Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Repeat victimisation: the threat of double extortion ransomware attacks

Despite ransomware’s stellar ROI, cybercriminal groups have recently decided there is more to be made from this brand of malware

by Andrew Hollister
October 14, 2020
in Insight
Repeat victimisation: the threat of double extortion ransomware attacks
Share on FacebookShare on Twitter

Ransomware has already proven itself to be a powerfully profitable weapon in the cybercriminal arsenal. According to Emsisoft, in 2019, ransomware incidents could have had a combined cost of more than $7.5 billion (£5.65 billion). That’s just for US-based incidents too.

As cybersecurity professionals and the public at large have come to realise, cybercrime is now a huge business, with organised threat groups sharing resources and techniques to boost profitability. Despite ransomware’s stellar ROI, cybercriminal groups have recently decided there is more to be made from this brand of malware, and have switched up their tactics, employing a new double extortion model.

Double trouble

In the last year or so, double extortion attacks have picked up the pace and made headlines, with the operators of Maze ransomware leading the way in utilising them. In the double extortion model, not only do ransomware attackers encrypt data and demand a ransom to regain access, but also threaten to publish any exfiltrated data online if their terms are not met.

This has proven successful for a number of reasons. Firstly, businesses are already highly aware of ransomware. The operational down-time that ransomware can force upon a company is of course damaging and rather difficult to conceal, leading to negative media attention. Even if a ransomware-afflicted business ultimately rids itself of the ransomware through the efforts of security professionals, there may still exist a public perception (even if erroneous) that a company paid the ransom, leading to more negative sentiment.

Clearly, the ransomware groups like the organisation behind Maze have realised that the damage caused by ransomware extends far beyond the locking of systems. After all, even the knowledge an attacker is in the network, and the threat of an encrypt button being pressed is enough to make some companies payout.

Ransomware groups are additionally diversifying their approach by taking copies of data before performing the encryption. This gives them a number of options, each of which has been seen played out in the wild.

Firstly, it proves to the victim and/or the wider world that they really have breached the organisation. It also adds a second layer of extortion – i.e. pay or we will leak the data. What’s particularly threatening about this approach is that, even if a company decides to restore from backup rather than pay up, that data is still valuable, and the threat of leakage is not diminished. In the cases where a company does pay the ransom, the cybercriminals can provide worthless assurance that they have deleted their copy of the data. This data could end up leaked later on or used again to leverage yet another payout.

Clearly, these are unscrupulous criminals seeking to exploit any opportunity they have for financial gain. The Maze gang, when referring to the attack on LG’s network earlier in the year, presented a veneer of ethicality to their actions, claiming they didn’t execute the ransomware as LG’s clients are “socially significant and we do not want to create disruption for their operations.” Instead, they leaked over 50GB of stolen data.

Doubling down on security

Fortunately for would-be victims, there are a number of ways in which ransomware attacks can be prevented, or at least mitigated. In many cases, the intruders have been in the network for what may be an extended period of time prior to initiating the actual malware attack – and a critical goal of any cybersecurity programme is minimising the time intruders remain undetected in the corporate network.

Minimising the time attackers spend within the company network relies upon being informed towards the process by which ransomware attacks are executed. There are five distinct stages that define a ransomware attack, and by being familiar with each phase – and its indicators of compromise (IOC) – security teams can quickly respond to an intrusion. This allows for companies to limit or even prevent entirely threat actors from accessing data that can then lead to a double extortion ransomware attack.

The five phases of a ransomware attack are:

  1. Exploitation and infection
  2. Delivery and execution
  3. Backup spoliation
  4. File encryption
  5. User notification and clean-up

To meet this threat, there are also five phases of defence against ransomware, which are preparation, detection, containment, eradication, and recovery. Large scale outbreaks result from inadequate containment – where the local host needs to be immediately blocked and isolated from the network, which prevents additional files on the network from being encrypted.

An organisation’s ability to recognise IOCs pointing to the five phases of attack and then employing the five phases of defence, lies in effective monitoring of company networks. It is crucial that companies recognise the stark nature of the ransomware threat and acquire the necessary technological solutions and security teams to ensure this comprehensive monitoring.

 

Contributed by Andrew Hollister, head of LogRhythm labs

ShareTweet
Previous Post

The click of death: Why ecommerce must work extra hard to thwart attackers

Next Post

Qualys VMDR Product Review

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol