166 terms · 75/46/45
Technique № 037 · class: exfiltration / impact

Double Extortion

Technique where data is first exfiltrated, then encrypted for ransom.

Term

description · examples · notes

Technique where data is first exfiltrated, then encrypted for ransom.

Description

If the victim does not pay, public data release is threatened.

Adds pressure on victims who have backups and can restore files.

Requires infrastructure for storing and publishing stolen data.

Standard in modern ransomware operations since 2020.

Examples

  • Maze group — pioneer of the double extortion model (2019)
  • LockBit leak site for publishing victim data

Notes

  • Evolution of ransomware; not a new threat but a new extortion technique.

Mentioned in the news

Composite

Threats

used by 2

Threats that use it. Select one to open its page.

Defenses

countered by 4