Double Extortion Ransomware: Understanding The Threat Backups Can't Solve

Key Takeaways:

  • Backups don't stop a data breach: Double extortion means threat actors steal your data before encrypting it. Backups help you recover systems, but they don’t undo data theft.

  • Over 95% of ransomware attacks now involve exfiltration: Data theft has become the standard playbook, not an added risk.

  • The regulatory clock starts immediately: Once your data is stolen, you’re required to notify regulators, and you’re legally liable regardless of whether you pay the ransom.

  • Detection is the only real defense: Backups are important for recovery, but reducing double extortion risk depends on earlier visibility, fast response, and stronger security controls.

In a double extortion attack, threat actors steal your data before they encrypt it. That means restoring from data backups doesn't undo the damage. Your backup ran last night, but your data left the network three days ago. Stolen client files, confidential records, and sensitive business data are already on an attacker's server, ready to be published or sold.

For IT and technology leaders, a confirmed data breach causes mandatory notifications, regulatory fines, and reputational damage that no backup plan can address. In this article, we'll discuss what double extortion ransomware is, the risks to businesses, and how to catch an attack before encryption runs.

Topics
Share

Double Extortion Ransomware: Understanding The Threat Backups Can't Solve

Key Takeaways:

  • Backups don't stop a data breach: Double extortion means threat actors steal your data before encrypting it. Backups help you recover systems, but they don’t undo data theft.

  • Over 95% of ransomware attacks now involve exfiltration: Data theft has become the standard playbook, not an added risk.

  • The regulatory clock starts immediately: Once your data is stolen, you’re required to notify regulators, and you’re legally liable regardless of whether you pay the ransom.

  • Detection is the only real defense: Backups are important for recovery, but reducing double extortion risk depends on earlier visibility, fast response, and stronger security controls.

In a double extortion attack, threat actors steal your data before they encrypt it. That means restoring from data backups doesn't undo the damage. Your backup ran last night, but your data left the network three days ago. Stolen client files, confidential records, and sensitive business data are already on an attacker's server, ready to be published or sold.

For IT and technology leaders, a confirmed data breach causes mandatory notifications, regulatory fines, and reputational damage that no backup plan can address. In this article, we'll discuss what double extortion ransomware is, the risks to businesses, and how to catch an attack before encryption runs.

What’s double extortion ransomware, & why is it a dominant tactic?

Ransomware is malware that encrypts a victim's systems and demands payment for the decryption key. For years, backups were the primary defense: Restore your systems and walk away without paying.

That stopped working when threat actors started taking data before encrypting it. This tactic is called double extortion.

Double extortion is a type of ransomware attack that hits organizations with two problems at once: stolen data and locked systems. Threat actors steal sensitive information first, then deploy ransomware to extort payment.

Even organizations that recover their systems from backups still face exposure. Stolen data is at risk of being published, sold, or used for further extortion, regardless of whether the organization pays the ransom. The Maze ransomware group pioneered this approach in 2019, publicly leaking data from victims who refused to pay.

The tactic spread quickly because it works. Backups no longer neutralize the threat, so more victims pay. Today, double extortion has become the dominant ransomware attack model. According to BlackFog’s 2025 Q3 Ransomware Report, 96% of ransomware attacks involve double extortion.

How double extortion attacks unfold from access to exfiltration

Double-extortion attacks usually follow a similar pattern, and there are multiple points to spot these attacks before encryption runs.

Most attacks start with phishing emails, stolen credentials, or exploited vulnerabilities. Once inside, threat actors conduct recon to map the network and spot information worth stealing, like financial records or intellectual property.

Data staging and exfiltration come next. Attackers compress and transfer data to external storage using a tool like Rclone, which shows up in 57% of ransomware exfiltration incidents, according to research from ReliaQuest.

Once the data is in their hands, cybercriminals encrypt it and shift to extortion tactics. Now they're holding two kinds of leverage, and the clock is ticking.

Multi extortion ransomware and triple extortion: The escalating threat

Some threat actors go even further. Triple extortion ransomware builds on the double extortion model, typically by threatening to launch DDoS attacks that disrupt the victim’s network, reach out directly to customers or partners whose data was stolen, or report the breach to regulators before the victim can. The aim is to make refusing to pay even more painful than complying.

Ransomware-as-a-service (RaaS) has made these tactics more viable. Groups like DragonForce and Akira make it easier for threat actors to run complex attacks without building their own infrastructure.


Extortion ransomware prevention: Detecting theft before encryption

Reducing ransomware impact means spotting attacker activity as early as possible and responding fast. In Huntress Managed EDR, Process Insights monitors suspicious process behavior on endpoints, Ransomware Canaries help detect malicious encryption activity, and Host Isolation can restrict network activity on infected endpoints while the Huntress SOC investigates and responds.

Mass file access is one of the clearest early indicators of data exfiltration—when an account or process suddenly reads far more files than normal, that pattern stands out. Large outbound transfers to a cloud service like Dropbox is another red flag, particularly when a tool like Rclone is present in the environment.

Threat actors rely on stolen credentials to move laterally across systems and access sensitive data. They then escalate privileges to access financial systems, HR platforms, and client databases. Unusual authentication patterns and repeated access attempts across systems all point to an active intrusion.


Why double extortion increases business risk beyond downtime

For IT and technology leaders, the risk doesn’t end when systems come back online. Stolen data creates liability that goes beyond the attack. A breach notification requirement doesn't go away just because you restored from backups. Neither does a regulatory investigation, a class-action lawsuit, or the damage to your reputation following a public announcement. Here are a few ways these attacks impact businesses.

Regulatory & legal consequences of data theft

When regulated data is involved, confirmed exfiltration triggers mandatory reporting obligations. Under the General Data Protection Regulation (GDPR), organizations in the EU generally have 72 hours to notify supervisory authorities after becoming aware of a qualifying personal data breach. Otherwise, they face fines of up to €20M or 4% of the firm’s annual revenue.

For breaches involving medical data, the Health Insurance Portability and Accountability Act (HIPAA) requires notification to the U.S. Department of Health and Human Services within 60 days. Failure to report results in fines, mandatory media reporting, and reputational damage.

Regulators assess penalties based on whether the organization had proper controls and governance in place, not on whether they paid the ransom or recovered the data. Legal liability follows the same logic. Class action lawsuits tied to data breaches are happening more often, with settlements running into the millions.

Paying the ransom doesn't eliminate this exposure, either. There’s no guarantee that threat actors will delete what they've stolen, and paying the ransom doesn’t erase a company’s duty to report the breach.


Real-world double extortion attacks & what they reveal

Below are a couple of case studies that show the negative consequences of double extortion attacks.

Change Healthcare: Paying the ransom wasn't enough

In early 2024, ALPHV/BlackCat used compromised credentials to access a Change Healthcare remote access portal with no multi-factor authentication (MFA). Days later, they deployed ransomware. UnitedHealth Group CEO Andrew Witty testified before Congress that the organization paid a $22M ransom. Despite that payment, stolen data later resurfaced with RansomHub, a RaaS group, which used it for a second extortion attempt. Public filings put the total cost in the billions of dollars.

Stolen credentials gave threat actors authenticated access to personal health information, insurance records, and financial data. Unusual authentication patterns and lateral movement during the dwell period were the warning signs, but without 24/7 endpoint visibility, they went unnoticed until encryption ran.

Qilin & Synnovis: When healthcare data becomes leverage

On June 3, 2024, the Qilin ransomware group attacked Synnovis, a pathology services provider for multiple NHS hospitals in London. According to Bleeping Computer, Qilin obtained admin credentials, moved through the network, and stole data before encrypting it.

Synnovis refused to pay the $50M ransom, and Qilin publicly published 400GB of stolen data. Over 1,100 elective surgeries were canceled in the first two weeks, and the disruption has since been linked to at least one patient death.

Credential abuse and lateral movement were the warning signs during the pre-encryption phase. Forensic investigators confirmed that threat actors moved through the environment, but they couldn’t determine how attackers got a hold of these credentials in the first place.


How organizations should respond to double extortion ransomware attacks

Organizations experiencing an attack must take steps to respond quickly and compliantly:

  • Isolate affected systems immediately: Disconnect compromised devices to stop movement and cut off active data theft.
  • Preserve logs before they're cleared: Threat actors routinely wipe evidence. Securing logs early helps your incident response team identify what data was stolen. With this information, they can meet reporting requirement timelines and figure out how threat actors got into your systems.
  • Develop response procedures: CISA’s Stop Ransomware Guide gives step-by-step response procedures worth having in place before an attack occurs.
  • Think carefully before paying: As Change Healthcare showed, paying doesn't guarantee deletion and can invite additional extortion.

How Huntress catches double extortion before encryption starts

By the time ransomware deploys, you've already lost the data. The real opportunity to stop a double extortion attack is earlier, when threat actors are still moving through your environment looking for what's worth stealing.

That’s where Huntress Managed Endpoint Detection and Response (EDR) steps in. Instead of waiting for known malware signatures, the Huntress Security Operations Center (SOC) analysts monitor endpoint telemetry from Managed EDR features like Process Insights, ransomware canaries, Host Isolation, and lateral movement focused detections to identify and contain active threats.

When those patterns show up, the Huntress 24/7 AI-assisted SOC is on it—with an industry-leading mean time to respond (MTTR) of eight minutes.

For organizations without a dedicated security team, that kind of response speed is the difference between stopping an attack during the dwell period and discovering it from a ransom note.


Stop double extortion before encryption runs

Backups solve one problem: They restore access. But they do nothing for data that’s already exfiltrated or sold. Regulatory fines, legal liability, and reputational damage don't go away when systems come back online. The only defense that matters is catching the attack before encryption runs.

For broader coverage, the Huntress Managed Security Platform also includes Managed ITDR for Microsoft 365 and Google Workspace, Managed SIEM, Managed Security Awareness Training, Managed ISPM, and Managed ESPM.

Explore Huntress Managed EDR to see how detection can stop threat actors in their tracks.

Frequently Asked Questions

Traditional ransomware attackers encrypt systems and demand payment for the decryption key. Double extortion adds a second step. Cybercriminals steal data, encrypt files, and threaten to publish them.

Triple extortion adds a third lever, typically a DDoS attack, direct contact with customers, or even a threat to report the victim to regulators. This gives threat actors more ways to pressure payment beyond threats to encrypt data and expose it publicly.

Managed EDR helps Huntress detect and respond to suspicious endpoint activity before or during ransomware execution. Product-documented examples include Process Insights for suspicious process behavior, Ransomware Canaries for malicious encryption signals, and Host Isolation to contain infected endpoints while the Huntress SOC investigates.


Protect What Matters

Secure endpoints, email, and employees with the power of our 24/7 SOC. Try Huntress for free and deploy in minutes to start fighting threats.
Try Huntress for Free