A conversation with a 'chief ransomware negotiator'

Quick Take
- A few years ago Karen Sprenger stepped in to negotiate with a ransomware group that had attacked one her company’s clients. Since then she has been the company’s chief ransomware negotiator.
- What exactly does a ransomware negotiator do? The Block connected with Sprenger to find out.
We'd love your feedback.
Victims of ransomware — like the operators of the Colonial Pipeline, which recently suffered a high-profile attack — face a dilemma: to pay or not to pay?
The U.S. Federal Bureau of Investigation has recommended that victims refrain from paying the ransom to get their files back, because it may not guarantee ransomers return stolen data and may encourage more ransomware attacks.
But not every ransomware victim is in a position to do that. And since the business of dealing with ransomware groups can be tricky, some have turned to a relatively new kind of professional expert for help: a so-called ransomware negotiator.
What exactly does a ransomware negotiator do? What is it like doing business with faceless extortionists? And what does the general public tend to miss about the nature of ransomware attacks?
The Block spoke with the ransomware negotiator Karen Sprenger — who is also the Chief Operating Officer at the Montana-based cybersecurity firm LMG Security — to find out.
The conversation has been edited for readability.
What exactly is your role at LMG Security?
I am the COO, so I’m responsible for day-to-day operations. My informal title is Chief Ransomware Negotiator because I'm the primary person on any ransomware negotiations that we need to handle. I also am a certified forensic examiner and worked in forensics for quite some time.
How did you become a ransomware negotiator?
By accident. We had a client in 2016 that got infected with ransomware. All of their servers and backups were offline but not off-network. They needed to negotiate, but there was no one else to do it so I jumped in. I guess I had watched a lot of movies.
I can see a movie plot forming already. In reality, is the experience really such high drama?
For our clients, it's extremely high stakes and high drama. For many of them, this is one of the worst business days of their lives. But for the actual negotiation itself, most people would find it pretty boring.
It's an exchange of emails back and forth finding out what they want. We go through a process called "proof-of-life.” Before we start negotiating, we want to make sure the group we're speaking with has the ability to decrypt the files. So we come to an agreement to send them two or three innocuous files, have them decrypt those, then send it back. Once we have that proof, we'll start negotiating a price.
It's really just a lot of back and forth, making sure we understand what they're looking for, they understand what we're looking for, and trying to come to an agreement.
Why is a third-party ransomware negotiator necessary for this?
Part of the reason clients have us handle it as a third party is because they’re often very emotionally involved. This is their livelihood. It's difficult for them to do the negotiation in a way that treats it as a business deal.
And really that's what's needed — to say, “This is a business contract, just like any other contract.” It involves criminal activity, but beyond that, it's very similar to negotiating with a vendor. As long as you treat it like that, it can usually go fairly smoothly.
What can cause a ransomware negotiation to go sour?
It starts to go off the rails if you let emotion get involved. If you want to lecture them on their life choices or call them names, or disparage them in any way, then it's not going to go as well.
Besides establishing “proof-of-life” and keeping a level head, what else have you found useful when negotiating with ransomware groups?
Those are the main ones: Keep calm, ask for proof, treat it like a business, no name-calling.
I think the other thing would be that we're seeing a lot more emphasis on exposure extortion. They're saying, “We've stolen your data. If you don't pay us, we're going to publicly release it.” In those situations, it's important to ask for proof of that as well. Sometimes they'll send a screenshot of a directory on the server that's impacted. You want to ask for them to deliver files. It could be random files but something you'll recognize to prove they actually have the data because they could have taken a screenshot while accessing the server and infecting it with ransomware. So, it's all about getting proof.
We also need to clarify if the encryption key you're asking for will work for all of the files. Sometimes they'll encrypt files more than once or sometimes they'll use different keys, depending on how the encryption first took place.
In those instances, it's best to ask upfront, "Will the decryptor you're providing decrypt all of the files?" And also to ask, “How quickly can we expect to receive it?" If it’s going to be 48 hours, it's good to know that instead of sitting there and sweating. A lot of the so-called professional groups can now get it to you within 30 minutes, which is also good to know because then you can watch and be ready for it.
Of course, once the negotiations finish and you get the decrypter, always test it. There's a chance there’s more malware in the decrypter itself. Sometimes it's not even the group who is extorting you that put it there. They may have purchased the software from someone else, and whoever wrote the software put it in there so it could be exploited again at a later date.
Have you encountered any other big surprises in this job — either in the negotiations or in other aspects of it?
The biggest surprise for me was that the people I was negotiating with are just people, and they view this as their job.
In some cases, you do work with the occasional group who will be short or abrupt with their responses. But for the most part, especially in the past year or two, they're very straightforward. Some of them are even what would be considered helpful or customer service-oriented.
I had one particular criminal who reminded me that we're partners in this and we both want what's best for my client. They kept saying, "Please trust us, this is our business, we don't want to let you down." They do understand that if they don't deliver after coming to an agreement with you, people quit paying the ransom. Then they're out of business. Most of the time they will deliver what they promised — and yeah, it may have an additional surprise in there.
The other thing is the focus on customer service. It was just email when I first started, but now, larger groups have portals set up. You go to the portals and it has directions on how to interact with them in terms of what they're looking for, and then one of the paths will say something like, "customer support." And if you click on that you're gonna live chat to negotiate with the ransomer.
I don't think the average person is aware of just how much this is a business. There’s a whole economy based on this criminal activity.
What else do you think the average person gets wrong about ransomware negotiations, or that you wish they knew about it?
I wish people understood that paying the ransom will not necessarily speed things up. A lot of times a client will say, "We're just going to pay it because we need to get back to work." I understand that, but it takes time to decrypt files, just like it takes time to restore from backup.
Regardless of the method you choose, you need to recover cleanly so you're not reinfected within a couple of weeks. No matter what, it's going to take time.
A lot of people also don't understand that backups need to be off-site and off-network. A lot of companies set up off-site, because they've been told over and over, but they're connected to the same Windows network. And that's how they end up in trouble.
Another thing people aren’t aware of is that, while it’s not illegal to pay a ransom at this time, there are situations where you have to check [the ransomer] very carefully. If their wallet address or anything in the conversation leads you to believe that you're dealing with someone on the Office of Foreign Asset Control (OFAC) sanction list, you can’t pay. Those are known terrorists.
If a company pays what turns out to be a sanctioned wallet, they can run into huge fines in the millions of dollars. If you’re in dire straits, though, you can apply for a waiver through OFAC. I have not had to do that so I don't know the likelihood of getting that approved, but they do have a process you can follow to ask for an exception.
If it's possible to recover without paying a ransom, I always recommend going in that way.
Yes, the FBI recommends that those affected by ransomware should not pay. What do you think would happen to the ransomware attack industry if victims stopped paying?
Well, I think they would find other avenues to attack. I do think we could reduce it if everyone stopped paying. I know that’s a Pollyanna-ish look at it since I made a living working with companies who can't not pay or they will be out of business.
So I don't know what the answer is, but I’m glad that, especially at the federal level, it's getting some attention. I keep hearing people say, “We should outlaw cryptocurrency," but that's not going to fix it either. They'll find other ways. Ransomware was around before cryptocurrency — you just had to send a check or money order.
I think really the important thing is for people and companies to understand that information security is now a foundational part of any company, just like human resources. You need to have information security. You need to pay attention to it. And you need to make sure you have good prevention measures in place. For everything we're able to fix and patch, they come out with another way to attack.
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

