Ransomware crews often price their extortion against a company's total revenue, even when the attack only hit one division, subsidiary, or system. It is a negotiation tactic as much as a technical one, and understanding it helps organizations avoid the rushed decisions it is designed to cause. Ransomware demands based on company revenue are built to feel urgent, large, and justified, whether or not the numbers make sense for the part of the business that was actually affected.
Why gangs anchor demands to total revenue
According to the source material, attackers use the larger revenue figure to create pressure, distort perceived affordability, and push executives toward faster settlement. The logic is simple. A company's total revenue is usually the biggest number an outsider can estimate, and it makes almost any ransom look small by comparison.
The unit that was hit may bring in a fraction of that revenue. But by pointing at the parent figure, a gang tries to reframe the conversation: "You can clearly afford this." That framing shifts attention away from the real question, which is what the incident actually costs and what recovery would take.
Public research points in the same direction. Palo Alto Networks has written that initial demands tend to fall between 0.05% and 5% of a victim's perceived annual revenue, and NetApp has described demands as often calculated as a percentage of annual revenue, typically around 3%. The key word is perceived. Attackers work from whatever figure they believe applies, and that is often the headline number.
How inflated figures distort negotiation decisions
Anchoring is a well-known bias: the first number put on the table shapes everything that follows. A demand pegged to total revenue sets a high anchor, so a later "discount" can feel like a win even when the final price is still far out of proportion to the damage.
Three distortions are worth watching for:
- Affordability confusion. Total revenue is not cash on hand, and it is not the budget available for incident response. A large company may still have limited liquidity, and the affected unit may have far less.
- Time pressure. Gangs pair big numbers with short deadlines. The source describes the aim as faster settlement, and a compressed timeline leaves less room for legal review, forensic work, and board input.
- Scope blur. If leadership is focused on the demand, it may spend less time establishing what was actually encrypted or stolen, which is the information that should drive the decision.
None of this means a demand is automatically bluff or bait. It means the number itself tells you more about the attacker's strategy than about your true exposure.
What it means for employees and customers whose data is at stake
Behind the negotiation are people. When a company rushes to settle, the decision is usually made around the financial figure, not around whose data was taken or what will happen to it afterward. Employees and customers are left exposed to the fallout, whatever the outcome of the talks.
Paying quickly does not guarantee that stolen data is deleted or that systems come back cleanly. It also does not remove the risk of follow-on pressure. As we reported in Ransomware Gangs Now Threaten to Contact Your Customers, some groups have moved to directly contacting the people whose information they hold, turning customer privacy into a second lever against the company.
If you are an employee or customer of an organization that has been hit, the practical concern is your personal data, not the ransom size. Pay attention to official breach notices, and be cautious about unexpected emails, calls, or texts that mention the incident, since those could come from extortionists or from scammers exploiting the news.
How organizations can resist pressure with a response plan
The best defense against a manipulated number is a plan made before the number arrives. Organizations that have already decided who is in the room, what information is needed, and how decisions get made are much harder to rush.
- Separate scope from price. Establish which systems and data were actually affected before discussing any figure. The unit's real revenue and recovery cost matter more than the group's estimate of the whole company.
- Slow the clock deliberately. Treat deadlines as part of the attacker's script. Involve legal counsel, incident responders, and leadership early so no single executive is deciding alone.
- Prepare communications. Know in advance how you would notify employees and customers, so threats to contact them carry less shock value.
- Keep tested backups and recovery paths. The more credible your ability to restore, the less leverage any demand has.
The human side of negotiation also carries risk. The case covered in Florida Ransomware Negotiator Convicted in US Extortion Case is a reminder that the intermediaries in these situations deserve scrutiny too.
For concrete preparation steps, our piece on a 2026 ransomware defense plan walks through a prevention checklist and the data protection considerations that come with it.
What This Means For You
If you run or advise a business, remember that a ransom figure tied to total revenue is a pressure device, not an accurate measure of your loss. Build your response around facts: what was hit, what was taken, and what recovery costs.
If you are a customer or employee, the figure matters less than your own exposure. Watch for official notifications, change passwords on affected accounts, enable multi-factor authentication where available, and treat unsolicited messages about a breach with suspicion.
Key takeaways
- Ransomware demands based on company revenue exploit the largest available number to make payment look affordable and urgent.
- Anchoring and deadlines push executives toward quick settlements before scope is understood.
- Employees and customers carry the risk if data is stolen, regardless of whether a ransom is paid.
- A rehearsed response plan, with clear roles and verified backups, is the strongest counter to this tactic.
Understanding how extortion pressure works is the first step in resisting it. To go further, review the 2026 ransomware defense plan and the report on gangs threatening to contact customers, then check whether your own organization's playbook is ready before a demand ever lands.




