Join our Newsletter — 33% off our NHI Course

Why do ransomware campaigns increasingly include data breach extortion?

Ransomware operators add data theft because encryption alone is no longer enough to force payment. If an organisation can restore systems from backups, the attacker’s leverage drops. Extortion by disclosure raises pressure by threatening reputational damage, regulatory scrutiny, and customer trust loss. That combination increases the chance of payment and broadens the attacker’s profit model.

Why data theft changes the ransomware bargain

Modern ransomware is no longer just a denial of access event. Once attackers can steal data before encryption, they gain a second pressure point that works even when recovery is possible. That matters because many organisations now have better backups, better restoration playbooks, and stronger recovery tooling, which reduces the value of encryption alone as a coercion tactic.

data breach extortion also changes the attacker’s economics. Instead of betting only on downtime, the campaign can monetise confidentiality failure, legal exposure, and brand damage at the same time. In practice, that means the victim is being asked to pay not just to restore operations, but to avoid the consequences of public disclosure.

For visibility into how often stolen data and compromised credentials appear together in real cases, see NHIMG’s The 52 NHI breaches Report and the broader pattern in 52 NHI Breaches Analysis.

What makes double extortion effective in practice

Double extortion works because it widens the set of stakeholders who feel pressure. Operations teams care about service restoration, legal and privacy teams care about breach notification duties, executives care about reputation, and customer-facing teams care about trust loss. Attackers exploit that asymmetry by turning one technical incident into several business crises at once.

The tactic also reduces the defender’s ability to dismiss the event as a recoverable outage. If data has already left the environment, restoring from backups does not eliminate the disclosure risk. That is why campaigns increasingly pair encryption with exfiltration, selective leaks, and threats to publish samples to prove the theft is real.

Recent cases show how theft and extortion combine into a single pressure campaign, for example the GitLocker GitHub extortion campaign, the Salt Typhoon US telecoms breach, and the Co-op Group DragonForce Breach.

Risk and Threat Considerations

Data breach extortion increases both exposure and leverage. The main risk is not only file loss or downtime, but secondary harm from disclosure, including regulatory scrutiny, contractual fallout, customer churn, and long-tail reputational damage. Once attackers can prove possession of sensitive data, they can pressure the victim even if encryption is contained or recovery is fast.

Failure mechanism: The attacker steals data first, then uses encryption, leak threats, and deadline pressure to force payment. If backups, segmentation, or rapid restoration reduce the encryption impact, the disclosure threat becomes the remaining bargaining chip.

Impact: Organisations face a broader incident scope, with potential legal, privacy, and reputational consequences layered on top of operational disruption. That is why campaigns increasingly treat theft as part of the initial access and monetisation chain, not as an optional add-on.

A useful indicator of how mature this monetisation model has become is that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which gives intruders durable access paths for both theft and exfiltration.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1486 — Data Encrypted for Impact Ransomware still relies on encryption to create operational impact and pressure.
T1078 — Valid Accounts Campaigns often use stolen credentials to gain access before theft and extortion.
Recommendation — Map encryption activity to T1486 and hunt for impact-stage execution across affected hosts. Investigate valid-account abuse and revoke compromised access paths immediately.
CIS Controls v8 8 — Audit Log Management Extortion campaigns depend on weak visibility into data access and exfiltration.
13 — Network Monitoring and Defense Outbound transfer monitoring is essential for spotting exfiltration in double-extortion attacks.
6 — Access Control Management Attackers frequently rely on abused or overprivileged access to reach data for theft.
Recommendation — Centralise and retain logs needed to detect large-scale data theft before encryption. Deploy monitoring that flags unusual outbound volume, destinations, and transfer timing. Reduce exposed access paths and remove unnecessary privileges from high-value systems.
NIST CSF 2.0 DE.CM — Security Continuous Monitoring Continuous monitoring is needed to detect theft and extortion precursors in time.
RC.RP — Recovery Planning Recovery planning must account for theft-driven extortion, not just system restoration.
RS.MI — Mitigation Mitigation must reduce both encryption impact and the likelihood of successful exfiltration.
Recommendation — Monitor for anomalous access, movement, and data transfer linked to extortion activity. Test recovery plans against scenarios where data disclosure remains the attacker’s leverage. Prioritise controls that limit exfiltration paths and constrain blast radius during compromise.
NIST AI RMF GOVERN — Govern The threat combines operational, legal, and reputational risk that needs coordinated governance.
Recommendation — Assign ownership for breach-extortion decisions across security, legal, privacy, and executive teams.

Practitioner Guidance

What to prioritise: Treat exfiltration as a first-class control objective, not a post-encryption concern. If your recovery plan only measures restore time, you are missing the part of the campaign that often drives payment.

What to verify: Confirm whether high-value data paths are observable, whether large outbound transfers are detectable quickly, and whether incident response can distinguish encryption-only events from steal-and-leak events. If you cannot prove data movement, you cannot confidently judge extortion exposure.

What practitioners underestimate: The attacker does not need to leak everything to create leverage. A small but credible sample, especially from regulated or customer-facing data, can be enough to escalate pressure and widen the incident from technical recovery into executive crisis management.

Practitioner takeaway: The real shift is from ransom as recovery payment to ransom as confidentiality insurance, so the defence has to reduce both the ability to steal data and the value of a disclosure threat.