Double Extortion
Technique where data is first exfiltrated, then encrypted for ransom.
Term
description · examples · notesTechnique where data is first exfiltrated, then encrypted for ransom.
Description
If the victim does not pay, public data release is threatened.
Adds pressure on victims who have backups and can restore files.
Requires infrastructure for storing and publishing stolen data.
Standard in modern ransomware operations since 2020.
Examples
- Maze group — pioneer of the double extortion model (2019)
- LockBit leak site for publishing victim data
Notes
- Evolution of ransomware; not a new threat but a new extortion technique.
Mentioned in the news
Threats
used by 2Threats that use it. Select one to open its page.
Defenses
countered by 4How it is countered. Select one to open its page.