Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Double extortion ransomware combines two forms of pressure: attackers encrypt systems to disrupt access, then threaten to disclose, sell, or otherwise expose data they have stolen. Restoring files from backups can help with the encryption, but it cannot undo data theft. Not every ransomware incident uses both tactics.

What is double extortion ransomware?

Traditional ransomware encrypts files or systems and demands payment for a decryption key. In double extortion, attackers also steal information and threaten to leak or sell it if the victim does not pay. That creates pressure on both availability—whether the organization can use its systems—and confidentiality—whether its information remains private. CISA’s #StopRansomware Guide and the FBI’s description of the tactic explain these distinct sources of leverage.

The term describes a tactic, not a guarantee that every ransomware attack includes data theft. Some incidents involve encryption without a verified theft or leak threat; public claims about stolen data also may not be independently confirmed.

How does a double extortion attack work?

  1. Gain access. An attacker may exploit a vulnerability, use stolen credentials, or trick someone through social engineering. The FBI’s October 2019 alert discussed phishing and unauthorized Remote Desktop Protocol (RDP) access among observed infection methods; these are examples, not a complete list of current entry routes. FBI IC3 alert, October 2, 2019
  2. Explore the environment. After entering, the attacker may move through systems to find valuable information and important services.
  3. Copy data out and encrypt systems. Attackers may exfiltrate information before or around the time they encrypt files, disrupting the organization’s ability to work.
  4. Make demands. The ransom threat may combine a promise to restore access with threats to publish or sell stolen information, shame the victim publicly, or contact affected people.

The sequence can vary. The defining feature is the added threat of exposing stolen data, not a fixed order of operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did ransomware evolve to include data theft?

Ransomware’s development is better understood as a gradual change in tactics than as a single, uncontested invention. In October 2019, the FBI described ransomware as increasingly targeted, sophisticated, and costly. Later FBI remarks characterized double extortion as a tactic in which actors encrypt systems, steal data, and threaten to leak or sell it. Those accounts support an evolution over time, but do not establish one definitive first group or incident.

In testimony discussing FBI Internet Crime Complaint Center figures, the FBI reported a 20% increase in reported ransomware incidents and a 225% increase in reported ransom amounts in 2020. Those are historical comparisons for that year, not current global rates or measures specific to double extortion. FBI testimony, “America Under Cyber Siege”

What do the reported numbers show—and what do they not show?

Reported figure What it measures Important limit
About 1,000 leak-site claims per quarter in Q2 2024 ENISA’s observation of claims appearing on data leak sites during that quarter. These are public claims, not a verified census of attacks or proof that every claimed data theft occurred. ENISA says leak-site information does not show the full picture: victims who pay quickly may not be posted, and groups may exaggerate or fabricate claims. ENISA Threat Landscape 2024, September 2024
32% of breaches involved some type of extortion technique, including ransomware Verizon Business’s description of its 2023 Data Breach Investigations Report dataset, published in 2024. The report analyzed 30,458 security incidents and 10,626 confirmed breaches. This is a combined extortion measure, not a double-extortion rate. It should not be read as the share of ransomware incidents involving data theft. Verizon Business, May 1, 2024

Leak sites can provide a useful signal about what criminal groups claim to be doing, but they are not a reliable standalone measure of the total number of incidents. ENISA also notes that stolen information may be resold or used for repeat extortion.

Why backups do not end the threat

Backups can help restore encrypted files, but they do not make a stolen copy disappear or prevent its disclosure. That is why recovery planning must address both system availability and the possibility that sensitive information has been exposed. An external drive can serve as one offline backup medium, but it does not stop intrusion or data exfiltration; any backup approach should be isolated from production systems, access-controlled, tested through restoration, and sized for the organization’s recovery needs. CISA’s guide treats offline backups as one part of preparation and resilience, not a complete defense.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How organizations can reduce risk and limit impact

CISA’s joint guidance organizes ransomware readiness around preparation, prevention, mitigation, and response. Practical controls should work together rather than relying on any single safeguard:

  • Maintain protected offline backups. Keep copies separate from production access and test that systems and data can actually be restored.
  • Patch exposed and exploited systems promptly. Verizon’s 2024 report highlighted vulnerability exploitation and unpatched systems as important in its breach dataset; that finding does not make vulnerability exploitation the only route attackers use.
  • Harden identity and remote access. Protect accounts and remote services, and limit access to what users and systems need.
  • Limit lateral movement. Segment networks so an intruder has fewer paths from an initial foothold to critical systems and data.
  • Monitor for suspicious data movement. Detection of unusual transfers can help identify possible exfiltration, although monitoring cannot guarantee that theft will be prevented.
  • Prepare an incident response and recovery plan. Define responsibilities and recovery priorities before an incident, and coordinate response and reporting with appropriate authorities and qualified incident responders.

These measures support prevention and recovery; none can guarantee that an organization will avoid a breach or a disclosure threat. CISA’s #StopRansomware Guide provides the broader preparation, prevention, mitigation, and response framework.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.