For years, the standard security advice against ransomware was fairly simple: if you have good backups, ransomware loses its negotiating power. It encrypts your files, you restore from backup, and the attacker is left with nothing to offer in exchange for their ransom. That logic worked reasonably well — until ransomware groups found a way to neutralize it entirely. The solution they landed on is called double extortion, and it completely changed the risk calculus for any business.
What Double Extortion Actually Is
In a traditional ransomware attack, the attacker encrypts the victim's files and demands payment for the decryption key. If the victim has functional backups, they simply restore from there and the attack loses most of its weight.
Double extortion adds a second component: before encrypting anything, the attacker first extracts — exfiltrates — a copy of the company's most sensitive information. Contracts, customer data, financial records, internal correspondence. Then they encrypt the systems as in a traditional attack, but now with an added threat: if the ransom isn't paid, the stolen information gets published or sold, regardless of whether the company managed to restore everything from backups.
That turns backups, on their own, into an insufficient defense. Having backups is still essential — it solves the problem of data availability — but it doesn't solve the problem of confidentiality. A company can regain access to its systems and still face the publication of sensitive data.
Why This Evolution Makes Sense From the Attacker's Perspective
Ransomware groups operate, essentially, as businesses trying to maximize the probability of getting paid. As more companies improved their backup practices in response to years of traditional attacks, encryption alone started losing its negotiating leverage. Double extortion was the logical offensive response: add a second pressure lever that doesn't depend on whether the victim can restore its systems.
The Consequences Go Beyond the Ransom Itself
When the leaked information includes personal data belonging to customers or employees, the incident stops being just an operational problem and also becomes a legal one under Colombia's Habeas Data Law — with specific reporting obligations we cover in detail in our guide on when reporting a cyberattack is legally required in Colombia. And if the leaked information includes trade secrets or intellectual property, the damage can far exceed the direct cost of the initial incident.
How to Reduce the Risk When Backups Aren't Enough Anymore
Defending against double extortion means thinking about two separate problems, not one:
For data availability, backups genuinely isolated from the main network are still essential — but they need to be immutable, meaning impossible to modify or encrypt even if an attacker gains access to them.
For data confidentiality, the defense has to happen before the attacker manages to exfiltrate anything: strict control over what can leave the network, monitoring for unusual data transfers, encrypting the most sensitive information even within your own infrastructure, and segmentation that limits what an attacker who got in through a single point can actually reach.
Detecting data exfiltration before it completes is, in practice, the most valuable window of opportunity to keep an attack from escalating into double extortion — one more reason to have 24/7 incident response capability that can act in the first hours, not days later.
Frequently asked questions
Are backups useless against ransomware now?
They're still essential — they solve the problem of regaining access to systems — but they're no longer enough on their own against a double extortion attack, because they don't prevent the leaked data from getting out.
How do I know if my business was hit by double extortion versus a traditional attack?
The ransom note usually says so explicitly, often with a sample of the allegedly stolen data as proof. A forensic analysis confirms the real scope of the exfiltration.
Does paying the ransom guarantee the leaked data gets deleted?
There's no guarantee at all. You're negotiating with a criminal actor whose compliance with any "agreement" has no legal backing whatsoever.
Does double extortion only target large companies?
No. Any business handling information worth leaking or selling — customer data, financial information, intellectual property — is a potential target, regardless of size.
Let's talk
Defending against double extortion requires controls that go beyond traditional backups. At T.I. RESCUE we help design that additional layer of protection, and we respond immediately if your business is already facing an active incident through our [24/7 incident response](https://tirescue.com/en/respuesta-ante-incidentes-247/) service. Need to assess how prepared your business actually is? [Let's talk](https://tirescue.com/en/contacto-ti-rescue/).
Contact usYou may also like
Comments (0)
Be the first to comment.