Cybersecurity Videos
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityVideosWhy This Organization Refused to Pay the Ransomware Demands - UNH
HealthTechHealthcareCybersecurity

Why This Organization Refused to Pay the Ransomware Demands - UNH

•February 24, 2026
0
This Week Health
This Week Health•Feb 24, 2026

Why It Matters

It shows that disciplined negotiation and data‑sensitivity assessment can prevent wasteful ransom payments, shaping how organizations respond to ransomware threats.

Key Takeaways

  • •Negotiators extended talks to buy time for assessment.
  • •Ransom demand rose from 1.25M to inflated data claims.
  • •Actual exfiltrated data was only 2.5 GB, not 380 GB.
  • •Leadership decided against payment after evaluating data sensitivity.
  • •Decision saved $1.25M but risk varies by organization.

Summary

The video recounts how a university‑level organization chose not to pay a $1.25 million ransomware ransom after a protracted negotiation with the LockBit gang. Executives, including the president, CFO, and legal counsel, weighed the threat, the alleged data volume, and the potential impact before reaching a consensus to refuse payment.

Negotiators deliberately prolonged discussions, extracting file‑path listings and demanding proof of the claimed 75 GB of stolen data. The attackers later inflated the figure to roughly 380 GB, but the organization’s analysts could not locate such data in their systems. By the deadline, the gang released only about 2.5 GB, revealing that the earlier claims were largely bluff.

Key moments include the team’s assessment that the exposed files likely contained limited FERPA information and no HIPAA‑protected data, and the internal debate among senior leaders and outside counsel. The decision hinged on the low sensitivity of the data versus the steep ransom, ultimately saving the institution a million‑plus dollars.

The case underscores the value of thorough forensic analysis, strategic negotiation, and cross‑functional leadership in ransomware incidents. While this organization avoided a costly payout, the outcome highlights that each breach must be evaluated on its own data‑sensitivity and risk profile, informing broader cyber‑risk management strategies.

Original Description

Watch the full episode - UnHack the Podcast Inside a Real LockBit Attack - Lessons From Fighting Ransomware with Zach Lewis: https://youtu.be/oEF27aMm16g
Linkedin: https://www.linkedin.com/company/ThisWeekHealth
Twitter: https://twitter.com/thisweekhealth
Donate: Alex’s Lemonade Stand: Foundation for Childhood Cancer - https://www.alexslemonade.org/mypage/3173454
0

Comments

Want to join the conversation?

Loading comments...