment for deletion should be understood as buying a delay, not an outcome.

Disclosure is a firewall against re-extortion. The single biggest reason this victim could walk away was that the first incident had been properly disclosed. Regulators knew, patients knew, and the second group was left trying to sell the suppression of a story that had already run. Victims who quietly pay and bury the first incident are the ones with everything to lose the second time.

Paying twice prices you as a repeat customer. The negotiator's argument; that payment advertises willingness to pay; is borne out across the broader ecosystem. Re-extortion targets are not chosen at random. They are chosen from ledgers.

Recovery changes the entire negotiation. With no encryption and no downtime, the attacker's only lever was reputational and regulatory harm; a lever that weakens dramatically once the harm is already public. The strongest position in any extortion is having nothing left to protect.

The first negotiation in this story cost $400,000 and ended with a promise. The second cost nothing and ended with the truth: stolen data does not come back, no matter who you pay or how sincere the deletion video looks. The victims who internalize that early; who disclose, notify, and treat exfiltrated data as permanently gone; are the ones who get to say no when the second chat window opens. And there is, increasingly often, a second chat window.