Glossary · simply explained

Double extortion

Double extortion is the standard model of today’s ransomware crime: before encrypting, the perpetrators steal large amounts of data. Blackmail then happens twice — ransom for decryption and additionally for refraining from publishing the stolen data.

The consequence is uncomfortable: a clean backup only neutralises the first extortion. Against the publication threat no restore helps — only preventing the data exfiltration itself.

How double extortion unfolds

After the break-in comes quiet collection first: the perpetrators move through the network, identify valuable data sets — contracts, HR data, finances, customer data — and exfiltrate them over weeks. Only then does encryption fire as the loud finale. Publication follows on leak portals with a countdown, sometimes augmented by pressure on customers and partners (triple extortion) or DDoS attacks on top.

Defence therefore means: make the quiet phase visible and limit it. Segmentation slows the spread, egress control and anomaly detection trigger on exfiltration, DLP marks sensitive holdings — and reporting processes (GDPR, NIS2) must be prepared, because a data leak is notifiable, ransom or not.

What counts against double extortion

  • Limit spread: microsegmentation and least privilege shrink the loot.
  • Detect exfiltration: unusual data movements and destinations alert before terabytes are gone.
  • Know your crown jewels: if you do not know where sensitive data lives, you notice its theft last.
  • Rehearse notification readiness: deadlines and communication paths stand before it gets serious.

Frequently asked questions about Double extortion

Is a good backup enough against double extortion?

No — it only neutralises the encryption blackmail. The threat of publishing stolen data remains untouched. That is why exfiltration detection, segmentation and data classification belong alongside the backup strategy with equal weight.

Should you pay when publication is threatened?

Authorities advise against it, and experience supports that: there is no guarantee of deletion, data resurfaces despite payment, and payments finance the business model. Notification duties exist regardless — the decision belongs weighed with legal counsel and authorities.

What is triple extortion?

The extension by a third pressure stage: in addition to encryption and leak threat, affected parties are contacted directly — customers, patients, partners — or the victim is pressured with parallel DDoS attacks. The goal is maximum escalation of willingness to pay.

How do you detect exfiltration in time?

Through behaviour: unusual volumes towards unknown destinations, access to data sets outside normal patterns, compression and staging activity on servers. NDR, egress monitoring and DLP deliver these signals — if someone watches before the countdown runs.

Is a data leak notifiable even without payment?

As a rule, yes: for personal data, GDPR deadlines towards the supervisory authority and possibly data subjects apply; for important and essential entities, NIS2 reporting paths come on top. These duties exist independently of negotiations with the perpetrators.

Want to put this into practice in your own network? Talk to KAEMI, aligned to your requirements and with a managed service from a single source.