What is Double Extortion Ransomware? - Check Point Software

What is Double Extortion Ransomware?

Originally, ransomware used the threat of data loss to inspire its victims to pay a ransom demand. It accomplished this by encrypting data on an organization’s systems and then demanding a ransom to provide the decryption key.

However, the effectiveness of this technique is limited by the fact that some organizations can restore their data from backups without paying the ransom. Double extortion ransomware is designed to overcome this hurdle and increase the attackers’ probability of receiving a payment.

How Does It Work?

Good data backups can defeat traditional ransomware. If an organization has another copy of its data, it does not need to pay for a decryption key to restore it.

Double extortion ransomware overcomes this challenge by combining data theft with data encryption. By stealing data and threatening to leak it if a ransom isn’t paid, the ransomware operator can successfully extort ransoms even if an organization has backups and could otherwise recover without payment.

Attack Sequence of Double Extortion Ransomware

Double extortion ransomware adds additional stages to the attack chain of a ransomware infection, and likely includes the following steps:

Potential Risks and Impacts

A successful ransomware infection can be extremely damaging to an organization. Some of the most common impacts include the following:

Examples of Double Extortion Ransomware

Many ransomware groups have adopted the double extortion methodology. Some of the most well-known include:

How to Prevent Double Extortion Ransomware Attacks

Some cybersecurity best practices to protect the organization against ransomware attacks include the following:

Prevent Ransomware Attacks with Check Point

Double extortion ransomware attacks pose a significant threat to businesses since they can defeat backups as a ransomware defense. To learn more about defending against this threat, check out the CISO Guide to Ransomware Prevention.

Ransomware is one of many cyber threats that organizations face, as detailed in Check Point’s Cyber Security Report. Check Point Endpoint Security offers strong protection against ransomware and other endpoint security threats.