Ransomware Splash Screens, Loss Aversion and Trust: Insights from Behavioral Economics
Abstract
1. Introduction
Related Literature
2. Gain–Loss Framing and Ransom Demands
- The victim does not pay the ransom and so stays without access to their files. Denote this NP for not pay. Without loss of generality, we set the payoff from NP at 0, denoted .
- The victim pays the ransom and recovers access to their files. Denote this PR for pay and recover. In evaluating the payoff, we need to consider the value of the files, denoted W, as well as the ransom paid, denoted R. We also take into account that the victim may experience disutility on moral and ethical grounds from having paid a ransom to criminals. Denote this cost by E. The net payoff is then given by .
- The victim pays the ransom and does not recover their files. Denote this PN for pay and not recover. In this case, the victim again pays the ransom R and experiences disutility on moral grounds. In addition, we also take into account additional disutility from ‘anger’ at the criminals not honouring their promise to return the files. Denote this cost by A. The net payoff is then given by .
- The victim does not pay and so stays without access to their files. The payoff takes into account the loss of files, valued at W, hence .
- The victim pays the ransom and recovers access to their files. In this outcome the victim has paid the ransom and incurred the ethical cost. The net payoff is thus .
- The victim pays the ransom and does not recover their files. In this outcome the victim has lost their files, paid the ransom and incurred the ethical cost and anger cost. The net payoff is thus .
3. Manipulation of Ransomware Frames
4. Experiment Design
- How likely would you be to pay the ransom? [WTP]
- How likely do you think it is that the criminals will provide the key to decrypt your files? [Trust]
- How fast do you think it is that you would make a decision? [Fast]
- To what extent would this ransom demand make you feel angry? [Angry]
- How helpful is the ransom demand in informing you about what has happened and what to do about it? [Helpful]
- If you ultimately get your files back, how positive you would feel about paying the ransom? [Positivity]
5. Experiment Results
6. Discussion
6.1. Limitations
6.2. Future Research Directions
7. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Appendix A. Summary of Comments on Features That Determined Highest Rank and Lowest Rank
| WTP/Trust/Helpful/Fast/Positivity (X for Least WTP) |
| CryptoWall |
| (Most willing to pay) |
| Something is free and able to see if it is a scam. |
| Doesn’t give you much time before the ransom is doubled. |
| Clear layout, professional with helpful steps on how to pay. |
| IP address makes the ransom more serious, makes you feel threatened. |
| CryptoLocker |
| (Most willing to pay) |
| Negative and serious language, company feel so makes it seem more valid, |
| threat at the end increases the likelihood that I pay. |
| Time limit, red warning, bold text to highlight, red background. |
| Threat of a short deadline. |
| Design of the warning. |
| Information provided on how the ransom is written. |
| WannaCry |
| (Most willing to pay) |
| Red colour makes me feel it’s emergency document. |
| Most information about consequences, time limit. |
| Option to decrypt some files for free, indicated they would decrypt all for payment. |
| (Most trustful) |
| Countdown adds pressure, information about file decryption. |
| Guarantee to return my files, can decrypt one for free. |
| Description of how to get files back. |
| Looks legitimate, not posed as a threat, friendly tone, more of a solution. |
| Informative details regarding the ransom payment. |
| (Most helpful) |
| Helpfully laid out, clear, explains situation and steps to rectify. |
| Could decrypt some files, extra information. |
| (Fastest) |
| Time limit puts pressure on the user, price increase provides incentive to decide |
| quickly. |
| (Most positive after recovery) |
| Professional scammer, could happen to anyone. |
| CTBLocker |
| (Most willing to pay) |
| Double price from £300 to £600. |
| Timer, warning about trying to take off software myself, promise to return files. |
| Get one file for free, direct access to the key. |
| Red colour looks like virus, threatening words. X |
| Looks like a fake pop up which comes up often. X |
| Looks fake and like a Windows XP virus. X |
| Dark colours don’t look professional. X |
| TorrentLocker |
| (Most willing to pay) |
| Simple design, explains what happened and what to do. |
| It seems legitimate, with FAQs. |
| If no time limit I could try and get external help first. X |
| Cerber |
| (Most willing to pay) |
| Poor and unprofessional layout, not clear or concise instructions. X |
| Doesn’t provide any valid or substantial information. X |
| Design shows the encrypters are amateurs, think of other solutions before paying. X |
| Looks simple like a pop up from a computer. X |
| Petya |
| (Most willing to pay) |
| Black and pink colouring makes it look fake. X |
| Uses html file and looks less professional. X |
| Colour, lots of words, dull, not easy on the eye. X |
| Complicated description and process. X |
| Patronizing, email address is suspicious. X |
| (Least trustful) |
| Unprofessional style and presentation. X |
| Uses html file and looks less professional. X |
| Vague about payment process. X |
| There wasn’t much to reassure me of the safe return of the files, doesn’t |
| seem authentic. X |
| Look like amateurs, or threatening rather than helping. X |
| (Least helpful) |
| No information provided, only that there is a special offer. X |
| Provides useless information and is impolite. X |
| (Least positive after recovery) |
| Seems most criminal, paying through email feels like you’re directly paying the |
| criminal. X |
| Locky |
| (Most willing to pay) |
| Warnings look least genuine. X |
| Too complicated, full of codes and words. X |
| Spelling mistakes, lack of information. X |
| Too simple. X |
| A lot of different webpages and potentially more viruses. X |
| Doesn’t look real, and it’s on notepad. X |
| Not double price. X |
| (Least fast) |
| No threat of deadline reduces urgency. X |
| Not giving much information leads me to believe it’s not real. X |
| Note: All the comments are from the 6 ranking tasks (rank 1 and 8). e.g., ‘What features in the example that determined your choice of most likely to pay?’ |
Appendix B. Experiment Instructions
- Questionnaire on ransomware
- Background
- The malware encrypts the files on your computer, laptop or similar. It encrypts documents, e.g., word or excel files, as well as photographs and videos.
- The victim is then asked to pay a ransom in order to regain access to their files. The criminals promise to provide the key to un-encrypt the files.
- If the malware is technically well designed (and many forms of ransomware now are), and if the victim has no backup, then the files can only be recovered by getting the key off the criminals. There is no other option.
- If the victim pays the ransom then they may or may not get the key to the files. Some criminals do provide the key and the victim regains access to their files. Some criminals do not provide the key and the files are lost.
- Your Task
- How likely would you be to pay the ransom?
- How likely do you think it is that the criminals will provide the key to decrypt your files?
- How fast do you think it is that you would make a decision?
- To what extent would this ransom demand make you feel angry?
- How helpful is the ransom demand in informing you about what has happened and what to do about it?
- If you ultimately get your files back, how positive you would feel about paying the ransom?
- Rating Task Example

- Ranking Task Example

- Other Splash Screens







References
- Kalaimannan, E.; John, S.K.; DuBose, T.; Pinto, A. Influences on ransomware’s evolution and predictions for the future challenges. J. Cyber Secur. Technol. 2017, 1, 23–31. [Google Scholar] [CrossRef] [Scilit]
- Kok, S.; Abdullah, A.; Jhanjhi, N.; Supramaniam, M. Ransomware, threat and detection techniques: A review. Int. J. Comput. Sci. Netw. Secur. 2019, 19, 136. [Google Scholar]
- Beaman, C.; Barkworth, A.; Akande, T.D.; Hakak, S.; Khan, M.K. Ransomware: Recent advances, analysis, challenges and future research directions. Comput. Secur. 2021, 111, 102490. [Google Scholar] [CrossRef] [Scilit]
- Oz, H.; Aris, A.; Levi, A.; Uluagac, A.S. A survey on ransomware: Evolution, taxonomy, and defense solutions. ACM Comput. Surv. 2022, 54, 1–37. [Google Scholar] [CrossRef] [Scilit]
- Razaulla, S.; Fachkha, C.; Markarian, C.; Gawanmeh, A.; Mansoor, W.; Fung, B.C.; Assi, C. The age of ransomware: A survey on the evolution, taxonomy, and research directions. IEEE Access 2023, 11, 40698–40723. [Google Scholar] [CrossRef] [Scilit]
- A Flawed Ransomware Encryptor. 2015. Available online: https://securelist.com/a-flawed-ransomware-encryptor/69481/ (accessed on 28 August 2025).
- The Rise of Low Quality Ransomware G-DATA Security Blog. 2016. Available online: https://www.gdatasoftware.com/blog/2016/09/29157-the-rise-of-low-quality-ransomware (accessed on 28 August 2025).
- Kharraz, A.; Robertson, W.; Balzarotti, D.; Bilge, L.; Kirda, E. Cutting the gordian knot: A look under the hood of ransomware attacks. In Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, Graz, Austria, 17–19 July 2015; Springer: Berlin/Heidelberg, Germany, 2015; pp. 3–24. [Google Scholar]
- Ruellan, E.; Paquet-Clouston, M.; Garcia, S. Conti Inc.: Understanding the internal discussions of a large ransomware-as-a-service operator with machine learning. Crime Sci. 2024, 13, 16. [Google Scholar] [CrossRef] [Scilit]
- Hernandez-Castro, J.; Cartwright, A.; Cartwright, E. An economic analysis of ransomware and its welfare consequences. R. Soc. Open Sci. 2020, 7, 190023. [Google Scholar] [CrossRef] [Scilit]
- Jarvis, K. Cryptolocker ransomware. Viitattu 2013, 20, 2014. [Google Scholar]
- Liao, K.; Zhao, Z.; Doupé, A.; Ahn, G.J. Behind closed doors: Measurement and analysis of CryptoLocker ransoms in Bitcoin. In Proceedings of the APWG Symposium on Electronic Crime Research (eCrime), Toronto, ON, Canada, 1–3 June 2016; IEEE: Piscataway, NJ, USA, 2016; pp. 1–13. [Google Scholar]
- Spagnuolo, M.; Maggi, F.; Zanero, S. Bitiodine: Extracting intelligence from the bitcoin network. In Proceedings of the International Conference on Financial Cryptography and Data Security, Christ Church, Barbados, 3–7 March 2014; Springer: Berlin/Heidelberg, Germany, 2014; pp. 457–468. [Google Scholar]
- Connolly, L.Y.; Wall, D.S. The rise of crypto-ransomware in a changing cybercrime landscape: Taxonomising countermeasures. Comput. Secur. 2019, 87, 101568. [Google Scholar] [CrossRef] [Scilit]
- Connolly, L.Y.; Wall, D.S.; Lang, M.; Oddson, B. An empirical study of ransomware attacks on organizations: An assessment of severity and salient factors affecting vulnerability. J. Cybersecur. 2020, 6, tyaa023. [Google Scholar] [CrossRef] [Scilit]
- Mott, G.; Turner, S.; Nurse, J.R.; MacColl, J.; Sullivan, J.; Cartwright, A.; Cartwright, E. Between a rock and a hard (ening) place: Cyber insurance in the ransomware era. Comput. Secur. 2023, 128, 103162. [Google Scholar] [CrossRef] [Scilit]
- Tversky, A.; Kahneman, D. The framing of decisions and the psychology of choice. Science 1981, 211, 453–458. [Google Scholar] [CrossRef] [Scilit]
- Barberis, N.C. Thirty years of prospect theory in economics: A review and assessment. J. Econ. Perspect. 2013, 27, 173–196. [Google Scholar] [CrossRef] [Scilit]
- Everett, C. Ransomware: To pay or not to pay? Comput. Fraud Secur. 2016, 2016, 8–12. [Google Scholar] [CrossRef] [Scilit]
- Halikias, H. The Three Cs of Ransomware. In Digital Shakedown: The Complete Guide to Understanding and Combating Ransomware; Springer: Berlin/Heidelberg, Germany, 2024; pp. 11–24. [Google Scholar]
- Exploring the Psychological Mechanisms Used in Ransomware Splash Screens. Sentin. One Rep. 2017. Available online: https://www.sentinelone.com/blog/exploring-psychological-mechanisms-used-ransomware-splash-screens/ (accessed on 28 August 2025).
- Kühberger, A. The influence of framing on risky decisions: A meta-analysis. Organ. Behav. Hum. Decis. Process. 1998, 75, 23–55. [Google Scholar] [CrossRef] [Scilit]
- Rodríguez-Priego, N.; Van Bavel, R.; Vila, J.; Briggs, P. Framing effects on article security behavior. Front. Psychol. 2020, 11, 527886. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Laszka, A.; Farhang, S.; Grossklags, J. On the economics of ransomware. In Proceedings of the International Conference on Decision and Game Theory for Security; Springer: Berlin/Heidelberg, Germany, 2017; pp. 397–417. [Google Scholar]
- Li, Z.; Liao, Q. Game theory of data-selling ransomware. J. Cyber Secur. Mobil. 2021, 10, 65–96. [Google Scholar] [CrossRef] [Scilit]
- Zhang, C.; Luo, F.; Ranzi, G. Multistage Game Theoretical Approach for Ransomware Attack and Defense. IEEE Trans. Serv. Comput. 2022, 16, 2800–2811. [Google Scholar] [CrossRef] [Scilit]
- Yin, T.; Sarabi, A.; Liu, M. Deterrence, backup, or insurance: Game-theoretic modeling of ransomware. Games 2023, 14, 20. [Google Scholar] [CrossRef] [Scilit]
- Arce, D.; Woods, D.W.; Böhme, R. Economics of incident response panels in cyber insurance. Comput. Secur. 2024, 140, 103742. [Google Scholar] [CrossRef] [Scilit]
- Cartwright, E.; Hernandez Castro, J.; Cartwright, A. To pay or not: Game theoretic models of ransomware. J. Cybersecur. 2019, 5, tyz009. [Google Scholar] [CrossRef] [Scilit]
- Connolly, A.Y.; Borrion, H. Reducing ransomware crime: Analysis of victims’ payment decisions. Comput. Secur. 2022, 119, 102760. [Google Scholar] [CrossRef] [Scilit]
- Mott, G.; Turner, S.; Nurse, J.R.; Pattnaik, N.; MacColl, J.; Huesch, P.; Sullivan, J. ‘There was a bit of PTSD every time I walked through the office door’: Ransomware harms and the factors that influence the victim organization’s experience. J. Cybersecur. 2024, 10, tyae013. [Google Scholar] [CrossRef] [Scilit]
- McIntyre, D.L.; Frank, R. No Gambles with Information Security: The Victim Psychology of a Ransomware Attack. In Cybercrime in Context: The Human Factor in Victimization, Offending, and Policing; Springer: Berlin/Heidelberg, Germany, 2021; pp. 43–60. [Google Scholar]
- Cartwright, A.; Cartwright, E.; Xue, L. Investing in prevention or paying for recovery-attitudes to cyber risk. In Proceedings of the International Conference on Decision and Game Theory for Security, Stockholm, Sweden, 30 October–1 November 2019; Springer: Berlin/Heidelberg, Germany, 2019; pp. 135–151. [Google Scholar]
- Yilmaz, Y.; Cetin, O.; Arief, B.; Hernandez-Castro, J. Investigating the impact of ransomware splash screens. J. Inf. Secur. Appl. 2021, 61, 102934. [Google Scholar] [CrossRef] [Scilit]
- Arief, B.; Periam, A.; Cetin, O.; Hernandez-Castro, J.C. Using eyetracker to find ways to mitigate ransomware. In Proceedings of the 6th International Conference on Information Systems Security and Privacy (ICISSP 2020), Valletta, Malta, 25–27 February 2020. [Google Scholar]
- Sharma, K.; Zhan, X.; Nah, F.F.H.; Siau, K.; Cheng, M.X. Impact of digital nudging on information security behavior: An experimental study on framing and priming in cybersecurity. Organ. Cybersecur. J. Pract. Process People 2021, 1, 69–91. [Google Scholar] [CrossRef] [Scilit]
- Plachkinova, M.; Menard, P. An examination of gain-and loss-framed messaging on smart home security training programs. Inf. Syst. Front. 2022, 24, 1395–1416. [Google Scholar] [CrossRef] [Scilit]
- Li, Z.; Liao, Q. Preventive portfolio against data-selling ransomware—A game theory of encryption and deception. Comput. Secur. 2022, 116, 102644. [Google Scholar] [CrossRef] [Scilit]
- Cartwright, A.; Cartwright, E.; MacColl, J.; Mott, G.; Turner, S.; Sullivan, J.; Nurse, J.R. How cyber insurance influences the ransomware payment decision: Theory and evidence. Geneva Pap. Risk Insur.-Issues Pract. 2023, 48, 300–331. [Google Scholar] [CrossRef] [Scilit]
- Meurs, T.; Cartwright, E.; Cartwright, A.; Junger, M.; Abhishta, A. Deception in double extortion ransomware attacks: An analysis of profitability and credibility. Comput. Secur. 2024, 138, 103670. [Google Scholar] [CrossRef] [Scilit]
- Caporusso, N.; Chea, S.; Abukhaled, R. A game-theoretical model of ransomware. In Proceedings of the International Conference on Applied Human Factors and Ergonomics, Orlando, FL, USA, 21–25 July 2018; Springer: Berlin/Heidelberg, Germany, 2018; pp. 69–78. [Google Scholar]
- Cartwright, A.; Cartwright, E.; Xue, L.; Hernandez-Castro, J. An investigation of individual willingness to pay ransomware. J. Financ. Crime 2023, 30, 728–741. [Google Scholar] [CrossRef] [Scilit]
- Bekkers, L.; van’t Hoff-De Goede, S.; Misana-ter Huurne, E.; van Houten, Y.; Spithoven, R.; Leukfeldt, E.R. Protecting your business against ransomware attacks? Explaining the motivations of entrepreneurs to take future protective measures against cybercrimes using an extended protection motivation theory model. Comput. Secur. 2023, 127, 103099. [Google Scholar] [CrossRef] [Scilit]
- Kahneman, D.; Tversky, A. Prospect Theory: An Analysis of Decision under Risk. Econometrica 1979, 47, 263–292. [Google Scholar] [CrossRef] [Scilit]
- Kahneman, D.; Knetsch, J.L.; Thaler, R.H. Anomalies: The endowment effect, loss aversion, and status quo bias. J. Econ. Perspect. 1991, 5, 193–206. [Google Scholar] [CrossRef] [Scilit]
- Camerer, C. Three cheers—Psychological, theoretical, empirical—For loss aversion. J. Mark. Res. 2005, 42, 129–133. [Google Scholar] [CrossRef] [Scilit]
- Gächter, S.; Johnson, E.J.; Herrmann, A. Individual-level loss aversion in riskless and risky choices. Theory Decis. 2022, 92, 599–624. [Google Scholar] [CrossRef] [Scilit]
- Brown, A.L.; Imai, T.; Vieider, F.M.; Camerer, C.F. Meta-analysis of empirical estimates of loss aversion. J. Econ. Lit. 2024, 62, 485–516. [Google Scholar] [CrossRef] [Scilit]
- Bateman, I.; Munro, A.; Rhodes, B.; Starmer, C.; Sugden, R. A test of the theory of reference-dependent preferences. Q. J. Econ. 1997, 112, 479–505. [Google Scholar] [CrossRef] [Scilit]
- Köszegi, B.; Rabin, M. A model of reference-dependent preferences. Q. J. Econ. 2006, 121, 1133–1165. [Google Scholar] [PubMed]
- De Dreu, C.K.; McCusker, C. Gain–loss frames and cooperation in two-person social dilemmas: A transformational analysis. J. Personal. Soc. Psychol. 1997, 72, 1093. [Google Scholar] [CrossRef]
- Kern, M.C.; Chugh, D. Bounded ethicality: The perils of loss framing. Psychol. Sci. 2009, 20, 378–384. [Google Scholar] [CrossRef] [Scilit]
- Nabi, R.L.; Walter, N.; Oshidary, N.; Endacott, C.G.; Love-Nichols, J.; Lew, Z.; Aune, A. Can emotions capture the elusive gain-loss framing effect? A meta-analysis. Commun. Res. 2020, 47, 1107–1130. [Google Scholar] [CrossRef] [Scilit]
- Connelly, B.L.; Certo, S.T.; Ireland, R.D.; Reutzel, C.R. Signaling theory: A review and assessment. J. Manag. 2011, 37, 39–67. [Google Scholar] [CrossRef] [Scilit]
- Karimov, F.P.; Brengman, M.; Van Hove, L. The effect of website design dimensions on initial trust: A synthesis of the empirical literature. J. Electron. Commer. Res. 2011, 12. [Google Scholar]
- Wells, J.D.; Valacich, J.S.; Hess, T.J. What signal are you sending? How website quality influences perceptions of product quality and purchase intentions. Mis Q. 2011, 35, 373–396. [Google Scholar] [CrossRef] [Scilit]
- Aakash, A.; Aggarwal, A.G. Role of EWOM, product satisfaction, and website quality on customer repurchase intention. In Strategy and Superior Performance of Micro and Small Businesses in Volatile Economies; IGI Global: Hershey, PA, USA, 2019; pp. 144–168. [Google Scholar]
- Shaw Brown, C.; Sulzer-Azaroff, B. An assessment of the relationship between customer satisfaction and service friendliness. J. Organ. Behav. Manag. 1994, 14, 55–76. [Google Scholar] [CrossRef] [Scilit]
- Tsai, W.C.; Huang, Y.M. Mechanisms linking employee affective delivery and customer behavioral intentions. J. Appl. Psychol. 2002, 87, 1001. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- El-Ebiary, Y.A.B.; Pathmanathan, P.R.; Tarshany, Y.M.A.; Jusoh, J.A.; Aseh, K.; Al Moaiad, Y.; Al-Kofahi, M.; Pande, B.; Bamansoor, S. Determinants of Customer Purchase Intention Using Zalora Mobile Commerce Application. In Proceedings of the 2021 2nd International Conference on Smart Computing and Electronic Enterprise (ICSCEE), Cameron Highlands, Malaysia, 15–17 June 2021; IEEE: Piscataway, NJ, USA, 2021; pp. 159–163. [Google Scholar]
- Kahneman, D.; Tversky, A. Choices, values, and frames. Am. Psychol. 1984, 39, 341. [Google Scholar] [CrossRef]
- Tversky, A.; Kahneman, D. Loss aversion in riskless choice: A reference-dependent model. Q. J. Econ. 1991, 106, 1039–1061. [Google Scholar] [CrossRef] [Scilit]
- Loewenstein, G.; Prelec, D. Anomalies in intertemporal choice: Evidence and an interpretation. Q. J. Econ. 1992, 107, 573–597. [Google Scholar] [CrossRef] [Scilit]
- Chandon, P.; Hutchinson, J.W.; Bradlow, E.T.; Young, S.H. Does in-store marketing work? Effects of the number and position of shelf facings on brand attention and evaluation at the point of purchase. J. Mark. 2009, 73, 1–17. [Google Scholar] [CrossRef] [Scilit]
- Reutskaja, E.; Nagel, R.; Camerer, C.F.; Rangel, A. Search dynamics in consumer choice under time pressure: An eye-tracking study. Am. Econ. Rev. 2011, 101, 900–926. [Google Scholar] [CrossRef] [Scilit]
- Cartwright, A.; Cartwright, E. Ransomware and reputation. Games 2019, 10, 26. [Google Scholar] [CrossRef] [Scilit]
- Exadaktylos, F.; Espín, A.M.; Branas-Garza, P. Experimental subjects are not different. Sci. Rep. 2013, 3, 1213. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Druckman, J.N.; Kam, C.D. Students as experimental participants. Camb. Handb. Exp. Political Sci. 2011, 1, 41–57. [Google Scholar]
- Blake, D.; Cannon, E.; Wright, D. Quantifying loss aversion: Evidence from a UK population survey. J. Risk Uncertain. 2021, 63, 27–57. [Google Scholar] [CrossRef] [Scilit]
- Zorabedian, J. Did the FBI Really Say “Pay Up” for Ransomware? Here’s What to Do… 2015. Available online: https://news.sophos.com/en-us/2015/10/28/did-the-fbi-really-say-pay-up-for-ransomware-heres-what-to-do/ (accessed on 28 August 2025).





| Characteristic | CryptoWall | CryptoLocker | WannaCry | CTBLocker | TorrentLocker | Cerber | Petya | Locky |
|---|---|---|---|---|---|---|---|---|
| 1. Words | 121 | 135 | 178 | 153 | 101 | 68 | 106 | 94 |
| 2. Software | Y | N | N | N | Y | Y | N | Y |
| 3. Timer | Y | Y | Y | Y | N | Y | N | N |
| 4. Price rise | Y | N | Y | N | N | Y | N | N |
| 5. Free sample | Y | N | Y | N | N | Y | N | N |
| 6. How to pay | 3 | 1 | 1 | 0 | 1 | 0 | 3 | 0 |
| 7. Encryption | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 3 |
| 8. Files | 3 | 1 | 0 | 1 | 0 | 0 | 0 | 0 |
| 9. Positive | 1 | 0 | 1 | 0 | 2 | 0 | 2 | 0 |
| 10. Negative | 0 | 4 | 2 | 4 | 0 | 0 | 1 | 0 |
| 11. Text colour | Black | Black | Black | Red | Blue | Black | Pink | Black |
| 12. Background | Blue | Red | Red | Black | White | White | Black | White |
| 13. Logo | N | Y | Y | N | N | N | N | N |
| Total Score * | 11 | 10 | 8 | 6 | 5 | 4 | 6 | 4 |
| Ransomware | WTP | Trust | Fast | Anger | Helpful | Positivity |
|---|---|---|---|---|---|---|
| CryptoWall | 5.59 | 5.40 | 6.22 | 7.89 | 5.56 | 5.33 |
| CryptoLocker | 5.37 | 4.87 | 6.22 | 7.96 | 4.87 | 4.99 |
| WannaCry | 5.16 | 4.88 | 5.83 | 7.75 | 5.30 | 5.28 |
| CTBLocker | 5.11 | 4.36 | 5.88 | 7.98 | 5.01 | 5.12 |
| TorrentLocker | 4.67 | 4.66 | 5.18 | 7.74 | 5.25 | 5.01 |
| Cerber | 4.45 | 4.10 | 6.00 | 7.90 | 4.11 | 4.92 |
| Petya | 4.03 | 3.70 | 5.58 | 8.19 | 4.31 | 4.65 |
| Locky | 4.01 | 3.97 | 5.44 | 7.65 | 4.57 | 4.94 |
| Mean | 4.80 | 4.49 | 5.79 | 7.88 | 4.87 | 5.03 |
| Ransomware | WTP | Trust | Fast | Angry | Helpful | Positivity |
|---|---|---|---|---|---|---|
| CryptoWall | 3.13 | 3.39 | 3.41 | 5.34 | 3.12 | 3.62 |
| CryptoLocker | 3.18 | 3.86 | 3.17 | 3.99 | 4.11 | 3.88 |
| WannaCry | 3.34 | 3.22 | 3.09 | 4.14 | 3.06 | 3.55 |
| CTBLocker | 4.30 | 4.82 | 4.60 | 3.79 | 4.65 | 4.90 |
| TorrentLocker | 4.52 | 3.82 | 5.23 | 5.35 | 3.51 | 3.94 |
| Cerber | 5.09 | 5.27 | 4.15 | 4.06 | 5.80 | 4.90 |
| Locky | 6.02 | 5.70 | 6.19 | 4.78 | 5.69 | 5.32 |
| Petya | 6.42 | 5.92 | 6.15 | 4.55 | 6.07 | 5.89 |
| Observations | 88 | 88 | 86 | 85 | 89 | 82 |
| (1) | (2) | (3) | (4) | (5) | (6) | |
|---|---|---|---|---|---|---|
| Dependent var. | WTP | Trust | Fast | Anger | Helpful | Positivity |
| Trust | 0.531 *** | 0.00364 | −0.0735 | 0.241 *** | 0.108 | |
| (0.0757) | (0.0809) | (0.0688) | (0.0728) | (0.103) | ||
| Fast | 0.0196 | 0.00216 | −0.148 ** | 0.00285 | 0.0914 | |
| (0.0767) | (0.0480) | (0.0693) | (0.0800) | (0.0857) | ||
| Anger | 0.116 | −0.0626 | −0.212 ** | −0.0845 | −0.0483 | |
| (0.0776) | (0.0601) | (0.0837) | (0.0799) | (0.0929) | ||
| Helpful | 0.129 * | 0.144 *** | 0.00288 | −0.0596 | −0.00161 | |
| (0.0771) | (0.0437) | (0.0809) | (0.0539) | (0.0792) | ||
| Positivity | 0.241 *** | 0.0658 | 0.0939 | −0.0345 | −0.00164 | |
| (0.0869) | (0.0599) | (0.0890) | (0.0672) | (0.0804) | ||
| WTP | 0.402 *** | 0.0250 | 0.103 | 0.162 * | 0.299 *** | |
| (0.0563) | (0.0976) | (0.0691) | (0.0899) | (0.101) | ||
| Constant | −0.448 | 2.000 *** | 6.846 *** | 9.04 5*** | 3.673 *** | 2.975 *** |
| (0.817) | (0.570) | (0.852) | (0.419) | (0.933) | (0.862) | |
| Observations | 738 | 738 | 738 | 738 | 738 | 738 |
| R−squared | 0.370 | 0.334 | 0.046 | 0.049 | 0.120 | 0.152 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Cartwright, E.; Cartwright, A.; Xue, L. Ransomware Splash Screens, Loss Aversion and Trust: Insights from Behavioral Economics. J. Cybersecur. Priv. 2025, 5, 69. https://doi.org/10.3390/jcp5030069
Cartwright E, Cartwright A, Xue L. Ransomware Splash Screens, Loss Aversion and Trust: Insights from Behavioral Economics. Journal of Cybersecurity and Privacy. 2025; 5(3):69. https://doi.org/10.3390/jcp5030069
Chicago/Turabian StyleCartwright, Edward, Anna Cartwright, and Lian Xue. 2025. "Ransomware Splash Screens, Loss Aversion and Trust: Insights from Behavioral Economics" Journal of Cybersecurity and Privacy 5, no. 3: 69. https://doi.org/10.3390/jcp5030069
APA StyleCartwright, E., Cartwright, A., & Xue, L. (2025). Ransomware Splash Screens, Loss Aversion and Trust: Insights from Behavioral Economics. Journal of Cybersecurity and Privacy, 5(3), 69. https://doi.org/10.3390/jcp5030069

