What is double extortion ransomware?
Double extortion ransomware both encrypts your data and steals a copy of it before encrypting. The attacker then demands payment twice over: once to restore your systems, and again to stop publication of the stolen data. It exists because reliable backups defeat plain encryption, so attackers added a second form of leverage that backups cannot undo.
This is why "we have backups" is no longer a complete answer to ransomware. Restoring from backup solves availability, but it does nothing about a copy of your data sitting on a leak site.
Some groups have extended the model further, adding pressure through denial-of-service, direct contact with your customers, or regulatory complaints against the victim.
The defensive implication is that ransomware readiness has to include preventing and detecting bulk data movement out of the network, not only protecting the ability to restore.
Related coverage
Ransomwaredispatches →Ransomware gangs, double-extortion campaigns, decryptors, and the incidents shaping today's ransomware landscape.
More on attacks