Double Extortion Ransomware: How It Works and 5 Defenses
- 8 minutes to read
Table of Contents
What Is Double Extortion Ransomware?
Double extortion ransomware is a cyberattack where threat actors both steal (exfiltrate) and encrypt sensitive data. By threatening to leak or sell the stolen files publicly on the dark web, attackers create two pressure points: operational disruption and reputational damage, compelling victims to pay even if they possess data backups.
Core attack workflow:
A standard double extortion incident follows these sequential stages:
- Initial access: Attackers penetrate the network using compromised credentials, malicious email attachments, or unpatched software vulnerabilities.
- Reconnaissance and privilege escalation: Threat actors spend days (or weeks) moving laterally across systems to identify highly valuable assets, proprietary intellectual property (IP), and PII.
- Data exfiltration: The targeted data is silently transferred out of the network via encrypted channels to attacker-controlled servers.
- Encryption and demand: Ransomware is deployed to lock the company’s systems. A ransom is demanded in cryptocurrency, accompanied by the threat of data exposure if payment is not met.
This is part of a series of articles about information security
Backups Are No Longer Enough
Traditional ransomware attacks could often be mitigated by restoring from backups. Double extortion reduces the effectiveness of this defense. Even if an organization restores encrypted files, attackers may still publish stolen data.
How to address:
Organizations must prevent data exfiltration, not just maintain backups. This requires broader security controls, including network monitoring and data loss prevention. The added complexity increases the burden on IT and security teams.
Regulatory Exposure
Double extortion often results in unauthorized disclosure of regulated data. This can trigger breach notifications under laws such as GDPR, HIPAA, or CCPA, leading to investigations and fines. Penalties for inadequate security controls or delayed reporting can exceed the ransom demand. Organizations may also face increased audits, oversight, and reputational harm.
How to address:
A defined incident response and legal strategy helps reduce impact and demonstrate due diligence.
Third-Party Pressure
These attacks often expose customer, partner, or vendor data. Third parties may take legal action or end business relationships. Data-sharing and privacy agreements are often violated during such incidents. Public disclosure can erode trust across the business ecosystem. Partners may require proof of improved controls or suspend contracts until issues are addressed. A single incident can disrupt supply chains and delay projects.
How to address:
Organizations should identify where sensitive third-party data resides, minimize unnecessary data sharing, and include breach response procedures in vendor risk management and contractual agreements.
Operational Disruption
Double extortion attacks aim to maximize disruption. Attackers often target critical systems or data repositories, halting production, interrupting services, or disabling core functions. Recovery and investigation can divert resources for extended periods. Organizations must also manage public communications and regulatory obligations. Indirect costs such as lost sales and customer churn can exceed the ransom.
How to address:
Organizations should maintain tested incident response, disaster recovery, and business continuity plans that enable rapid containment, system restoration, and continued operation during an attack.
Double Extortion vs. Traditional Ransomware
Traditional ransomware encrypts files and demands payment for a decryption key. With reliable backups, recovery may be possible without paying. Double extortion adds data theft and the threat of exposure. Even if data is restored, attackers can still extort victims by threatening to publish stolen information.
This shift has made ransomware more profitable. Organizations must consider data recovery, regulatory penalties, and legal risks. Attackers often publish proof of stolen data to increase pressure. Double extortion is now widely used and has changed how organizations prepare and respond.
Related content: Read our guide to ransomware as a service.
Tips from the expert

Steve Moore is Vice President and Chief Security Strategist at Exabeam, helping drive solutions for threat detection and advising customers on security programs and breach response. He is the host of the “The New CISO Podcast,” a Forbes Tech Council member, and Co-founder of TEN18 at Exabeam.
In my experience, here are tips that can help you better defend against double extortion ransomware:
- Monitor for pre-encryption activity, not just encryption: Most double extortion attacks spend days performing reconnaissance, credential theft, privilege escalation, and data staging before encryption. Detecting these behaviors provides a much larger window for containment.
- Baseline outbound data movement: Establish normal patterns for data transfers by user, server, and application. Large encrypted uploads, unusual cloud storage activity, or sustained outbound traffic from file servers often indicate data exfiltration.
- Treat backup infrastructure as a Tier 0 asset: Backup servers, management consoles, and recovery credentials should be isolated, monitored, and protected with dedicated privileged accounts. Attackers frequently target backup infrastructure before launching ransomware.
- Protect identity infrastructure first: Active Directory, Entra ID, federation services, and privileged identity systems are common attacker objectives. Compromising identity infrastructure enables widespread encryption and makes recovery significantly more difficult.
- Detect data staging before exfiltration: Monitor for archive creation, bulk file compression, encryption utilities, and unusually large temporary files. Attackers commonly stage data locally before transferring it outside the environment.
Core Double Extortion Ransomware Workflow
Step 1: Initial Access
Attackers gain access by exploiting public-facing vulnerabilities, using phishing to steal credentials, or buying access from initial access brokers. They establish persistence and avoid detection. Techniques include abusing legitimate administrative tools and using zero-day vulnerabilities. The goal is to remain undetected while preparing for data theft and encryption.
Step 2: Reconnaissance and Privilege Escalation
Attackers map the network to identify critical servers, sensitive data, and high-privilege accounts. They often search for backup systems and security controls. Privilege escalation allows attackers to disable tools, move laterally, and prepare for exfiltration and encryption.
Step 3: Data Exfiltration
Attackers compress and encrypt data before sending it to external servers. Stolen data may include intellectual property, financial records, and customer information. Exfiltration often occurs over days or weeks. Organizations may not detect theft until the ransom demand is issued.
Step 4: Encryption and Demand
Attackers encrypt files and leave ransom notes with payment instructions and threats of exposure. Ransom amounts are often based on the organization’s size and perceived ability to pay. They may provide samples of stolen data and set deadlines. Even with backups, exposure remains a risk.
Related content: Read our guide to the cyber kill chain and how to mitigate advanced threats.
Common Types of Data Targeted in Double Extortion Attacks
Attackers prioritize data that creates financial, legal, or reputational pressure. Common targets include:
- Personally identifiable information (PII): Customer names, addresses, Social Security numbers, passport details, and other personal records.
- Financial data: Bank account details, payment card information, invoices, tax records, payroll data, and financial reports.
- Healthcare records: Medical histories, insurance information, patient records, and protected health information (PHI).
- Intellectual property: Product designs, source code, research data, patents, engineering documents, and trade secrets.
- Employee information: HR records, employment contracts, salary details, background checks, and internal communications.
- Customer and partner data: Contracts, contact databases, pricing agreements, purchase histories, and business communications.
- Authentication data: User credentials, password hashes, API keys, authentication tokens, SSH keys, and digital certificates.
- Legal and compliance documents: Legal correspondence, merger and acquisition documents, audit reports, regulatory filings, and agreements.
- Business communications: Internal emails, chat logs, meeting notes, and executive communications.
- Backup and infrastructure information: Backup configurations, network diagrams, security documentation, and system inventories.
Key Initial Access Vectors of Double Extortion Attacks
Double extortion attacks typically begin through established entry points:
- Phishing emails: Malicious attachments or links that install malware or steal credentials.
- Exploiting unpatched vulnerabilities: Targeting internet-facing systems that lack updates.
- Compromised credentials: Using stolen usernames and passwords from breaches or infostealer malware.
- Remote Desktop Protocol (RDP) abuse: Brute-force attacks or stolen credentials against exposed RDP services.
- Initial access brokers (IABs): Purchasing pre-compromised network access.
- Supply chain compromises: Compromising vendors or managed service providers (MSPs).
- Drive-by downloads and malvertising: Malware delivered through compromised websites or ads.
- Insider threats: Employees or contractors who provide or sell access.
- Cloud service misconfigurations: Exposed storage or overly permissive identity and access management (IAM) settings.
- Trusted tool abuse: Using legitimate remote management tools after gaining access.
How to Prevent Double Extortion Ransomware
Here are some of the ways that organizations can better protect themselves against double extortion.
1. Strengthen Identity and Access Controls
Strong identity controls make it more difficult for attackers to gain initial access, escalate privileges, and move laterally after compromising an account. Organizations should continuously monitor identities, remove excessive permissions, and require strong authentication for high-risk systems to reduce the likelihood that stolen credentials lead to widespread compromise.
Key actions:
- Use multi-factor authentication (MFA) for remote access, privileged accounts, VPNs, and cloud services.
- Use phishing-resistant methods such as FIDO2 security keys or passkeys.
- Enforce strong password policies and remove unused accounts.
- Apply least privilege so users and service accounts have only required permissions.
- Review privileged accounts and use privileged access management (PAM) solutions for sensitive operations.
2. Utilize Immutable Backups
Backups reduce downtime and eliminate paying solely for decryption. Immutable backups remain an essential recovery control because attackers cannot easily modify or encrypt them. However, backups should be part of a broader resilience strategy that includes protecting backup infrastructure, limiting administrative access, and validating recovery procedures regularly so critical systems can be restored quickly after an incident.
Key actions:
- Maintain regular backups using immutable or write-once storage.
- Store backups offline or in isolated environments not accessible from production networks.
- Test restoration procedures to confirm recovery time objectives (RTOs) and recovery point objectives (RPOs).
3. Implement Robust Network Segmentation
Network segmentation limits an attacker’s ability to move laterally between systems and access high-value assets. Separating users, servers, backups, and sensitive workloads into controlled security zones helps contain ransomware outbreaks and reduces opportunities for large-scale data theft before encryption begins.
Key actions:
- Divide networks into zones based on sensitivity.
- Isolate critical servers, backups, domain controllers, and sensitive repositories from user workstations.
- Restrict communication between segments and monitor for unusual traffic or large transfers.
4. Centralize Logging for Faster Investigation
Centralized logging gives security teams a complete view of attacker activity across endpoints, identities, networks, cloud services, and applications. Correlating events from multiple sources accelerates detection, supports forensic investigations, and helps identify both data exfiltration and ransomware deployment before the attack spreads.
Key actions:
- Collect logs from endpoints, servers, network devices, cloud services, identity providers, and security tools into a centralized platform.
- Ensure logs capture authentication events, privilege changes, process execution, network connections, and file access.
- Configure alerts for suspicious behavior.
5. Use SIEM and UEBA to Correlate Attack Signals
Double extortion attacks typically generate multiple behavioral indicators before encryption begins, including unusual authentication activity, privilege escalation, reconnaissance, and large outbound data transfers. SIEM and UEBA help correlate these signals across the environment, enabling earlier detection of attack chains that individual alerts may not reveal.
Key actions:
- Deploy a security information and event management (SIEM) platform to correlate events across the environment.
- Use user and entity behavior analytics (UEBA) to establish baselines and detect anomalies such as unusual access patterns or large data transfers.
- Integrate threat intelligence and automate high-confidence response actions such as isolating compromised endpoints or disabling compromised accounts.
How Exabeam Detects and Stops Double Extortion Ransomware
Double extortion attacks generate abnormal behavior long before encryption begins, but many of these signals evade traditional, rule-based defenses. Exabeam is an AI-powered security platform that helps eliminate blindspots by identifying and reporting on abnormal activity from external attackers, using machine learning (ML) and user and entity behavior analytics (UEBA) to add context to threats including ransomware, malware, unauthorized access, phishing, and attacker reconnaissance. Exabeam correlates security signals across the environment to automatically construct chronological timelines of user and entity behavior. These auto-built timelines map the entire lateral progression of an attack, allowing analysts to immediately see the scope of an incident without manual log parsing.
Key capabilities of Exabeam:
- Real-time ransomware detection: Exabeam uses real-time data analysis to detect techniques and behaviors commonly associated with ransomware, providing visibility into credential use, vulnerable assets, and suspicious processes or commands aimed at encrypting critical files or disabling recovery mode.
- Malware behavior analysis: The platform analyzes web, DNS, and endpoint activity to rapidly detect malware entering or operating on an endpoint, tracking abnormal behavior such as unusual processes or file activity with UEBA, and automating workflows like sandbox file detonation through a malware playbook.
- Abnormal authentication and access detection: Exabeam analyzes key data sources to flag unusual behavior, such as a first-time login from a different country or a login at an unusual time, contextualizing anomalies against historical user and peer behavior and using labels such as “suspected leavers” to surface high-risk events early.
- Phishing detection and response: Exabeam detects phishing attacks and generates a list of compromised users, with UEBA detections adding context, while a phishing checklist and playbook automate response actions such as verifying link reputations and email attachments.
- Guided investigation and response: Analysts can quickly investigate and respond using automated timelines, guided checklists, and playbooks that visualize events by risk, ensuring early intervention and appropriate next steps.
Learn how Exabeam helps security teams detect and respond to threats like double extortion ransomware before encryption begins – explore the Exabeam External Threats solution.
Learn More About Exabeam
Learn about the Exabeam platform and expand your knowledge of information security with our collection of white papers, podcasts, webinars, and more.
-
Blog
Five Ways Exabeam Delivers Better Detection and Security Outcomes Than Microsoft Sentinel
- Show More