1. $50k or we attack - didn’t register anything
2. $25k or else - a minor overload on the server but nothing serious.
3. $10k or else - a serious attack which affected the service in a major way.
4. $5k or we really pissed - this time they took down a whole Tier2 ISP and Datacenter in London for a day. Other carriers peering on London Internet Exchange had to blackhole traffic to our service provider and finally kept blackholing one of our IPs for a while. I had to scramble to find a DDoS mitigation service, new DC and servers.
We did not respond to any of the emails. The attackers were also quite dumb, they attacked the web servers which were located in a well connected place.
The money making service of the business was in the Caribbean with a 1,5Mbps T1 and a 0,5Mbps satellite backup. They could have saturated those much easier for much longer and the impact then would have been about $1M revenue loss per hour.
Somewhere I read that some ransomware had excellent "customer" service for helping you transfer over the payment and promptly restore your files.
From their side, the logic seems as simple as: repeat the attack -> some chance of more money, don't repeat the attack -> 0% chance of more money
To puff and look important and to say
Though we know we should defeat you
We have not the time to beat you
We will therefore give you cash to go away
And that is called paying the Dane-Geld
And we've proved it again and again
That if once you have paid him the Dane-Geld
You never get rid of the Dane
From the german chaos computer clubs yearly meeting. Linus talks about what to do and who ransoms work, how "well" the service is and briefly pros and cons of paying.
https://media.ccc.de/v/37c3-12134-hirne_hacken_hackback_edit...
Also a good one was the first part: https://media.ccc.de/v/36c3-11175-hirne_hacken