What is Triple Extortion Ransomware? - Check Point Software

What is Triple Extortion Ransomware?

Originally, ransomware used a single extortion vector, encrypting data and demanding a ransom for the decryption key. Double extortion ransomware attacks added data theft to the attack, extorting a ransom to not leak the data if a victim refuses the original ransom request.

Triple extortion ransomware adds a third threat to the attack. In addition to encrypting and exfiltrating data, an attacker might perform a distributed denial-of-service (DDoS) attack, threaten the victim’s customers, or make other threats.

How Does A Triple Extortion Ransomware Work?

A triple extortion ransomware attack performs all of the same functions as a double extortion attack. The attacker will deploy ransomware on an organization’s network, and it might move laterally through the network to a system with high-value data. Once there, it will exfiltrate sensitive data before encrypting it.

Once data encryption is complete, the attacker makes their ransom demand of the victim. Originally, the organization might use the encrypted and exfiltrated data as leverage for a ransom demand. However, triple extortion ransomware attackers will escalate to include a third extortion attempt. Some possibilities include:

Risks and Impacts to Businesses from Triple Extortion Ransomware

Some common risks and impacts of triple extortion ransomware attacks include:

Examples of Triple Extortion Ransomware

Some ransomware groups known to engage in triple extortion ransomware attacks include the following:

How to Prevent Triple Extortion Ransomware Attacks

Ransomware attacks can cause significant harm to a business. Some best practices for preventing ransomware attacks include: