The ransom note is typically sent to the common group email aliases of the company—i.e. noc@, support@, help@, legal@, abuse@, etc. In several cases, it has ended up in spam.
You can view a sample of the whole ransom note
here. You can also view the FBI report
here.
What to do if you receive a threat:
-
Do not panic and do not pay the ransom: Paying ransom only encourages bad actors—and there's no guarantee that they won't attack your network now or later.
-
Notify local law enforcement: They will also likely request a copy of the ransom letter that you received.