What’s double extortion ransomware, & why is it a dominant tactic?
Ransomware is malware that encrypts a victim's systems and demands payment for the decryption key. For years, backups were the primary defense: Restore your systems and walk away without paying.
That stopped working when threat actors started taking data before encrypting it. This tactic is called double extortion.
Double extortion is a type of ransomware attack that hits organizations with two problems at once: stolen data and locked systems. Threat actors steal sensitive information first, then deploy ransomware to extort payment.
Even organizations that recover their systems from backups still face exposure. Stolen data is at risk of being published, sold, or used for further extortion, regardless of whether the organization pays the ransom. The Maze ransomware group pioneered this approach in 2019, publicly leaking data from victims who refused to pay.
The tactic spread quickly because it works. Backups no longer neutralize the threat, so more victims pay. Today, double extortion has become the dominant ransomware attack model. According to BlackFog’s 2025 Q3 Ransomware Report, 96% of ransomware attacks involve double extortion.
How double extortion attacks unfold from access to exfiltration
Double-extortion attacks usually follow a similar pattern, and there are multiple points to spot these attacks before encryption runs.
Most attacks start with phishing emails, stolen credentials, or exploited vulnerabilities. Once inside, threat actors conduct recon to map the network and spot information worth stealing, like financial records or intellectual property.
Data staging and exfiltration come next. Attackers compress and transfer data to external storage using a tool like Rclone, which shows up in 57% of ransomware exfiltration incidents, according to research from ReliaQuest.
Once the data is in their hands, cybercriminals encrypt it and shift to extortion tactics. Now they're holding two kinds of leverage, and the clock is ticking.
Multi extortion ransomware and triple extortion: The escalating threat
Some threat actors go even further. Triple extortion ransomware builds on the double extortion model, typically by threatening to launch DDoS attacks that disrupt the victim’s network, reach out directly to customers or partners whose data was stolen, or report the breach to regulators before the victim can. The aim is to make refusing to pay even more painful than complying.
Ransomware-as-a-service (RaaS) has made these tactics more viable. Groups like DragonForce and Akira make it easier for threat actors to run complex attacks without building their own infrastructure.