← Back to Insights
Cyberattack Case

Paying the ransom: the decision gets made before the attack

Paying the ransom: the decision gets made before the attack

What happened in mid August 2026

In mid August the government of Liechtenstein ruled out paying a ransom after attackers took beneficial owner records covering roughly 31,000 legal entities. Prime Minister Brigitte Haas said so in remarks reported on 14 August. For Swiss readers it matters, because the register is tied to structures administered from here.

The same week a communications provider also declined to pay, and the attackers published a 280 gigabyte archive covering roughly 1.6 million accounts. Two organisations, the same answer, different consequences: a single case makes a poor template, the preparation makes a good one.

What does a payment actually buy?

Less a moral question than a practical one. The decryption key concerns getting operations back. An organisation with backups held separately and restored as a test on a regular schedule usually does not need it.

The promise not to publish stolen data concerns nothing verifiable. The data is already copied, and what is bought is an assurance from someone whose business model runs on broken assurances.

The first is a technical problem with an alternative, the second is not. So the weight shifts forward, onto the days before any demand arrives.

How would you know it is coming?

Almost every attack of this kind starts with a person, an email or a call that sounded plausible enough. Whether anyone notices and says something is checkable in advance: Korix simulates those attacks under control and shows how many people report them, and how fast.

Why does the decision have to be made in advance?

Because conditions on the day rule out any calm weighing of options: a deadline is running, the facts are unclear, systems are down. What has to be fixed in advance is not the outcome but the frame: who decides, and at what threshold outside help is called.

Who decides, and with what authority?

In small organisations the answer is rarely written down. It belongs on one page stored outside the affected systems: the person authorised to decide and their deputy, the numbers for the insurer, the lawyer and the IT provider, and the question of whether a payment is legally available at all. That last one belongs with your own legal advisers, settled beforehand.

Its absence rarely comes down to willingness, but to the fact that nobody can carry the role on the side. Korix is built to be the security team you do not have to operate.

How does the reporting duty fit in?

The reporting question and the payment question run in parallel but are separate: one carries a deadline towards an authority, the other carries none towards an attacker. More on that in "Meldepflicht erfüllt, Risiko unverändert".

What can be done this week?

Four things, none of them a project.

First, attempt a restore on a real system. A backup that has never been restored is an assumption.

Second, write the one page of names and numbers, and store it outside your own systems.

Third, say the starting position out loud in the management meeting, before a demand arrives.

Fourth, measure instead of guessing, and that is exactly what Korix is for. The Phishing Simulation schedules and launches itself, and the dashboard shows how many people reported it. Nobody on your side has to run it. An assumption becomes a number.

The Liechtenstein case will be two weeks old soon enough. The question it raises will not be: is there someone named who answers it?

If not, that is not a failing, it is the normal state without a security team of your own. That gap is what Korix fills: we simulate the attacks continuously and measure the response, so you hold the numbers before anyone makes a demand.

Fifteen minutes is enough to show you what this looks like where you work. Book a call