Double extortion ransomware is an attack in which criminals steal your data, encrypt your systems, and then demand payment twice: once for the decryption key and once to keep the stolen files private. It is now the default playbook for most ransomware groups, which is why restoring from backups no longer ends an incident.
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
What Is Double Extortion Ransomware?
Double extortion ransomware combines data theft with file encryption, giving attackers two separate pieces of leverage. The victim loses access to systems and also faces the public release of sensitive information.
Double Extortion Definition in Plain English
Double extortion ransomware is an attack in which criminals copy your data out of your network, lock your systems with encryption, and threaten you on two fronts: lock-out and leak. If you restore from backups and refuse to pay, the attackers threaten to publish the stolen data on leak sites. Encryption creates operational pressure, and stolen data creates legal, financial, and reputational pressure that survives even a clean recovery.
How CISA Defines Double Extortion Ransomware
CISA’s #StopRansomware advisories describe double extortion as a model where actors take sensitive data before encryption and threaten to publish it on a leak site unless the ransom is paid. Its August 2026 advisory on the Gunra ransomware, based on FBI observations, describes exactly this pattern. Two elements define the term: exfiltration happens before encryption, and public disclosure is the stated consequence of non-payment.
Double Extortion vs. Single Extortion Ransomware
Single extortion ransomware relies only on encryption, so its leverage is lost access to systems. A victim with clean, tested backups can often recover without paying. Double extortion adds a confidentiality threat that backups cannot remove. Even a fully restored company still has to decide what to do about stolen customer records, contracts, or health data.
Why Attackers Moved Beyond Encryption-Only Attacks
Attackers added data theft because victims got better at recovering and refusing to pay. Verizon’s 2025 DBIR found that 64% of ransomware victims did not pay, up from 50% two years earlier. Groups such as Maze popularized this approach in 2019 by publishing stolen files from victims who refused to pay. Threat intelligence firm Analyst1 traces the same path: encryption-only attacks expanded to include data theft, which in turn made public leak sites standard.
How a Double Extortion Ransomware Attack Works, Step by Step
A double extortion attack moves through five stages: gaining access, spreading through the network, stealing data, encrypting systems, and applying pressure. Encryption is the last technical step, not the first.
Initial Access and Lateral Movement
Attackers usually enter through an unpatched internet-facing system or stolen credentials. Verizon’s 2026 DBIR reports that vulnerability exploitation now drives 31% of breaches, passing stolen credentials for the first time in 19 years. Many groups simply buy credentials harvested by infostealer malware, and days to weeks can pass between the theft and the ransomware deployment. Once inside, operators typically work by hand, leaning heavily on legitimate built-in tools (living-off-the-land binaries) to escalate privileges and locate file servers, databases, and backup systems.
Data Exfiltration Before Encryption
Data theft comes first because encryption is the noisy step that alerts defenders. Operators identify the most sensitive material, such as financial records, customer data, contracts, and source code, and copy it to attacker-controlled storage. In the Osiris case, attackers used Rclone to move data into Wasabi cloud buckets before encrypting anything.
File Encryption and the Ransom Note
With data secured, the attackers deploy the encryptor across as many systems as possible. Osiris, for example, stops SQL, Exchange, and backup services and deletes Volume Shadow Copy snapshots to prevent easy recovery. The ransom note then arrives, and in the Osiris case, it detailed the data the attackers claimed to have stolen and linked to a chat for negotiation.
The Dual Threat: Pay to Decrypt and Pay to Prevent Leaks
The victim is pushed to pay for a decryption key and for a promise that stolen data will be deleted. That second promise is unverifiable. Coveware describes a June 2026 case in which the Icarus group compromised Klue. After a payment was reportedly made to guarantee deletion, a separate criminal group turned out to have kept victim names and data samples, leaving victims exposed to further extortion.
Publication on Ransomware Leak Sites
If negotiations stall, the group names the victim on its data leak site, posts a preview of the stolen files, and eventually releases the rest. Gunra actors publicly disclose non-paying victims on their leak site and offer a preview of the leaked data. Check Point’s Q2 2026 report counts 2,139 organizations listed on leak sites in that quarter alone.
Double Extortion Tactics and Techniques
Double extortion tactics center on quiet data theft followed by escalating public pressure. The techniques below recur across most active groups.
Common Exfiltration Methods and Staging
Attackers commonly stage data on a compromised server and push it to cloud storage using legitimate transfer tools. Trigona affiliates have used the open-source Rclone tool to send victim files to the cloud service pCloud and, in March 2026, began using a Custom uploader tool for exfiltration. Because these tools are legitimate, the traffic often resembles normal backup or sync activity.
Leak Sites and Victim Shaming
A leak site is the public stage for the second extortion threat. BlackCat’s innovation was posting excerpts of victim data on a site reachable from an ordinary web browser, rather than only on the dark web. Trigona’s site went further, pairing a countdown timer with bidding options for parties interested in buying the leaked data. Leak sites are also resilient. Gunra moved its site to a new .onion address in March 2026.
Pressure Tactics (Deadlines, Countdown Timers, Sample Data Drops)
Pressure is engineered through time and proof. Newly listed Trigona victims carried a “Preview” status and a timer counting down to the data release. The Kairos group builds its model on time-bound escalation and posts negotiation guidelines that spell out demands, deadlines, and its escalation process. Sample data drops prove the theft is real and give the victim a concrete view of what will be exposed.
Negotiation Behavior of Ransomware Groups
Negotiation usually happens in a Tor-based chat portal, and the first demand is rarely the final price. Gunra, for instance, demands payment through a Custom Tor negotiation portal. One analysis of Coveware data found that actual payments average about 8.7% of the initial demand. Treat any figure as a range, since group behavior varies widely.
From Double to Triple Extortion (and Data-Theft-Only Extortionware)
Triple extortion adds a third pressure lever to encryption and data leaks, while extortionware drops encryption entirely and relies on theft alone. Both grew out of the double extortion model.
What Is Triple Extortion Ransomware?
Triple extortion ransomware layers an additional threat on top of encryption and the leak threat. The most common third lever is a distributed denial-of-service attack. The group behind BlackCat mostly used double extortion but sometimes added DDoS threats against victims’ infrastructure.
Added Pressure Layers: DDoS, Customer and Partner Outreach
Beyond DDoS, attackers contact the victim’s customers, partners, employees, or executives directly, making the victim’s stakeholders the pressure point. In a July 2026 campaign attributed to Cl0p, victims received emails warning of a serious data leak. The tactic shifts the decision from the security team to the boardroom and the customer base.
Extortionware: Extortion Without Encryption
Extortionware, also called encryption-less or data-theft-only extortion, skips the encryptor and monetizes stolen data alone. Insomnia appeared in October 2025 as a data-theft-only operation with no encryptor, no negotiation portal, and no affiliate program, and had over 30 claimed victims through late April 2026. Coinbase Cartel presented itself as a data-exfiltration-only group and distanced itself from traditional ransomware. Coveware reports the payment rate for exfiltration-only cases fell to a historic low of 15% in Q2 2026.
Double and Triple Extortion Compared
Double extortion has two levers: encrypted systems and a data-leak threat. Triple extortion keeps both and adds a third, such as DDoS or direct pressure on customers and partners. Extortionware removes encryption and leaves only the data threat. The more levers an attacker holds, the less any single defense, whether backups, DDoS protection, or legal preparation, can neutralize the attack alone.
Double Extortion vs. Cyber Extortion vs. Traditional Ransomware
Cyber extortion is the umbrella term for any attack that demands payment under threat; ransomware is one form, and double extortion is ransomware that also steals data. The differences determine which defenses actually help.
Is Ransomware a Type of Cyber Extortion?
Yes. Ransomware is a subset of cyber extortion. The industry itself blurs the line: Verizon’s DBIR counts both traditional encrypting ransomware and pure non-encrypting extortion in its ransomware figures. That matters when you compare statistics across reports, because definitions vary.
Comparison Table: Encryption, Data Theft, Leak Threat, Recovery Options
| Vector / Feature | Traditional Ransomware | Double Extortion Ransomware | Data-Theft-Only Extortion |
|---|---|---|---|
| Files encrypted | Yes | Yes | No |
| Data stolen | Not necessarily | Yes, before encryption | Yes |
| Leak threat | No | Yes | Yes (the only lever) |
| Restoring from backup solves it | Mostly | Only the outage, not the leak | Not applicable |
| Main defensive priority | Backups and recovery | Prevent intrusion and exfiltration, plus recovery | Prevent intrusion and exfiltration |
Why Backups Alone No Longer Solve the Problem
Backups restore availability, not confidentiality. As one analysis of the Insomnia group put it, backup and disaster recovery, the traditional ransomware defense, has no relevance when the threat is exfiltration. Payment does not fix it either: Coveware notes there is no reliable way to know whether stolen data will actually be deleted.
Real-World Double Extortion Attack Examples
Double extortion ransomware examples range from the model’s 2019 origins to groups active today. Each case shows a slightly different way the model is used.
Where It Began: Early Adopters of the Model
Maze is widely credited with popularizing double extortion in late 2019, when it published data from a victim that refused to pay. Other groups copied the approach quickly. Zscaler counted 19 ransomware families using double or multi-extortion approaches by 2021.
Colonial Pipeline and DarkSide
In May 2021, the DarkSide group attacked Colonial Pipeline, halting the pipeline’s operations for about six days and reportedly stealing roughly 100 GB of data first. Colonial paid about $4.4 million, and the FBI later recovered part of it. The case showed that double extortion could disrupt critical infrastructure and prompted a sharp US government response.
Recent Groups Using Double Extortion (Trigona, Osiris, Tengu, Insomnia, VolkLocker)
Trigona, Osiris, and Tengu are recent double extortion operators, while Insomnia and VolkLocker show variations on the model.
- Trigona: A ransomware-as-a-service group that emerged in 2022. It kept operating after Ukrainian hacktivists wiped its original leak site in October 2023.
- Osiris: First seen in a November 2025 attack on a Southeast Asian food service franchisee, with signs of a link to Inc ransomware. It steals data with Rclone before encrypting.
- Tengu: A hands-on-keyboard, double extortion RaaS that surfaced in October 2025 and had nearly 50 claimed victims by mid-2026.
- Insomnia: A data-theft-only group (see above), a contrast to true double extortion.
- VolkLocker: A RaaS operation first identified in August 2025 and run by the pro-Russian hacktivist group CyberVolk, with cross-platform Windows and Linux encryptors. Public sources say little about its leak practices, so treat any RaaS family as a data-theft risk.
Lessons From Each Case
Maze showed that refusing to pay no longer ends the story. DarkSide showed that the stakes reach operations and supply chains, not just data. Trigona shows that taking down a leak site does not end the operation. Osiris shows that established tradecraft moves between groups. Insomnia shows that encryption is now optional. The common lesson is to defend against theft, not just lock-out.
Double Extortion Ransomware Statistics and Trends (2024-2026)
Ransomware is present in nearly half of all breaches, and leak-site victim counts reached record levels in 2026 even as fewer victims chose to pay.
Prevalence and Growth
Verizon’s 2026 DBIR found ransomware in 48% of breaches, up from 44% in 2025 and 32% in 2024. In the 2025 edition, small and medium businesses saw ransomware in 88% of their breaches, compared with 39% at larger organizations.
Most Targeted Industries
Manufacturing leads most months. Breachsense recorded manufacturing as the most targeted sector in January 2026 with 57 victims, and the US accounted for 48.6% of all victims. In March, construction ranked second with 53 victims, and finance recorded 48. Coveware finds that companies with 11 to 10,000 employees accounted for 75.8% of its Q2 2026 cases.
Leak-Site Victim Volume
Black Kite tracked 7,551 publicly disclosed victims between April 2025 and March 2026, with second-half volume running 60% above the first half. Active groups grew to 146 by June 2026, more than double the 61 counted in 2023. July 2026 recorded 873 claimed victims, up from 722 in June. Payment behavior is diverging: Coveware’s Q2 2026 average payment jumped 176% to $1.88 million while the median fell to $150,000, and payment rates hit a record low.
The Business Impact of Double Extortion Attacks
A double extortion attack creates regulatory, reputational, and financial damage that outlasts the technical recovery. The leak risk is what separates it from an ordinary outage.
Data Breach Notification and Regulatory Exposure
Once data is stolen, the incident is a data breach regardless of whether systems are restored. That can trigger notification duties to regulators and affected individuals, such as the GDPR’s 72-hour deadline and various US state and sector rules. Public companies may also face securities disclosure requirements. Legal counsel should be involved early, because timelines start from awareness of the breach, not from the ransom note.
Reputational and Customer Trust Damage
Leaked data cannot be recalled. Once patient health information is posted on a leak site, the consequences are irreversible. Customers, partners, and employees may learn about the breach from the attacker’s site before hearing from you, which is why prepared communications matter.
Financial and Operational Costs
Ransom demands are only part of the cost. Incident response, legal fees, downtime, notification and monitoring services, and lost business often exceed the payment. Large cases can be severe: UnitedHealth’s payment following the Change Healthcare attack was reported at $22 million.
How to Detect Double Extortion Activity
The best detection window is before encryption, during the days or weeks when attackers move through the network and stage data.
Early Warning Signs Before Encryption
Watch for new privileged accounts, disabled security tools, unexpected remote-access software, and unusual use of administrative tools. Osiris used a Custom driver to turn off security software. Credential exposure in infostealer logs is another early signal, since a gap of days to weeks often separates credential theft from deployment.
Exfiltration Indicators in Network Traffic
Look for large outbound transfers from servers that rarely send data, connections to cloud storage services you do not use, and file-transfer tools such as Rclone appearing on systems. Off-hours transfers and archive files staged on file servers are common signs. Egress monitoring and data loss prevention alerts are the main controls here.
Leak-Site and Dark Web Monitoring for Your Data
Monitoring leak sites and dark web forums tells you when your name, domain, or credentials appear, sometimes before the attacker contacts you. Verify each claim before acting: Breachsense removed fake claims from a group called 0APT from its February 2026 data, and leak-site listings are attacker assertions that may be recycled, exaggerated, or fabricated.
How to Prevent and Defend Against Double Extortion Ransomware
Effective defense against double extortion has to stop the intrusion, limit what can be stolen, and keep recovery options ready. No single control covers all three.
Reduce the Attack Surface (MFA, Patching, Segmentation)
Require phishing-resistant multi-factor authentication, especially on remote access and email. Patch internet-facing systems fast: Verizon’s 2026 DBIR puts the median time to resolve a critical vulnerability at 43 days. Segment networks so one compromised account cannot reach every file server.
Limit Exfiltration (Egress Controls, DLP, Least Privilege)
Restrict outbound traffic to approved destinations, block or alert on unsanctioned cloud storage and transfer tools, and apply least-privilege access so a stolen account exposes less. Classify and minimize sensitive data. Data you no longer keep cannot be leaked.
Backups and Recovery Planning
Keep immutable or offline backups and test restores regularly. Backups remain essential because they shorten downtime and reduce the leverage of the encryption threat. Pair them with an incident response plan that assumes data theft has occurred, since recovery alone does not address the leak threat.
Security Awareness and Tabletop Exercises
Train staff on phishing and phone-based social engineering. Coveware attributes the Silent Ransom group’s large law-firm payments to high-touch social engineering. Run tabletop exercises that include a leak-site scenario, so leadership has already decided how to handle notification, communications, and payment questions before a real incident.
What to Do If A Double Extortion Attack hits you
Contain the attack, preserve evidence, bring in incident response and legal support, and treat the data theft as a breach from the start.
Immediate Containment Steps
Isolate affected systems from the network rather than powering them off or wiping them, so forensic evidence survives. Disable compromised accounts, block known attacker infrastructure, and protect clean backups. Engage an incident response firm and legal counsel immediately, and use out-of-band communication in case email is compromised.
Reporting to CISA and Law Enforcement
Report the incident to the FBI through ic3.gov or your local field office, and to CISA through cisa.gov/report. Reporting helps investigators link campaigns, may unlock decryption keys or recovery help, and is often expected by cyber insurers and regulators.
To Pay or Not to Pay: The Considerations
US authorities discourage paying, and payment guarantees neither a working decryptor nor deletion of stolen data. Verizon’s 2026 DBIR reports that 69% of victims refused to pay. Consider legal risk, including sanctions exposure, restoration capability, the sensitivity of the stolen data, and the Klue case above, where a payment did not end the exposure. Leadership, counsel, and your incident response team should decide.
Communicating With Customers, Regulators and Staff
Decide who needs to hear what, and in what order, before the attacker decides for you. Notify regulators within the applicable deadlines, inform affected individuals with clear guidance on protecting themselves, and give employees a single point of contact. Factual, timely disclosure usually costs less in trust than being outed by a leak site.
Frequently Asked Questions (FAQ)
What is a double extortion attack?
A double extortion attack is a ransomware attack where criminals steal sensitive data before encrypting systems, then demand payment both to unlock the files and to prevent the data from being published. The two threats apply pressure independently, so fixing one does not end the attack.
What does double extortion mean in ransomware?
In ransomware, double extortion means the attacker extorts the victim twice using two different threats: loss of access through encryption, and exposure of stolen data through leak sites. The term distinguishes these attacks from older encryption-only ransomware.
How is double extortion different from triple extortion?
Double extortion combines encryption with a data-leak threat. Triple extortion adds a third lever, such as a DDoS attack or direct pressure on the victim’s customers and partners. The additional layer makes it harder for any one defense to neutralize the attack.
Is cyber extortion the same as ransomware?
No. Cyber extortion is the broader category covering any attack that demands payment under threat, including data-theft-only extortion and DDoS threats. Ransomware is one type of cyber extortion, and double extortion ransomware is a type of ransomware that also steals data.
Can backups protect against double extortion?
Backups protect against the encryption half of the attack by letting you restore systems without paying for a key. They do not stop attackers from leaking stolen data, so backups must be paired with controls that prevent intrusion and exfiltration, plus a plan for handling a data breach.
What is an example of double extortion ransomware?
The DarkSide attack on Colonial Pipeline in 2021 is a well-known example, as are more recent operations like Trigona, Osiris, and Tengu. Each steals data before encrypting it and threatens to publish it on a leak site if the victim doesn’t pay.
Article Link: Double Extortion Ransomware | How It Works & Defense (2026)