Double Extortion
Double extortion is a ransomware tactic in which attackers steal (exfiltrate) an organization's sensitive data before encrypting it, then make two demands: pay to unlock the encrypted systems and pay to prevent the stolen data from being leaked publicly. This means keeping reliable backups alone may not fully protect a victim, because the threat of publishing the stolen data remains even if the encrypted files can be restored.
Double extortion refers to a ransomware attack pattern in which threat actors first exfiltrate sensitive data from a victim environment and then deploy crypto-malware to encrypt that data in place, creating two distinct leverage points for extortion: recovery of encrypted systems and non-disclosure of the exfiltrated data. Because the attacker retains a copy of the stolen data, restoring from backups addresses the availability impact but does not neutralize the confidentiality-based extortion threat of public leakage. This entry describes the threat tactic itself and does not address whether resulting losses (for example, cyber extortion payments, data restoration, business interruption, or third-party privacy liability) are covered under any given cyber insurance policy; coverage depends on the specific policy wording, endorsements, exclusions, and conditions.
Why it matters
Double extortion changes the calculus of ransomware preparedness because reliable backups, long considered the primary defense against ransomware, address only one of the two leverage points attackers create. An organization that can restore encrypted systems from backups has resolved the availability impact of an attack, but the attacker still holds a copy of the exfiltrated data and can threaten to publish it. This means that recovery capability alone does not neutralize the confidentiality-based extortion threat, and the decision about whether to pay is no longer solely about regaining access to systems.
Because the tactic combines an availability event (encryption) with a confidentiality breach (data theft), a single incident can simultaneously implicate multiple exposure categories that resilience planners and insurance professionals otherwise treat separately. The theft and potential publication of sensitive data can give rise to third-party privacy claims and regulatory scrutiny, while the encryption drives first-party impacts such as business interruption and data restoration costs. Any cyber extortion demand may separately implicate first-party extortion considerations. Whether losses arising from these distinct impacts are covered under a given cyber insurance policy depends entirely on the specific policy wording, endorsements, exclusions, and conditions, and nothing about the tactic itself guarantees coverage.
For risk and resilience professionals, double extortion underscores that insurance is a mechanism of risk transfer, not risk mitigation: purchasing coverage does not reduce the likelihood of exfiltration and does not by itself prevent the reputational, regulatory, or legal harm that can follow public leakage of stolen data. Effective preparedness for this tactic typically requires layering data-protection and detection controls, incident response planning, and any applicable risk transfer, rather than relying on backups or a policy in isolation.
Who it's relevant to
Inside Double Extortion
Common questions
Answers to the questions practitioners most commonly ask about Double Extortion.