Data Extortion
Data extortion is a type of cyberattack in which criminals steal an organization's sensitive information and then threaten to publish, sell, or otherwise misuse it unless a ransom is paid. Unlike traditional ransomware that locks up files by encrypting them, this approach relies on the threat of disclosure rather than denial of access. Increasingly, attackers focus on stealing data and demanding payment instead of, or in addition to, encrypting systems.
Data extortion is a form of cyber extortion in which threat actors exfiltrate a victim's data through an intentional, unauthorized transfer from a system or network, then leverage the threat of disclosure, sale, or destruction to compel payment. It may occur without any encryption of victim systems (sometimes called encryption-free or exfiltration-only extortion) or as a component of double extortion, in which data is both exfiltrated and encrypted. This entry describes the threat activity itself and does not address whether resulting losses are insurable; coverage for extortion demands, ransom payments, or data-related liability depends on the specific policy wording, applicable sublimits and retentions, exclusions, and jurisdiction, and should not be inferred from this definition.
Why it matters
Data extortion has become a central feature of the cyber threat landscape, and the evidence indicates the criminal ecosystem is increasingly focusing on data theft and extortion rather than simply locking up victims' files through encryption. This shift matters because organizations that invested heavily in backup and recovery capabilities to defeat traditional encryption-based ransomware may find those defenses far less effective against an attacker whose leverage is the threat of disclosure. Restoring encrypted files does nothing to un-steal data that has already left the environment.
For risk managers and insurance professionals, data extortion complicates both loss assessment and coverage analysis. A single event can blur the line between first-party exposures, such as the costs of responding to an extortion demand, and third-party exposures, such as liability to individuals whose information is published. Whether any resulting loss is insurable depends entirely on the specific policy wording, applicable sublimits and retentions, exclusions, and jurisdiction; the existence of an extortion threat does not by itself establish that a ransom payment, extortion cost, or downstream liability will be covered. These questions must be resolved against the actual policy form rather than assumed.
Data extortion also underscores the limits of risk transfer. Purchasing cyber insurance does not reduce the likelihood that an attacker will exfiltrate data, nor does paying a ransom guarantee that stolen data is actually deleted rather than retained, sold, or leaked later. Effective preparedness therefore combines risk mitigation controls that reduce the chance of exfiltration with resilience planning and, separately, any risk transfer arrangements an organization chooses to put in place.
Who it's relevant to
Inside Data Extortion
Common questions
Answers to the questions practitioners most commonly ask about Data Extortion.