Home  ›  Glossary  ›  Double Extortion Ransomware

What is double extortion ransomware?

Double extortion ransomware is an attack in which the attacker copies an organization's data out before encrypting it, then threatens to publish or sell the stolen files unless the ransom is paid. One intrusion produces two threats: an outage from the encryption and an exposure from the leak.

Theft first, then the leak-site countdown

The order suits the attacker. Encrypted files are worthless as leverage, and a large transfer is easier to finish before anyone is alerted, so the copying happens while the intrusion is still quiet. Attackers pick the data that hurts most in public: payroll and HR files, contracts, legal correspondence, customer records. It is usually compressed and sent to ordinary cloud storage or file transfer services, where the traffic blends in with normal business use, a step covered under data exfiltration.

Once the encryption has run, the ransom note refers to both the locked systems and the stolen files. If no payment arrives, the organization's name appears on the group's leak site, often with a countdown and a sample of documents to prove the theft is real. Some groups go on to email customers, partners or journalists directly. The tactic spread because restoring from backup had become a common way to refuse payment, and stolen data gives the attacker leverage that a restore leaves untouched.

Cyber extortion with no encryption at all

Cyber extortion is the broader category: any use of a digital attack, or a credible threat of one, to force a payment. Double extortion is one form of it. Several others skip encryption entirely:

  • Data theft alone: files are stolen and a publication threat follows, while production keeps running.
  • Service disruption: a denial-of-service attack on websites or internet links, with payment demanded to stop it.
  • Third-party pressure: customers, partners or the press are contacted to raise the cost of staying silent.

None of these is answered by a restore, because the stored data is either untouched or already outside. For leadership, legal counsel and the cyber insurer, the question moves from how fast systems come back to what was taken and who has to be told. Contact with the attacker, where it happens, is described under ransomware negotiation.

The backup repository as a source of stolen data

A backup repository holds years of file shares, mailboxes and databases in one place. Read access to it gives an attacker more than any single production server would, without touching production at all. Stolen backup console credentials or S3 keys therefore expose confidentiality as much as availability, and retention locks do not prevent a copy being read: S3 Object Lock governs deletion and overwrite and leaves reads to access permissions.

Two properties decide how serious that exposure is. Backups encrypted by the backup software, with keys kept away from the repository, are of little use to whoever copies them. Logs showing which identity read which objects establish what actually left, and that scope drives the notification duties. Under GDPR Article 33, the 72-hour clock for telling the supervisory authority about a personal data breach starts when the controller becomes aware of it, with an exception only where the breach is unlikely to put individuals at risk, and a completed restore does not stop that clock.

Clean backups still shift the negotiation: with encryption gone as leverage, the demand rests on the leak alone.

ARTESCA and double extortion ransomware

ARTESCA answers the encryption half of a double extortion attack and only part of the theft half. Compliance-mode S3 Object Lock keeps backup versions from being deleted or overwritten until their retain-until date, yet it sets no limit on who reads them. Read rights on ARTESCA follow account and key permissions that can be narrowed to specific buckets and actions, and audit logs record each request, which supplies the read history the leak question turns on.

Data that has already left the network is beyond the reach of any storage system, ARTESCA included.