Resource icon

Ransomware double extortion: when backups solve only half the problem

In double extortion, a ransomware actor both disrupts access to files and threatens to publish or sell data it claims to have copied. A working backup can help restore encrypted files, but it cannot retrieve copies already taken by an attacker. The threat in a note is a claim until evidence is assessed.

A useful example​

A business restores its systems from clean backups, yet the attacker posts samples of customer records. Recovery now includes investigating what was copied, protecting affected people and meeting any applicable reporting duties, not just restoring computers.

What to do​

Preserve the note and evidence, isolate affected systems and involve qualified responders. Avoid assuming that payment guarantees deletion; it cannot verify every copy. CISA's ransomware guide covers incident response. Our first-hour checklist separates containment from later recovery.

Practical distinction​

An attacker may claim to have copied files without showing proof. Responders should investigate the evidence and scope; neither a ransom note nor a restored backup settles the data-exposure question.
Posted by
Jack
Views
2
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack