Skip to contentExploitQuest

Lesson 1 of 1 in Exfiltration And Extortion

What They Do With It

Stolen data is only worth the leverage it buys. Attackers sell it, ransom it, or do both at once — encrypt your copy and threaten to publish theirs. The defences aim at the leverage itself: make the theft not pay.

3 min read

Not yet reviewed

Wrenlearner

They have the data. That is the end — game over.

Magpieadversary

The data is not the point. The *leverage* is. I can sell it, I can lock your copy and charge you to get it back, or I can do both — take a copy, encrypt yours, and threaten to publish unless you pay. Two hostages from one theft.

Rookmentor

Which tells you where the defence lives. Not in the theft, which you may not even see — in making the theft worth nothing.

One theft, two hostages

For years ransomware simply encrypted your files and sold you the key. Then attackers noticed that a victim with good backups could restore and refuse to pay — so they added a second hostage. Now they steal a copy *before* they encrypt, and the threat is no longer only "you cannot get your data back" but "everyone will see it". This is double extortion, and it changed the defensive question.

Single extortion

Encrypt the victim's files.
Sell the decryption key.
Good backups defeat it.

Double extortion

Steal a copy first, then encrypt.
Threaten to publish if unpaid.
Backups restore the files — not the secrecy.

Backups still matter enormously, but double extortion is why they are no longer the whole answer. Once data has left, you cannot un-leak it — which moves weight onto stopping and detecting the theft, and onto not holding data you did not need to keep.

Making the theft not pay

The defences target the payday from several sides at once: keep tested, offline backups so encryption loses its grip on your operations, encrypt data at rest so a stolen copy is unreadable, watch what leaves your network because large or strange outbound transfers are the theft in progress, and hold less data for less time so there is less to steal. Behind all of it sits a plan written before the bad day, not during it.

Tested offline backups   restore without paying — and test the restore
Encryption at rest        a stolen copy is unreadable noise
Egress monitoring         large odd transfers are the theft, live
Data minimisation         what you never kept cannot be stolen
An incident plan          decisions made calm, not under a countdown
  1. Line 1"Tested" is the whole word. A backup nobody has ever restored from is a hope, not a backup, and the ransom note is a bad time to find out.
  2. Line 4The cheapest data to protect is the data you deleted. Every record you keep past its usefulness is inventory for the attacker.

A company hit by double-extortion ransomware has perfect, tested backups. Should they pay?

One thing you can do this week: test a backup. Pick something that matters — your photos, your documents — and actually restore it somewhere fresh to prove the backup works. A backup you have restored from is the single thing that turns "pay or lose everything" back into merely "a very bad week".