Case file
Founded 2018 in Connecticut Acquired by Veeam in 2024 - price undisclosed More than 2,000 cases handled annually Q3 2025 payment rate: 23% Founded 2018 in Connecticut Acquired by Veeam in 2024 - price undisclosed More than 2,000 cases handled annually Q3 2025 payment rate: 23%

Company profile / Cyber extortion

Coveware Built a Ransomware Business Around One Awkward Goal: Pay Nothing

The company built its edge by studying thousands of extortion cases, then turning the evidence into a blunt recommendation many victims do not expect: the best ransom payment is often no payment at all.

The first thing Coveware sells in a ransomware emergency is not cryptocurrency, a decryptor, or a silver-tongued conversation with a criminal. It sells a pause. Somewhere inside a company, the servers are down, the backups are suspect, a ransom note is glowing, and the cost of another idle hour is becoming painfully legible. Coveware's job is to replace panic with a short list of facts: what happened, what still works, whether the attacker can deliver what it claims, and whether paying would change the outcome.

That distinction matters because the public image of ransomware response is a dim room and a professional negotiator tapping messages into the dark web. The actual work is more clerical, technical, and consequential. Coveware identifies the strain, gathers forensic evidence, checks sanctions and compliance exposure, compares the incident with similar cases, evaluates backups, estimates recovery time, handles threat-actor communications, and - only when the client authorizes it - procures and transfers cryptocurrency. Then comes decryption, validation, restoration, and the paperwork insurers and regulators will want.

THE PAYMENT STEP IS CONDITIONAL. THE EVIDENCE STEP IS NOT.

The real productA database made from terrible Tuesdays

Coveware was founded in 2018 by Bill Siegel, a finance and marketplace operator who had been CFO of SecurityScorecard, and Alex Holdtman, a technologist who had worked at backup provider Datto. The pair did not arrive with a crisp menu of products. Siegel has said they began with a more primitive question: how do you collect accurate information about what really happens inside ransomware incidents?

That was the opening. Victims rarely volunteered details. Vendors saw only their slice. Public reports leaned on surveys, dramatic outliers, and anecdotes. Coveware put itself inside the workflow, where every case could produce structured evidence about the attacker, initial access, demand, negotiation, payment, decryptor reliability, downtime, data loss, and recovery. By 2021, the firm said it had handled more than 2,000 cyber-extortion incidents. Today it says it manages more than 2,000 cases a year.

“The goal is to find a way for the company to recover without having to pay at all.”Bill Siegel, speaking to NPR in 2021

The loop is the business. Case data improves the next assessment. Better assessments produce faster, more defensible decisions. The same anonymized evidence feeds quarterly reports read by security teams, insurers, lawyers, journalists, and law enforcement. The reports, in turn, establish why a narrow specialist may know more about a particular actor or decryptor than a general incident-response shop.

2,000+cases handled per year, according to Coveware
<24htarget for Recon triage and reporting
23%share of cases paying in Q3 2025

What changedNegotiation became the exception, not the product

In 2019, Coveware occupied an awkward neighborhood. Some “data recovery” vendors quietly paid attackers while implying they had a technical remedy. Coveware was unusually explicit about the transaction. It charged flat per-incident fees, separated its fee from the ransom, and said settlement reimbursements carried no markup or crypto spread. Transparency was not decorative. A frightened buyer needed to know whether its adviser profited when the ransom grew.

But the market changed. Backups improved. Insurers and specialist lawyers developed playbooks. Law enforcement disrupted large ransomware brands. More boards learned that paying for a promise to delete stolen data offers little durable protection. Coveware's own cases show the share of victims paying falling from more than 80 percent in 2019 to 23 percent in the third quarter of 2025. That is not a universal market rate; it is the view through Coveware's case mix. It is still a striking change in the default answer.

Paying became less normal

Selected Coveware case cohorts
2019
80%+
Q1 '24
28%
Q3 '24
32%
Q3 '25
23%
Q1 '26
23%

Directional, not a census of all ransomware events. Percentages reflect incidents visible to Coveware and vary by quarter and case mix.

The data also changed what Coveware could say. In 2025, it reported that company size and industry were less important cost drivers than operational impact. In early 2026, it documented a bug in Nitrogen ransomware for ESXi systems that corrupted the public key used during encryption. The criminal could not decrypt the files either. In that situation, paying was not merely distasteful. It was technically useless.

Product, not theaterRecon, Unidecrypt, and the flat-fee clock

Coveware gradually turned repeated service work into software. Recon is a non-persistent collection tool backed by an automated analysis platform. It gathers incident data, encrypts it locally, and maps observed behavior to the MITRE ATT&CK framework. Coveware says the agent takes about ten minutes on average to run and can support a remediation report within hours. Unidecrypt supports the next ugly phase: using a decryptor across real systems without compounding the damage.

Customers can call during an incident, assuming capacity is available, or buy a retainer with defined events, response-time commitments, 24/7/365 coverage, a success manager, and preparation sessions. A bespoke tier adds tabletop or hands-on exercises. Public list prices are not posted. Active response uses flat incident fees; retainers are prepaid. The price Veeam paid to acquire Coveware was also not disclosed. In other words, the two numbers everyone asks for - the service fee and the exit - remain private, while the cost of the underlying crisis is documented obsessively.

Veeam graphic announcing complete ransomware support from protection through response and recovery
Veeam bought the people who answer after the backup plan meets the actual attacker. The transaction closed in March 2024; the price stayed in the vault.

The buyer and the marketWhy Veeam wanted a first responder

Veeam announced its acquisition of Coveware in April 2024, after the deal closed on March 29. The logic was cleaner than the cap table. Veeam protects and restores data. Coveware arrives when protection has been tested, recovery is uncertain, and legal, technical, financial, and executive decisions collide. The combination lets Veeam sell resilience before an attack and bring operational case experience into the response after one.

Coveware continued as Coveware by Veeam. Its Recon technology surfaced in Veeam Data Platform 12.3 later that year. The fit also widened Coveware's distribution beyond the privacy lawyers, forensic firms, cyber insurers, restoration teams, and managed service providers that already orbit an incident. Competitors include ransomware specialists such as Kivu and Arete, broad responders such as Mandiant, Palo Alto Networks' Unit 42, and CrowdStrike Services, plus the improvised alternative: counsel hires forensics, the insurer calls its panel, IT calls its MSP, and someone finds a crypto broker.

That improvised team can work. It can also create five clocks, four contracts, three versions of the facts, and no obvious owner. Coveware's differentiation is less “we know hackers” than “we put the decision chain in one operating system.” The firm bundles assessment, negotiation, settlement, decryption support, and documentation, while its software compresses the forensic wait.

Who callsThe customer is a temporary coalition

The organization on the invoice may be a hospital, manufacturer, professional-services firm, public agency, or midsize business. The user is rarely one person. During a live event, the working customer becomes a temporary coalition: the chief information security officer wants containment, the infrastructure team wants systems back, outside counsel wants privilege preserved, the insurer wants an approved process, finance wants to know who can move funds, and the chief executive wants a credible opening time. Each participant can be rational alone and still produce gridlock together.

Coveware solves coordination as much as malware. Its assessment gives the coalition a shared set of options. Threat-actor communication keeps improvised messages from changing the leverage. Financial controls make any authorized settlement traceable. Decryption support turns a key into a recovery plan. Post-incident records create an account of what was known and decided. Retained service moves some of those introductions, approvals, and rehearsals to a calm day, when executives can disagree without a ransom clock running in the corner.

This is also why the company does not replace the rest of the response market. Privacy counsel still owns legal advice. Deep forensic investigators may need to establish scope. Restoration teams rebuild. Insurers interpret coverage, and law enforcement investigates the crime. Coveware fits between them as the specialist for extortion decisions and ransomware recovery mechanics. The boundary is part of the product: a narrow responder can be useful precisely because it is not pretending to be every expert in the room.

The stealable playbookInstrument the mess before you automate it

There is a useful company-building lesson hiding inside the incident room. Coveware did not start by declaring a grand platform. It entered a painful, high-touch workflow and recorded the exhaust. Repeated questions became data fields. Repeated tasks became Recon and Unidecrypt. Repeated observations became public reports. The services generated the dataset; the dataset improved the services; the software made both faster.

What to copy

Pick a workflow where judgment is expensive. Capture the same structured facts every time. Publish aggregate insight. Automate collection and analysis, while leaving irreversible decisions with accountable humans.

Where it breaks

The loop fails when cases are too rare to compare, definitions drift, data cannot be anonymized safely, yesterday's pattern is mistaken for certainty, or the software outruns the expert who understands its limits.

The model also depends on trust. A response provider sees sensitive systems, privileged communications, financial approvals, and evidence that may interest law enforcement. If the provider earns more from a large settlement, hoards data, or presents anecdote as probability, the loop becomes a liability. Coveware's flat-fee posture and no-markup settlement claim are designed to answer that concern, but clients still need counsel, independent authority, tested backups, clean approval paths, and a willingness to walk away from a bad deal.

“You have to practice, and you have to do it regularly.”Bill Siegel at VeeamON, 2024

That may be the least cinematic and most useful Coveware advice. The company cannot rescue files that were irreversibly corrupted. It cannot make a criminal honor a deletion promise. It cannot create clean backups after the network is encrypted. It works best when an organization has already decided who can isolate systems, who can authorize a shutdown, who speaks to the attacker, who informs regulators, and under what conditions payment is forbidden.

Coveware sits in the narrow gap between security software and corporate judgment. Its tools can move the facts faster, and its case history can make probabilities less imaginary. The final decision still belongs to the victim. On the worst Tuesday of the year, that sober boundary may be the product.