DarkScout

Double Extortion Ransomware: How It Works and Why Backups Alone Can’t Stop It

nikhil
16 min read 29 Jul 26
Share :
Double Extortion Ransomware: How It Works and Why Backups Alone Can’t Stop It

Double extortion now shows up in 87.6 percent of all ransomware claims, according to Travelers Insurance’s most recent data. It is not the exception anymore. It is the default.

The reason is almost mechanical in its simplicity. Good backups can defeat traditional ransomware, since an organization with a clean, recent copy of its data does not need to pay for a decryption key at all. Attackers noticed this years ago and adapted. Instead of relying purely on encryption to force a payment, they steal the data first, then threaten to publish it regardless of whether the victim can restore from backup or not.

The speed of that theft has accelerated dramatically too. Unit 42’s 2026 Global Incident Response Report found that the fastest quartile of attackers now reaches full data exfiltration in just 72 minutes after gaining access, well before most organizations even realize they have been breached.

This guide covers exactly how double extortion attacks unfold, why the tactic emerged in the first place, the major groups running these campaigns in 2026, a real case study most people have never fully understood, and what actually helps when a backup alone is no longer the safety net it used to be.

What Is Double Extortion Ransomware?

Double extortion ransomware is an attack where criminals steal an organization’s data before encrypting it, then use both the encryption and the threat of publishing the stolen data as separate points of leverage to force a ransom payment. A traditional ransomware attack only encrypts data. Double extortion adds a second, independent threat on top of that.

This distinction matters because it closes the one reliable escape route organizations used to have. Even a company with perfect, tested backups still faces the second threat: paying to keep sensitive customer records, financial data, or intellectual property from being published publicly or sold to other criminals. Our broader overview of dark web ransomware covers how this entire ecosystem, including the leak sites where stolen data ultimately surfaces, actually operates.

How Double Extortion Attacks Actually Work

A double extortion attack follows a fairly consistent chain, adding two extra stages onto what a traditional ransomware infection would look like.

  1. Initial access. The attacker gains entry through phishing, a purchased or stolen credential, or an unpatched vulnerability, the same entry points covered in depth in our malware protection guide.
  2. Network reconnaissance and lateral movement. The attacker maps the environment, identifies high-value systems, and moves across the network toward the most sensitive data available, often over a period of days rather than hours.
  3. Data exfiltration. Before anything gets encrypted, the attacker quietly copies sensitive data out to infrastructure they control. Research from Symantec and Broadcom has found the file transfer tool rclone present in 57 percent of ransomware exfiltration incidents specifically because of how effectively it moves large volumes of data undetected.
  4. Encryption. Once the data is safely exfiltrated, the attacker deploys the actual ransomware payload, locking the victim out of their own systems and triggering the visible, disruptive part of the attack.
  5. Ransom demand and proof of compromise. The attacker posts a small sample, often around 1 percent of the stolen data, to a dedicated leak site as proof, then sets a payment deadline and opens negotiation through encrypted channels.
  6. Leak site publication. If payment is not received, the remaining stolen data gets published on the leak site, and increasingly, it may also get sold or handed off to other criminal groups regardless of what was agreed to during negotiation.

Why Double Extortion Emerged

Double extortion is not a random evolution. It is a direct, calculated response to organizations getting better at exactly the thing that used to guarantee a payment.

1. Backups were winning

Through the mid-2010s, organizations steadily improved their backup and disaster recovery practices in direct response to the ransomware wave sweeping through that era. As offline and immutable backups became more common, a growing share of victims discovered they could simply wipe infected systems and restore clean data, walking away from an attack without paying anything at all. That shift genuinely threatened the entire ransomware business model, since encryption alone only works as leverage if the victim has no other way to recover.

2. Maze set the precedent

The tactic first emerged as a clear trend around 2019, with the Maze ransomware group widely credited as the first to combine encryption with a public data leak threat at scale. Maze began publishing samples of stolen data from victims who refused to pay, using a dedicated website specifically built to pressure organizations through public exposure rather than operational disruption alone. It was a genuinely new kind of leverage, one that a backup could do nothing to counter.

3. REvil scaled the model

REvil followed closely behind, refining and scaling the same approach across a much larger volume of victims, and demonstrating that the tactic was not a one-off tactic but a repeatable, highly profitable business model. Both groups recognized the same underlying insight: a victim’s disaster recovery capability was irrelevant to a threat aimed at reputational and regulatory damage instead of operational downtime.

4. The model spread fast

What started with a small number of pioneering groups became the industry standard within a remarkably short window. Once the effectiveness of the tactic became clear, competing ransomware-as-a-service operations adopted the same playbook almost immediately, since any group still relying on encryption alone was leaving an entire category of leverage on the table. The approach worked so well that it has since become the default model across the ransomware ecosystem, present in the overwhelming majority of attacks today rather than a specialized tactic used by only a handful of groups.

Triple and Multi-Extortion: How Far This Has Gone

Once double extortion proved effective, ransomware groups kept adding pressure points, and the tactic has continued escalating well beyond the original two-part model.

1. Distributed denial-of-service threats

Some groups now layer a DDoS attack on top of encryption and data theft, taking a victim’s public-facing systems offline entirely to add urgency and force faster payment decisions.

2. Direct customer and third-party notification

Rather than only threatening the victim organization, some groups now contact the victim’s own customers, patients, or business partners directly, informing them their data was stolen and applying reputational pressure that the original victim cannot control. This tactic hits especially hard for organizations with extensive vendor and customer networks, a risk covered in more depth in our guide to third-party cyber risk.

3. Harassment campaigns

In more aggressive cases, groups have targeted executives and employees directly through calls, emails, or public exposure, adding a personal dimension to what was originally a purely organizational threat.

Major Double Extortion Groups to Know in 2026

The ransomware landscape shifts constantly as groups get disrupted and new ones emerge, but a handful of names have defined 2026 so far.

Qilin

Originally launched in 2022 under the name Agenda before rebranding, Qilin operates a mature ransomware-as-a-service platform believed to be run by a Russian-speaking group, evidenced partly by its policy of avoiding targets in CIS countries, according to SANS Institute’s analysis of the group’s evolution. Affiliates keep 80 to 85 percent of any ransom collected, with the operators taking the remainder in exchange for the payload, leak site infrastructure, and negotiation portal.

Qilin’s growth has been dramatic. The group logged just 45 attacks in 2023, grew to 179 in 2024, then surged past 1,000 claimed victims in 2025, more than any other ransomware operation worldwide that year, as documented by managed security provider OSIbeyond. Much of that acceleration came from absorbing affiliates displaced when rival operations like RansomHub, LockBit, and ALPHV went offline or fractured. It has dominated the leak site rankings into 2026, posting its highest monthly victim count on record in March with 131 claimed victims, three consecutive months above 100 for a single group being unprecedented in tracking history. Its affiliate panel has also grown unusually feature-rich, including automated ransom negotiation tools and, as of mid-2025, an in-panel option to summon legal counsel during negotiations.

Cl0p

Cl0p takes a fundamentally different approach from most of its peers. Rather than running a public affiliate recruitment program, it operates with no visible forum presence, handling zero-day discovery and mass exploitation internally or through a small number of contracted specialists. That discipline is exactly what made its MOVEit campaign so effective, when a single SQL injection zero-day let the group exfiltrate data from hundreds of organizations through one compromised file transfer platform, a pattern CISA and the FBI’s joint advisory later confirmed had compromised at least 160 victims within a single month.

The same playbook has repeated on a roughly annual cycle since. Cl0p previously exploited Accellion and GoAnywhere file transfer platforms, then Cleo managed file transfer products in 2024, and an Oracle E-Business Suite vulnerability in 2025 that one threat intelligence roundup reported affected over 100 companies, including several large, well-known organizations. In most of these campaigns, Cl0p skips traditional encryption entirely, favoring pure data-theft extortion, which is faster to execute and considerably harder for defenders to interrupt once exfiltration has already occurred.

Akira

Akira has grown into one of the most consistently active operations tracked heading into 2026, nearly doubling its victim count month over month during the same stretch that saw Qilin surge. The same 2026 ransomware ranking cited above lists Akira alongside Qilin and Cl0p as one of the three most prolific operations currently active, a position it has held consistently across multiple monthly leaderboards.

ALPHV/BlackCat

ALPHV, also known as BlackCat, has diminished significantly since 2024, though CSO Online’s ongoing tracking of major ransomware groups still lists it among the most consequential operations in the ecosystem’s recent history. It remains one of the most instructive examples in the industry precisely because of what happened after one of its highest-profile attacks. The group’s collapse, including an exit scam that betrayed its own affiliate mid-negotiation, is covered in full detail in the case study below.

Real-World Example: The Change Healthcare Attack

Few incidents illustrate the real mechanics of double extortion, including its failure points, as clearly as the 2024 attack on Change Healthcare.

A BlackCat/ALPHV affiliate gained access through a remote Citrix portal that lacked multi-factor authentication, then spent roughly nine days moving through the network undetected before exfiltrating an estimated 6 terabytes of data and deploying ransomware. Optum, a UnitedHealth Group subsidiary, paid a 22 million dollar ransom specifically to secure deletion of the stolen data, according to HIPAA Journal’s detailed account of the incident. The BlackCat group then performed what is known in ransomware circles as an exit scam, taking the payment and shutting down without paying the affiliate who actually carried out the attack.

That unpaid affiliate still held a full copy of the stolen data. They handed it to a second group, RansomHub, which attempted to extort Change Healthcare a second time using the exact same information. The final tally, confirmed in mid-2025, put the number of affected individuals at approximately 192.7 million people, more than half the United States population, making it the largest healthcare data breach in the country’s history. The 22 million dollar payment did not prevent any of it.

How to Detect and Respond to Double Extortion

Speed and preparation both matter enormously, since the window between initial access and full data exfiltration has compressed dramatically.

  • Monitor for unusual outbound data transfer. Large or unusual volumes of outbound traffic, especially involving known exfiltration tools, are frequently the earliest visible sign of an attack in progress, often occurring well before encryption ever begins.
  • Enforce multi-factor authentication on every remote access point. The Change Healthcare breach traced back to exactly one unprotected entry point, a pattern that repeats across a significant share of major ransomware incidents.
  • Segment networks to limit lateral movement. Restricting how far an attacker can travel after initial access directly limits how much data is ultimately exposed to theft.
  • Have an incident response plan ready before an attack happens, not during one. Our full incident response guide covers building this process in advance rather than improvising it mid-crisis.
  • Understand your data breach notification obligations in advance. Our data breach response plan covers the legal and communication requirements that activate the moment exfiltration is confirmed.
  • Assess third-party and vendor exposure regularly. A single vendor’s breach, as Change Healthcare demonstrated, can disrupt an entire dependent ecosystem well beyond the original victim.

Where Dark Web Monitoring Fits In

Most double extortion prevention advice focuses on stopping the attack before encryption happens. Fewer strategies account for the exposure that often exists well before an attacker even gains access in the first place.

Stolen credentials frequently circulate on dark web markets before they get used in an actual attack, which is exactly the entry point that led to incidents like Change Healthcare. Catching that exposure early, before it becomes the foothold an affiliate uses to start the entire chain, is a meaningfully different posture than only watching for signs of an attack already underway. Once an attack has succeeded, monitoring leak sites also matters directly, since data appearing there confirms exfiltration occurred and triggers formal breach notification obligations. It also matters for protecting brand reputation more broadly, a topic covered in our guide to brand protection on the dark web.

DarkScout’s dark web monitoring service tracks both of these fronts continuously, flagging exposed credentials before they become an attacker’s way in, and monitoring leak sites and forums for any mention of your organization’s data after the fact.

Conclusion

Double extortion ransomware succeeded because it closed the one reliable defense organizations had against traditional encryption-based attacks. Good backups still matter enormously for operational recovery, but they were never designed to stop a criminal group from publishing stolen data regardless of whether you can restore your systems or not.

The Change Healthcare case shows exactly how far this can go, and how little control a victim retains even after paying. The most effective response is not choosing whether to pay after the fact. It is closing the entry points, like unprotected remote access and exposed credentials, that let an attacker start the chain in the first place.

If your organization wants to know whether employee credentials are already circulating in the same channels attackers use to launch these campaigns, DarkScout’s dark web monitoring service checks continuously so exposure gets caught before it becomes the next headline.

Frequently Asked Questions

What is double extortion ransomware?

Double extortion ransomware is an attack where cybercriminals steal sensitive data before encrypting it, then demand payment to both restore access and prevent the stolen data from being published.

How does double extortion differ from traditional ransomware?
Why are backups no longer enough against ransomware?
How do double extortion attacks usually begin?
Which ransomware groups commonly use double extortion?
What is triple extortion?
How can organizations prevent double extortion attacks?
How does dark web monitoring help prevent double extortion?
What should organizations do after a double extortion attack?
Scroll to Top