Glossary
Double Extortion
Double extortion means even if you have backups, attackers threaten to leak your stolen data publicly. Pay to decrypt, AND pay to keep your data private. Having backups isn't enough anymore.
What is Double Extortion?
A ransomware tactic where attackers both encrypt data and steal it, threatening to publish stolen data if ransom is not paid.
Why Should You Care?
Double extortion fundamentally changes the calculus of ransomware defense because backup systems—the traditional mitigation—no longer fully neutralize attacker leverage. When data theft precedes encryption, organizations face regulatory notification obligations and compliance exposure regardless of whether they can restore systems from backups. Attackers count on this added pressure: even a victim that recovers cleanly still has to weigh the risk of stolen data being leaked or sold. This makes data governance and breach response capabilities as critical as system recovery.
Is your business exposed?
Real-World Example
Colonial Pipeline fell victim to DarkSide ransomware in May 2021, in an attack in which data was stolen before critical systems were encrypted. The incident disrupted fuel distribution across the southeastern US and forced the company to shut down operations and ultimately pay a ransom—not just to decrypt systems, but in the context of pressure that included the threat of exposing stolen data. It illustrates how the combination of operational disruption and data theft compounds the leverage attackers hold.
How to Protect Against Double Extortion
- 1.
Implement data loss prevention
- 2.
Monitor for unusual data transfers
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required