A ransomware technique combining data encryption with the threat of publication to increase pressure on the victim.
Double extortion is a tactical evolution of ransomware that emerged at scale around 2019 and 2020. To the classic pressure of encryption, which renders the victim's data inaccessible, the attacker adds the prior exfiltration of that data and the threat to publish it on a leak site if the ransom is not paid. The aim is to neutralize the company's first natural defense, its backups, since even a victim able to restore its systems remains exposed to the disclosure of confidential data, whether customer, employee or intellectual property. This technique changes the nature of the insurable loss, since it adds to remediation and business-interruption costs a liability risk linked to the data breach and to regulatory notification. Some groups have pushed the logic further toward triple extortion, adding denial-of-service attacks or directly contacting the victim's customers. For the insurer, double extortion blurs the line between cyber cover and liability cover, and reinforces the importance of affirmative cyber in contracts.
A hospital hit by ransomware sees not only its systems encrypted but also its patients' medical records threatened with publication, adding a data-protection liability risk to the loss.
double extorsion, double extortion