Inside the Minds of Threat Actors with Jennifer Polliard of Booz Allen Hamilton

In a world where ransomware attacks are growing more frequent and complex, DigitalMint’s latest Cyber Fireside Chat pulled back the curtain on what it’s like to negotiate with threat actors.


Joining our COO and Head of Threat Actor Intelligence, Don Wyper, was Jennifer Polliard, Director of Threat Actor Communications and Intelligence at Booz Allen Hamilton — and someone who’s been on the front lines of cyber extortion for years.
Here are some of the key highlights from the conversation:

From Law Enforcement to Cyber Negotiator

Jennifer’s path to becoming one of the top threat actor negotiators was anything but traditional.
A former U.S. Army veteran and law enforcement officer, Jennifer specialized in crisis negotiation and child victim investigations before transitioning into cyber. She admits she’s “not technical whatsoever,” but emphasizes that ransomware negotiation is more about people skills than coding skills.
”Throughout my time in law enforcement I was also trained through the FBI Academy Crisis Negotiation. So I was also a part of the crisis negotiation team, so that kind of parallels what we do a little bit. The tactics are somewhat the same – stall and distract. The only thing that ends up different is we end up sometimes having to pay the bad guy.” — Jennifer Polliard

1. Data Extortion Over Encryption

Threat actors are focusing more on exfiltrating and ransoming data rather than just encrypting systems. This shift is due to improved corporate backups and incident response practices.

2. Rise of Unknown ‘One-Off’ Groups

After major FBI takedowns of groups like LockBit and BlackCat, there’s been a surge in smaller, lesser-known groups trying to fill the power vacuum — often aggressively.
“Sometimes you could tell that they are new and they have a point to prove if they are super aggressive, because then they don’t have the rules that the other larger groups tend to follow.”

What It’s Like Negotiating With Criminals

Jennifer’s team communicates with cybercriminals daily. Some come from larger groups and mimic structured negotiation practices. Others are chaotic and aggressive.
She explains that:
  • Many threat actors pride themselves on their “reputation”, which ironically helps maintain a degree of “honor among thieves.”
  • Red flags for potential re-extortion include overly quick negotiations or steep discounts.
  • Some attackers display empathy—especially when it comes to attacks involving children’s hospitals.
“They said to me, this is business. you need to get back up and running and we need to get paid. And I said, ‘I understand that, but at the cost of children’s lives?’ And they apologized and immediately gave the decryptor back for free.”

Common Misconceptions From Clients

Many of Jennifer’s clients are seasoned business negotiators, but ransomware negotiations are different:
“I have to explain to them that these guys don’t really care about your reputation. All they care about is getting paid. so they’re not going to think logically.”
Educating clients about the psychology and behavior of cybercriminals is a crucial part of her role.

Day-to-Day Dialogues: AI, Google Translate, and Virtual High Fives

While AI tools like ChatGPT or “WormGPT” have been rumored among threat actors, Jennifer says she hasn’t seen wide adoption. Most criminals still use broken Google Translate, which often causes confusing exchanges.
Still, the negotiation process is nuanced and can become oddly personal.
“We communicate with them daily, it’s almost as if you get to know them. So when we tell a client, what we’re going to say, this is what we expect them to say back to us. It’s always kind of like a virtual high five, we knew exactly what they were going to do.”
One story she shared involved a particularly aggressive actor who kept calling her “sir”:
“I kind of was a little frustrated with the aggressiveness and the tone that they were taking with me. So my response to them was, ‘I appreciate the respect of and the formality of calling me sir, I’m not a sir. I’m a ma’am.’ And they completely changed their tone and started calling me ‘madam’ and we ended up working out a good deal for the client.

Who Are the Big Players Now?

Following the takedown of LockBit and BlackCat, a few groups are leading today’s threat landscape:
  • Akira (especially leveraging the recent SonicWall vulnerability)
  • INC Ransom
  • Qilin
These are the groups that both Booz Allen Hamilton and DigitalMint are encountering most often in the trenches of cyber extortion.

Final Thoughts


A big thank you to Jennifer Polliard for joining us in the 5th episode of our Fireside Chat Series and sharing her expert insights
We look forward to more thought-provoking discussions in future episodes of our Fireside Chat series!

About Jennifer & Booz Allen Hamilton:

Jennifer Polliard is a Sr. Director at Booz Allen and leads the Threat Actor Communication & Intelligence (TACI) team for the commercial Incident Response business. A 25-year veteran of local law enforcement and the military police, Jennifer is an experienced negotiator who has handled thousands of crisis negotiations during her career. ​
Jennifer has a proven track record in intelligence gathering, strategy development, and crisis communications/negotiations, which she uses as she leads a team of experts who navigate hundreds of ransomware events and other cyber incidents each year. Jennifer and her team work with a broad range of companies across every business sector, from small, privately owned organizations to the Global Fortune 2,000. Jennifer and her team successfully negotiate and communicate directly with adversaries by using data-driven intelligence and tracking the behaviors/patterns of threat actor groups (both independent and nation-state affiliated). The TACI team also works closely with clients to proactively develop strategies to mitigate ransomware incidents. ​
An advocate for women in cybersecurity, Jennifer serves as a mentor and often speaks to individuals and organizations that are focused on recruiting women into cybersecurity and advancing women in the field.​
If your organization needs help navigating a ransomware crisis, don’t hesitate to reach out to the teams at DigitalMint or connect with Jennifer on LinkedIn.
Learn more about Booz Allen Hamilton