Double extortion is the standard model of today’s ransomware crime: before encrypting, the perpetrators steal large amounts of data. Blackmail then happens twice — ransom for decryption and additionally for refraining from publishing the stolen data.
The consequence is uncomfortable: a clean backup only neutralises the first extortion. Against the publication threat no restore helps — only preventing the data exfiltration itself.
How double extortion unfolds
After the break-in comes quiet collection first: the perpetrators move through the network, identify valuable data sets — contracts, HR data, finances, customer data — and exfiltrate them over weeks. Only then does encryption fire as the loud finale. Publication follows on leak portals with a countdown, sometimes augmented by pressure on customers and partners (triple extortion) or DDoS attacks on top.
Defence therefore means: make the quiet phase visible and limit it. Segmentation slows the spread, egress control and anomaly detection trigger on exfiltration, DLP marks sensitive holdings — and reporting processes (GDPR, NIS2) must be prepared, because a data leak is notifiable, ransom or not.
What counts against double extortion
- Limit spread: microsegmentation and least privilege shrink the loot.
- Detect exfiltration: unusual data movements and destinations alert before terabytes are gone.
- Know your crown jewels: if you do not know where sensitive data lives, you notice its theft last.
- Rehearse notification readiness: deadlines and communication paths stand before it gets serious.