Skip to main content
Omaha office · 9224 S 169th St
Serving local businesses since 2016
Veteran-owned and operated
Onsite support across the metro
Back to Blog
Cybersecurity

What Does a Ransomware Note Actually Say? (Real Examples, Explained)

Ransom notes are sales letters written under duress. Here is what LockBit, Akira, Black Basta and others actually write on the screen — and the pressure tactics hidden in the wording.

August 4, 2026

Almost nobody sees a ransomware note until the morning it is on their own screen. By then it is the worst possible moment to be reading one for the first time. So here is what they actually say, why they are worded the way they are, and what an Omaha business owner should do in the first hour.

We publish real, sanitized notes from the eight gangs most likely to hit a US small business in our ransomware note library. Every Tor address, wallet and contact ID is stripped out and nothing is clickable — you can read them safely.

A ransom note is a sales letter

It helps to understand what the note is for. It is not a threat written in anger. It is a conversion tool, refined over thousands of victims, and its only job is to get you into a chat window fast, before you have talked to your IT provider, your insurer, or the FBI. Nearly every note from every gang does the same four things.

1. It establishes control

The note opens by telling you what happened in flat, technical language: your network was encrypted, your files were copied, do not attempt to rename or repair them. The calm tone is deliberate. It reads like a vendor notice because panic makes people call the police, and confidence makes people negotiate.

2. It adds a second threat you cannot fix with backups

This is the change that matters most. Modern gangs steal your data before encrypting it, then threaten to publish it. Akira and Black Basta both lead with this. It means a clean backup restores your operations but does nothing about the leak — which is exactly why the note mentions your clients, your patients, or your contracts by name.

3. It puts a clock on it

A deadline, usually 72 hours to a week, after which the price rises or the data is published. Sometimes there is a live countdown on the leak site. The deadline is almost always softer than it looks, but it exists to stop you from getting outside advice.

4. It offers to be helpful

The strangest part of a real ransom note is the customer-service tone. Many offer to decrypt two or three files for free as proof, promise a "security report" explaining how they got in, and warn you against hiring a recovery firm because middlemen will only mark up the price. That warning is the tell: they do not want a professional in the room.

What the wording tells you about the attack

The note itself is evidence. The filename, the gang's branding, and the phrasing usually identify the group within minutes, and knowing the group tells your responders how the attackers got in, what tools they used inside the network, and whether a free decryptor already exists. Our ransomware intelligence dashboard tracks active groups and their known tactics for exactly this reason.

If a note is on your screen right now

  • Do not pay and do not reply yet. The first conversation should be with a responder, not the attacker.
  • Do not delete the note. It identifies the group, and it is evidence for your insurer and the FBI.
  • Disconnect, do not wipe. Pull affected machines off the network but leave them powered as-is where possible — encryption keys sometimes live in memory.
  • Do not restore before you know how they got in. Restoring into a network the attacker still has access to buys you a second attack.
  • Call your insurer early. Many policies require notification before you engage anyone, and paying without them can void coverage.

Our ransomware recovery resources walk through the first hour in more detail, including who to report to.

The honest prevention list

Every note in our library came from an attack that started somewhere ordinary: an exposed remote desktop port, a password from an old breach, an unpatched firewall, or one convincing email. Multi-factor authentication on email and remote access, offline backup copies you have actually tested restoring, prompt patching of anything facing the internet, and endpoint detection that flags the intruder during the days they spend inside your network before encrypting anything — that is the list, and it has not changed.

If you would rather read a ransom note as a curiosity than as a message addressed to you, start with the note library, then look at what our cybersecurity services cover. DME is a local Omaha team — call 402-650-8407 and you will get a person here.

Omaha-based team · Same-day response available

Get IT Support in Omaha Today

Talk with DME about IT support, managed IT, cybersecurity, Microsoft 365, networks, backup, AI, or search optimization for your Omaha business. Scope and response commitments are documented before service begins.