DOI: 10.1177/08944393261478555 ISSN: 0894-4393

Managing Conti: Temporal Dynamics of Managerial Communication in a Ransomware Group

Giovanni Radhitio Putra Sadewo, David Bright, Chad Whelan, Jürgen Lerner

Ransomware groups are frequently described as structured enterprises with defined managerial hierarchies, yet most empirical research adopts cross-sectional designs that treat leadership positions as static. This study asks: How do upper- and middle-management actors in a ransomware organisation adjust their communication patterns over time, particularly in balancing coordination and concealment? Focusing on the Conti ransomware group, we examine whether managerial centrality and rank-based communication preferences remain stable or shift across different operational phases. We analyse leaked Jabber chat logs comprising 95,134 cleaned message events exchanged among 287 unique user IDs between June 2020 and March 2022. Actors were classified into upper management ( n = 9), middle management ( n = 9), staff ( n = 81), and affiliates/unassigned ( n = 188). The data were divided into four temporal periods. Using relational event models (REMs) estimated via Cox proportional hazard models with sampled non-events, we model rank-based sending, receiving, and homophily/heterophily effects, interacting these mechanisms with time to capture period-specific dynamics. The findings indicate that upper management was highly active in sending and receiving messages during the early stage of operations, but subsequently withdrew from routine communication. Despite reduced visibility, upper managers consistently exhibited cross-rank (heterophilous) communication rather than insulating themselves through same-rank ties. Middle management, by contrast, remained consistently active across most periods and alternated between cross-rank and same-rank communication patterns, reflecting a flexible intermediary role. Overall, managerial centrality did not persist uniformly over time. This study contributes to the literature by advancing a dynamic, longitudinal perspective on ransomware governance. It demonstrates that managerial embeddedness is temporally contingent and tier-specific, underscoring the importance of event-level and rank-based network analysis. The findings also inform disruption strategies by identifying when and which managerial tiers are most structurally central, highlighting stage-specific vulnerabilities in ransomware organisations.

More from our Archive