Extortion Tactics

Double Extortion Ransomware: Data Theft Before Encryption

Modern ransomware no longer just encrypts — it exfiltrates first, then threatens publication. Double extortion is why backups alone no longer guarantee recovery.

Last updated October 2, 2026

Overview

Double extortion transformed ransomware from a pure availability problem into a confidentiality and regulatory crisis. In a double-extortion attack, the operator exfiltrates sensitive data before deploying the encryptor, then threatens to publish the stolen data on a leak site if the ransom is unpaid. Even organisations with perfect, tested offline backups face the prospect of public disclosure of customer records, financial data, and trade secrets.

First observed widely with Maze in late 2019, the tactic is now universal across RaaS operations. It shifted the negotiation leverage decisively toward attackers: a victim that can restore systems from backup still has to weigh the cost of a data-breach notification, regulatory fines (GDPR, HIPAA, state breach laws), and reputational damage against the ransom demand.

A further evolution — triple and quadruple extortion — adds DDoS attacks against the victim's public services and direct extortion of the individuals whose data was stolen (patients, customers). The defensive priority therefore expands beyond recovery to data minimisation, exfiltration detection, and network segmentation that limits what an attacker can stage and steal.

Key Points

Exfiltration precedes encryption

Attackers spend days staging and stealing data via tools like rclone, mega.io, or custom exfiltrators before any file is encrypted — making egress monitoring a critical detection.

Leak sites as enforcement

Tor-based leak sites publish stolen data on a schedule, applying public pressure and signalling to future victims that threats are carried out.

Backups are necessary, not sufficient

Recovery from backup restores availability but does not prevent the confidentiality breach; defenders must also detect and block exfiltration.

Regulatory amplification

Stolen personal data triggers mandatory breach notification, multiplying cost and creating legal exposure that extortionists explicitly exploit in negotiations.

Multi-layer extortion

Triple and quadruple variants add DDoS and direct victim contact, increasing pressure on organisations that might otherwise refuse to pay.

Latest Intelligence

Frequently Asked Questions

Defensive Intelligence

Encrygma produces defensive intelligence only. This analysis is derived from public reporting, government advisories, and OSINT — no exploit code or attack instructions.

Sovereign Defense Solutions
Weekly Briefing

Get the Weekly Cyberwarfare Briefing

State cyber operations, AI-powered attack campaigns, and offensive cyber industry developments — delivered to your inbox every week.

Defensive intelligence only. No spam — unsubscribe anytime.