Ransomware & Incident Response
Double Extortion
Data is exfiltrated before encryption — paying the ransom no longer restores confidentiality.
What it is
Modern ransomware groups exfiltrate data during the dwell period before deploying encryption. This creates a second extortion lever: even organisations with clean backups face the threat of public data release. Following law enforcement disruptions of LockBit (Operation Cronos, February 2024) and ALPHV/BlackCat (March 2024), RansomHub emerged as the most prolific ransomware-as-a-service group in 2024–2025, alongside Cl0p, Play, and Akira — each operating leak sites publishing victim data from thousands of organisations.
Attack techniques
- Data exfiltration via Rclone / cloud sync (T1537)
- Exfiltration over C2 channel (T1041)
- Staged data collection (T1074)
- Use of legitimate cloud storage for staging
Business impact
Organisations that recover from backups still face regulatory notification obligations if data was exfiltrated. Clean backups do not prevent data breach consequences.